Skip to content
CVE-2026-85694 - Exploits & Severity

CVE-2026-85694 - Exploits & Severity

Feedly • September 5, 2026

LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code through web pages using indirect prompt injection to execute arbitrary code on the operator's host without review.

An unauthenticated attacker over the network can inject malicious Python code through web page content via indirect prompt injection to execute arbitrary code on the operator's host machine.

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

Update LaVague to a version after 0.2.35 that includes fixes for the remote code execution vulnerability. Review and sanitize all web page content processed by LaVague, and consider implementing additional input validation and sandboxing for language model output evaluation. Restrict network access to LaVague instances where possible.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Feedly found the first article mentioning CVE-2026-85694 . See article

NVD published the first details for CVE-2026-85694

A CVSS base score of 8.1 has been assigned.

CVE-2026-85694 | lavague-ai LaVague up to 0.2.35 PythonFromMarkdownExtractor PythonFromMarkdownExtractor.extract_as_object injection

Be the first to know critical vulnerabilities

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities

Attack Types (1)

CWE Weaknesses (1)

MITRE ATT&CK (1)

Platforms (1)

Tools (1)