PT-2026-85580 · Lavague Ai · Lavague

·

CVE-2026-85694

·

Published

2026-09-04

·

Updated

2026-09-04

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract as object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code through web pages using indirect prompt injection to execute arbitrary code on the operator's host without review.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85694

Affected Products

Lavague