Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-30117: Scalar Proxy allows attackers to execute arbitrary code

CVE-2026-30117
Summary

An attacker can upload a malicious file, potentially executing code on your server. This is a serious issue, especially if you're hosting user-uploaded content. Update to the latest version of Scalar Proxy to fix this vulnerability.

Original title
scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows attackers to exec...
Original description
scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows attackers to execute arbitrary code via uploading a crafted SVG file.
Vulnerability type
CWE-94 Code Injection
Published: 19 May 2026 · Updated: 28 May 2026 · First seen: 19 May 2026