Code Injection Vulnerability in VibeSurf by vibesurf-ai
CVE-2026-18770
6.9MEDIUM
What is CVE-2026-18770?
A code injection vulnerability has been identified in the VibeSurf product by vibesurf-ai, found in the Python Validation Handler component. This vulnerability allows an attacker to manipulate an unknown function in the file /code, potentially leading to remote code execution. As this product employs a rolling release strategy for its updates, specific version details regarding the vulnerability or its remediation have not been disclosed. The vendor was contacted prior to this disclosure but did not respond.
Affected Version(s)
VibeSurf cd6e519d507cdd4d63061300bf60fb176e1f57e0
