PT-2026-31677 · Unknown · Hashgraph Guardian
Christ Bouchuen
·
Published
2026-04-09
·
Updated
2026-05-01
·
CVE-2026-39911
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Hashgraph Guardian versions through 3.5.0
Description
Hashgraph Guardian through version 3.5.0 has an unsandboxed JavaScript execution issue in the Custom Logic policy block worker. Authenticated Standard Registry users can execute arbitrary code by supplying JavaScript expressions directly to the Node.js Function() constructor without isolation. This allows attackers to import native Node.js modules to read arbitrary files from the container filesystem, access process environment variables containing sensitive credentials such as RSA private keys, JWT signing keys, and API tokens, and forge valid authentication tokens for any user, including administrators.
Recommendations
Update to a version later than 3.5.0.
Fix
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hashgraph Guardian