Critical RCE Vulnerability in LaVague 0.2.35 Disclosed

Critical RCE Vulnerability in LaVague 0.2.35 Disclosed

First seen 5 Sep 2026, 07:02 UTC Feedlycve.reportvuldb.comnvd.nist.gov 57.8

Article Content

Browse articles
ThreatCluster

A remote code execution vulnerability, CVE-2026-85694, has been identified in LaVague version 0.2.35. The flaw exists in the PythonFromMarkdownExtractor.extract_as_object function, allowing unauthenticated attackers to inject malicious Python code via web pages using indirect prompt injection. This could lead to arbitrary code execution on the operator's host without prior review. Currently, no public proof-of-concept or evidence of exploitation has been reported. Users are advised to update to a version beyond 0.2.35 and to implement sanitization and input validation measures. The CVSS base score assigned to this vulnerability is 8.1, indicating a high severity level. The vulnerability was published on September 4, 2026.

Key Points: • CVE-2026-85694 affects LaVague version 0.2.35, enabling remote code execution. • Attackers can exploit the vulnerability via indirect prompt injection through web pages. • No public proof-of-concept or exploitation evidence has been reported yet.

Ask AI about this cluster

Timeline

2026-09-04
CVE-2026-85694 published
The vulnerability details for CVE-2026-85694 were officially disclosed, highlighting a critical RCE flaw in LaVague 0.2.35.
cve.report