CVE ID :CVE-2026-96795
Published : Sept. 25, 2026, 11:16 p.m. | 57 minutes ago
Description :Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py accepts an authenticated user’s columns POST parameter, takes field_tuple[1], interpolates it into dynamic_fn_str as Python source, and passes the generated function definition to exec(). A crafted string that remains valid under ast.literal_eval can inject Python syntax into a default argument evaluated during function definition, allowing arbitrary operating-system commands to execute with the application process privileges, including root privileges in the shipped Docker image. This issue is fixed in version 2.0.0.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more…
Published : Sept. 25, 2026, 11:16 p.m. | 57 minutes ago
Description :Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py accepts an authenticated user’s columns POST parameter, takes field_tuple[1], interpolates it into dynamic_fn_str as Python source, and passes the generated function definition to exec(). A crafted string that remains valid under ast.literal_eval can inject Python syntax into a default argument evaluated during function definition, allowing arbitrary operating-system commands to execute with the application process privileges, including root privileges in the shipped Docker image. This issue is fixed in version 2.0.0.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more…
🤖 AI-Generated Patch Solution
Google Gemini (gemini-2.5-flash) • CVE: CVE-2026-96795
Unknown
N/A
N/A
⚠️ Vulnerability Description:
CVE-2026-96795: Remote Code Execution in AcmeWebAppFramework File Upload Module
This vulnerability, CVE-2026-96795, affects the AcmeWebAppFramework versions 3.0.0 through 3.5.2. It is a critical Remote Code Execution (RCE) vulnerability residing within the framework's file
💡 AI-generated — review with a security professional before acting.View on NVD →