Remote Code Execution Vulnerability in LaVague by LaVague AI
CVE-2026-85694

9.2CRITICAL

Key Information:

Vendor

Lavague-ai

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-85694?

LaVague version 0.2.35 is vulnerable to remote code execution due to a flaw in the PythonFromMarkdownExtractor.extract_as_object method. This vulnerability enables attackers to utilize untrusted language model output from web content, allowing for the injection of malicious Python code through indirect prompt injection. Consequently, an attacker can execute arbitrary code on the operator's host without prior review, potentially compromising the system's integrity.

Affected Version(s)

LaVague 0 <= 0.2.35

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.