← Browse

CVE-2026-88937

Medium

Elevated severity or exploit probability.

CVSS base
8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
0.7%
49.1th percentile
CISA KEV
Not listed
Weakness / dates
CWE-22
Published 2026-09-10 · modified 2026-09-10

Description

knowns through 0.33.0 fails to properly validate template destination paths in the code generation template engine, allowing attackers to read and write arbitrary files outside the project root. Attackers can supply malicious templates that traverse directories to overwrite shell profiles, steal credentials, or achieve persistent code execution on victim systems.

References

Official: NVD · CVE.org