Remote Code Execution in AI Scanner by NVIDIA Garak
CVE-2026-41512
9.9CRITICAL
What is CVE-2026-41512?
The ai-scanner, developed on NVIDIA garak, is vulnerable to a remote code execution exploit due to JavaScript injection in the BrowserAutomation::PlaywrightService component. This issue affects versions from 1.0.0 to below 1.4.1, allowing attackers to execute arbitrary code remotely. A patch has been implemented in version 1.4.1 to resolve this vulnerability.
Affected Version(s)
ai-scanner >= 1.0.0, < 1.4.1
