PT-2026-24927 · Codegenieapp · Serverless-Express
Ana10Gy
+1
·
Published
2026-03-12
·
Updated
2026-03-12
·
CVE-2026-3992
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
CodeGenieApp serverless-express versions through 4.17.1
Description
A weakness exists in CodeGenieApp serverless-express. This issue affects an unknown part of the
utils/dynamodb.ts file within the Users Endpoint component. Manipulation of the filter argument can lead to injection. The attack can be initiated remotely, and an exploit has been publicly released. The vendor was contacted regarding this disclosure but did not respond.Recommendations
Versions prior to 4.17.1 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Neutralization
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Serverless-Express