← Browse

CVE-2026-42601

High

High exploit probability or critical severity with a known exploit.

CVSS base
9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
0.4%
34.4th percentile
CISA KEV
Not listed
Weakness / dates
CWE-88
Published 2026-05-09 · modified 2026-07-24

Description

ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6rc0 and prior, the /add/ endpoint (AddView in core/views.py) accepts a config JSON field that gets merged into the crawl config without validation. This config is exported as environment variables when archive plugins run, allowing injection of arbitrary tool arguments to achieve RCE. At time of publication, there are no publicly available patches.

Affected

archivebox

References

Official: NVD · CVE.org