Remote Code Execution Vulnerability in ArchiveBox Affected by Unsanitized Input
CVE-2026-42601

9.3CRITICAL

Key Information:

Vendor

Archivebox

Vendor
CVE Published:
9 May 2026

What is CVE-2026-42601?

ArchiveBox is an open source self-hosted web archiving system that faced a significant security flaw due to improper validation of user inputs. The issue resides in its /add/ endpoint, where a user-supplied JSON configuration is merged into the crawl configuration without adequate checks. This vulnerability allows attackers to inject arbitrary tool arguments, potentially leading to Remote Code Execution (RCE) when archive plugins are executed. At present, no public patches are available, heightening the urgency for users to mitigate risks associated with this vulnerability.

Affected Version(s)

ArchiveBox <= 0.8.6rc0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.