PT-2026-31677 · Unknown · Hashgraph Guardian

Christ Bouchuen

·

Published

2026-04-09

·

Updated

2026-05-01

·

CVE-2026-39911

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hashgraph Guardian versions through 3.5.0
Description Hashgraph Guardian through version 3.5.0 has an unsandboxed JavaScript execution issue in the Custom Logic policy block worker. Authenticated Standard Registry users can execute arbitrary code by supplying JavaScript expressions directly to the Node.js Function() constructor without isolation. This allows attackers to import native Node.js modules to read arbitrary files from the container filesystem, access process environment variables containing sensitive credentials such as RSA private keys, JWT signing keys, and API tokens, and forge valid authentication tokens for any user, including administrators.
Recommendations Update to a version later than 3.5.0.

Fix

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39911

Affected Products

Hashgraph Guardian