VYPR
Critical severity9.8GHSA Advisory· Published May 9, 2026· Updated May 14, 2026

CVE-2026-42601

CVE-2026-42601

Description

ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6rc0 and prior, the /add/ endpoint (AddView in core/views.py) accepts a config JSON field that gets merged into the crawl config without validation. This config is exported as environment variables when archive plugins run, allowing injection of arbitrary tool arguments to achieve RCE. At time of publication, there are no publicly available patches.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
archiveboxPyPI
<= 0.8.6rc0

Affected products

4
  • ArchiveBox/ArchiveboxGHSA3 versions
    <= 0.8.6rc0+ 2 more
    • (no CPE)range: <= 0.8.6rc0
    • cpe:2.3:a:archivebox:archivebox:*:*:*:*:*:*:*:*range: <0.8.6
    • cpe:2.3:a:archivebox:archivebox:0.8.6:rc0:*:*:*:*:*:*
  • ghsa-coords
    Range: <= 0.8.6rc0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.