Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

LaVague 0.2.35 Remote Code Execution via Prompt Injection

LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code through web pages using indirect prompt injection to execute arbitrary code.

Disclosed 4 September 2026 · Record updated 13 September 2026

Impact

Arbitrary code execution on the operator's host through indirect prompt injection via web page content

Our coverage

No articles linked to this incident yet.

Sources

  1. github.comhttps://github.com/advisories/GHSA-gvgx-3mw6-m592