Critical severity9.8NVD Advisory· Published Jan 9, 2026· Updated Jun 17, 2026
CVE-2026-22584
CVE-2026-22584
Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Executable Code in Non-Executable Files.This issue affects Uni2TS: through 1.2.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
uni2tsPyPI | < 2.0.0 | 2.0.0 |
Affected products
3cpe:2.3:a:salesforce:uni2ts:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:salesforce:uni2ts:*:*:*:*:*:*:*:*range: <2.0.0
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-7x99-8x99-xc54ghsaADVISORY
- help.salesforce.com/s/articleViewnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-22584ghsaADVISORY
- github.com/SalesforceAIResearch/uni2ts/commit/7f2d51dd729de018f0f22504f39a8475c6fed1c4ghsaWEB
- github.com/SalesforceAIResearch/uni2ts/pull/218ghsaWEB
- github.com/SalesforceAIResearch/uni2ts/releases/tag/2.0.0ghsaWEB
News mentions
0No linked articles in our index yet.