PT-2026-103194 · Siteskite · Siteskite
CVE-2026-96349
·
Published
2026-09-30
·
Updated
2026-10-01
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SiteSkite versions prior to 2.2.0
Description
An unauthenticated remote code execution issue exists due to a critical chain involving API-key autologin and the
eval() function within the MCP component. This allows an attacker to execute arbitrary code on the server.Recommendations
Update SiteSkite to version 2.2.0.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siteskite