PT-2026-20786 · Node.Js+1 · Node.Js+1

Tygo-Van-Den-Hurk

·

Publicado

2026-02-18

·

Atualizado

2026-03-02

·

CVE-2026-26974

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Slyde versions 0.0.4 and below
Description Slyde is a program used to create animated presentations from XML. A remote code execution issue exists because Node.js automatically imports **/*.plugin.{js,mjs} files, including those from node modules. This allows any malicious package containing a .plugin.js file to execute arbitrary code when installed or required. All projects utilizing this loading behavior are affected, particularly those installing packages from untrusted sources.
Recommendations Upgrade to version 0.0.5 or later. Audit and restrict which packages are installed in node modules.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-26974
GHSA-W7H5-55JG-CQ2F

Produtos afetados

Node.Js
Slyde