vulnti.work

Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise as commands are exec…

Critical CVSS 9.9
CVECVE-2026-9645
First seen2026-07-21 11:15 UTC
Disclosed2026-05-28 21:16 UTC
Last updated2026-07-21 11:15 UTC
Channel statusauto

Summary

Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise as commands are executed as root.

In-depth triage · Auto channel

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Sources

  • NVD DATABASE

Original Links

Timeline

  1. nvd_ingest NVD