PT-2026-24842 · Undefined · Undefined

Zast.Ai

·

Published

2026-03-11

·

Updated

2026-03-11

·

CVE-2026-3955

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions elecV2P versions through 3.8.3
Description A security issue exists in elecV2P that allows for code injection. The runJSFile function within the wbjs.js file, part of the jsfile Endpoint component, is susceptible to manipulation. This manipulation can lead to remote code execution. The exploit for this issue has been publicly disclosed. The project maintainers were notified of the problem but have not yet responded.
Recommendations Versions through 3.8.3 should be updated when a fix becomes available. As a temporary workaround, consider disabling the runJSFile() function until a patch is available.

Exploit

Fix

Special Elements Injection

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-3955

Affected Products

Undefined