Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-85694: Lavague 0.2.35 can run malicious code from web pages

CVE-2026-85694 · published 26 days ago
Summary

The Lavague 0.2.35 library can execute Python code that comes from web pages without checking it first. An attacker who controls a web page could cause the software to run any code they want on the machine running Lavague. Update to a patched version or stop using this function until it is fixed.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
lavague-ai lavague <= 0.2.35
Original advisory text
LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attacker...
LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code through web pages using indirect prompt injection to execute arbitrary code on the operator's host without review.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.2 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-94Code Injection
Timeline
Published4 Sep 2026
Updated30 Sep 2026
First seen4 Sep 2026
Sources
CVE-2026-85694 · MITRE
Track software like this
Free during beta