CVE-2026-5011

MEDIUM

elecV2 elecV2P JSON webhook runJSFile code injection

Title source: cna
STIX 2.1

Description

A vulnerability was detected in elecV2 elecV2P up to 3.8.3. This vulnerability affects the function runJSFile of the file /webhook of the component JSON Parser. Performing a manipulation of the argument rawcode results in code injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

References (5)

Core 5
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-353896 | elecV2 elecV2P JSON webhook runJSFile code injection
https://vuldb.com/vuln/353896
Signature, Permissions Required signature permissions-required
VDB-353896 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/353896/cti
Third Party Advisory third-party-advisory
Submit #779173 | elecV2 <=3.8.3 Remote Code Execution
https://vuldb.com/submit/779173
Exploit exploit issue-tracking
https://github.com/elecV2/elecV2P/issues/195

Scores

CVSS v3 6.3
EPSS 0.0023
EPSS Percentile 13.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-74 CWE-94
Status published
Products (4)
elecV2/elecV2P 3.8.0
elecV2/elecV2P 3.8.1
elecV2/elecV2P 3.8.2
elecV2/elecV2P 3.8.3
Published Mar 28, 2026
Tracked Since Mar 29, 2026