PT-2026-36547 · Nextlevelbuilder · Ui-Ux-Pro-Max-Skill

Yu-Bao

·

Published

2026-05-01

·

Updated

2026-05-01

·

CVE-2026-7595

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
A flaw has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this vulnerability is the function format plugins of the file .claude/skills/ui-styling/scripts/tailwind config gen.py of the component Tailwind Config Generator. This manipulation causes code injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet.

Exploit

Fix

Special Elements Injection

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-7595

Affected Products

Ui-Ux-Pro-Max-Skill