LaVague 0.2.35 Remote Code Execution via Prompt Injection
LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code through web pages using indirect prompt injection to execute arbitrary code.
Disclosed 4 September 2026 · Record updated 13 September 2026
Impact
Arbitrary code execution on the operator's host through indirect prompt injection via web page content
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-gvgx-3mw6-m592
