PT-2026-24896 · Npm+2 · @Whyour/Qinglong+1
A7Cc
·
Published
2026-03-11
·
Updated
2026-03-12
·
CVE-2026-3965
CVSS v2.0
6.5
Medium
| AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
whyour qinglong versions through 2.20.1
Description
A security issue has been identified in whyour qinglong. The problem resides in an unknown function within the
back/loaders/express.ts file of the API Interface component. Manipulation of the command argument can bypass a protection mechanism. This issue can be exploited remotely, and a public exploit is available.API Endpoint: Not specified.
Vulnerable Parameter:
commandRecommendations
Versions prior to 2.20.2 should be upgraded to version 2.20.2 to address this issue.
Exploit
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Whyour/Qinglong
Qinglong