Critical RCE Vulnerability in LaVague 0.2.35 Disclosed
Article Content
A remote code execution vulnerability, CVE-2026-85694, has been identified in LaVague version 0.2.35. The flaw exists in the PythonFromMarkdownExtractor.extract_as_object function, allowing unauthenticated attackers to inject malicious Python code via web pages using indirect prompt injection. This could lead to arbitrary code execution on the operator's host without prior review. Currently, no public proof-of-concept or evidence of exploitation has been reported. Users are advised to update to a version beyond 0.2.35 and to implement sanitization and input validation measures. The CVSS base score assigned to this vulnerability is 8.1, indicating a high severity level. The vulnerability was published on September 4, 2026.
Key Points: • CVE-2026-85694 affects LaVague version 0.2.35, enabling remote code execution. • Attackers can exploit the vulnerability via indirect prompt injection through web pages. • No public proof-of-concept or exploitation evidence has been reported yet.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.