Plugin Signature Enforcement Bypass in Stigmem Node by Eidetic Labs
CVE-2026-76241
7.3HIGH
What is CVE-2026-76241?
The Stigmem Node version 0.9.0a1 contains a vulnerability that allows users to disable crucial plugin signature enforcement without a second confirmation. This misconfiguration can pose a substantial risk in environments where plugin directories are accessible to less-trusted users. In such scenarios, unauthorized and potentially harmful plugin code may be loaded and executed, leading to arbitrary code execution. This issue has been addressed in version 0.9.0a2, which mandates an additional confirmation step before disabling signature enforcement.
Affected Version(s)
stigmem 0 < 0.9.0a2
stigmem 0.9.0a2
