PT-2026-36547 · Nextlevelbuilder · Ui-Ux-Pro-Max-Skill
Yu-Bao
·
Published
2026-05-01
·
Updated
2026-05-01
·
CVE-2026-7595
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
A flaw has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this vulnerability is the function format plugins of the file .claude/skills/ui-styling/scripts/tailwind config gen.py of the component Tailwind Config Generator. This manipulation causes code injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet.
Exploit
Fix
Special Elements Injection
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ui-Ux-Pro-Max-Skill