{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/lavague-0.2.35/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:lavague:lavague:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-85694"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["LaVague (0.2.35)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","injection","ai-security","supply-chain"],"_cs_type":"advisory","_cs_vendors":["LaVague"],"content_html":"\u003cp\u003eLaVague version 0.2.35 is vulnerable to remote code execution within its PythonFromMarkdownExtractor.extract_as_object function. This flaw exists due to the insecure evaluation of Python code that is extracted from language model (LLM) outputs. These outputs are derived from arbitrary web page content during automated browser interaction tasks. An attacker can craft a malicious web page containing instructions that trigger an indirect prompt injection attack. When a LaVague operator navigates to or processes this content, the LLM generates malicious Python code based on the injection, which is subsequently executed by the library on the operator's host system without validation or sandbox restrictions. This vulnerability poses a significant risk to users performing web automation or data extraction tasks.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary code execution on the host system running the LaVague automation agent. This can lead to full system compromise, data theft, or further lateral movement within the network, depending on the privileges of the service account or user running the LaVague framework.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all instances of LaVague (0.2.35) in the environment by scanning for package manifestations or process execution patterns.\u003c/li\u003e\n\u003cli\u003eReview internal automation pipelines and restrict the ability of the LaVague framework to process content from untrusted, public-facing web sources.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unauthorized Python execution or subprocess calls originating from the directory or service account where LaVague is deployed.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T15:32:05Z","date_published":"2026-09-04T15:32:05Z","id":"https://feed.craftedsignal.io/briefs/2026-09-lavague-rce/","summary":"LaVague version 0.2.35 contains a remote code execution vulnerability in the PythonFromMarkdownExtractor.extract_as_object function, allowing attackers to execute arbitrary code via indirect prompt injection.","title":"Remote Code Execution in LaVague via Indirect Prompt Injection","url":"https://feed.craftedsignal.io/briefs/2026-09-lavague-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - LaVague (0.2.35)","version":"https://jsonfeed.org/version/1.1"}