CVE-2026-3955

MEDIUM

elecV2P <= 3.8.3 - Remote Code Execution via runJSFile Function

Title source: llm
STIX 2.1

Description

A security vulnerability has been detected in elecV2P up to 3.8.3. Affected by this issue is the function runJSFile of the file source-code/elecV2P-master/webser/wbjs.js of the component jsfile Endpoint. Such manipulation leads to code injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

References (5)

Core 5
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.350385
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.350385
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.767277
Issue Tracking issue-tracking
https://github.com/elecV2/elecV2P/issues/194

Scores

CVSS v3 6.3
EPSS 0.0023
EPSS Percentile 13.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-74 CWE-94
Status published
Published Mar 11, 2026
Tracked Since Mar 12, 2026