CVE-2026-21628
CRITICALFile Management Feature - Unauthenticated RCE
Title source: llmDescription
A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading to remote code execution.
Exploits (1)
References (1)
Scores
CVSS v3
9.8
EPSS
0.0025
EPSS Percentile
48.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-434
Status
published
Products (1)
templaza/astroid_framework
2.0.0 - 3.3.10
Published
Mar 05, 2026
Tracked Since
Mar 05, 2026