VulnWatch VulnWatch
← Back to dashboard
Critical nvd · CVE-2026-85694

CVE-2026-85694: LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that eval

Published Sep 4, 2026 CVSS 9.2

LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code through web pages using indirect prompt injection to execute arbitrary code on the operator's host without review.

Affected AI Products

prompt injection indirect prompt
Get the weekly digest. Every Monday: top AI security stories of the week. Free.