Remote Code Execution Vulnerability in LaVague by LaVague AI
CVE-2026-85694
9.2CRITICAL
What is CVE-2026-85694?
LaVague version 0.2.35 is vulnerable to remote code execution due to a flaw in the PythonFromMarkdownExtractor.extract_as_object method. This vulnerability enables attackers to utilize untrusted language model output from web content, allowing for the injection of malicious Python code through indirect prompt injection. Consequently, an attacker can execute arbitrary code on the operator's host without prior review, potentially compromising the system's integrity.
Affected Version(s)
LaVague 0 <= 0.2.35
