CVE-2026-85694: LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that eval
Summary
LaVague version 0.2.35 has a remote code execution vulnerability (RCE, where attackers can run commands on a system they don't own) in a component called PythonFromMarkdownExtractor.extract_as_object that unsafely runs Python code generated by an AI model. Attackers can exploit this by injecting malicious code through web pages using indirect prompt injection (tricking the AI by hiding instructions in web content), allowing them to execute harmful commands on the operator's computer without any human review.
Vulnerability Details
8.1(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
network
high
none
none
September 4, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-85694
First tracked: September 4, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 92%