216.73.217.22

CVE-2026-42601

· Published 09/05/2026 20:16 · Modified 09/05/2026 20:16

Labels: CVE-2026-42601 2026-05-09CVE-2026-42601CWE-88[email protected]

Essential information

Published
09/05/2026 20:16
Modified
09/05/2026 20:16
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6rc0 and prior, the /add/ endpoint (AddView in core/views.py) accepts a config JSON field that gets merged into the crawl config without validation. This config is exported as environment variables when archive plugins run, allowing injection of arbitrary tool arguments to achieve RCE. At time of publication, there are no publicly available patches.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
archivebox / archivebox cpe:2.3:a:archivebox:archivebox:0.8.6rc0:*:*:*:*:*:*:*
archivebox / archivebox cpe:2.3:a:archivebox:archivebox:<0.8.6rc0:*:*:*:*:*:*:*

References