Plugin Signature Enforcement Bypass in Stigmem Node by Eidetic Labs
CVE-2026-76241

7.3HIGH

Key Information:

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-76241?

The Stigmem Node version 0.9.0a1 contains a vulnerability that allows users to disable crucial plugin signature enforcement without a second confirmation. This misconfiguration can pose a substantial risk in environments where plugin directories are accessible to less-trusted users. In such scenarios, unauthorized and potentially harmful plugin code may be loaded and executed, leading to arbitrary code execution. This issue has been addressed in version 0.9.0a2, which mandates an additional confirmation step before disabling signature enforcement.

Affected Version(s)

stigmem 0 < 0.9.0a2

stigmem 0.9.0a2

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.