CVE Feed

    Dashboard / CVE / CVE-2026-85694

    CVE-2026-85694

    LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code through web pages using indirect prompt injection to execute arbitrary code on the operator's host without review.

    Published:Sep 4, 2026
    Last Modified:Sep 8, 2026
    EPS:Sep 4, 2026
    EPSS Score:0.0055
    CVSS Score:8.1

    Affected Products

    Vendor
    Lavague
    Product
    Lavague

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High