Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-85694: Lavague 0.2.35 can run malicious code from web pages
CVE-2026-85694 · published 26 days ago
Summary
The Lavague 0.2.35 library can execute Python code that comes from web pages without checking it first. An attacker who controls a web page could cause the software to run any code they want on the machine running Lavague. Update to a patched version or stop using this function until it is fixed.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| lavague-ai | lavague | <= 0.2.35 |
Original advisory text
LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attacker...
LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code through web pages using indirect prompt injection to execute arbitrary code on the operator's host without review.
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-94Code Injection
Timeline
Published4 Sep 2026
Updated30 Sep 2026
First seen4 Sep 2026
Track software like this
Free during beta