Remote Code Execution Vulnerability in ArchiveBox Affected by Unsanitized Input
CVE-2026-42601
9.3CRITICAL
What is CVE-2026-42601?
ArchiveBox is an open source self-hosted web archiving system that faced a significant security flaw due to improper validation of user inputs. The issue resides in its /add/ endpoint, where a user-supplied JSON configuration is merged into the crawl configuration without adequate checks. This vulnerability allows attackers to inject arbitrary tool arguments, potentially leading to Remote Code Execution (RCE) when archive plugins are executed. At present, no public patches are available, heightening the urgency for users to mitigate risks associated with this vulnerability.
Affected Version(s)
ArchiveBox <= 0.8.6rc0
