๐Ÿ” CVE Alert

CVE-2026-5532

MEDIUM 6.3

ScrapeGraphAI scrapegraph-ai GenerateCodeNode generate_code_node.py create_sandbox_and_execute os command injection

CVSS Score
6.3
EPSS Score
0.5%
EPSS Percentile
66th

A vulnerability was found in ScrapeGraphAI scrapegraph-ai up to 1.74.0. The affected element is the function create_sandbox_and_execute of the file scrapegraphai/nodes/generate_code_node.py of the component GenerateCodeNode Component. The manipulation results in os command injection. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CWE CWE-78 CWE-77
Vendor scrapegraphai
Product scrapegraph-ai
Published Apr 5, 2026
Last Updated Apr 6, 2026
Stay Ahead of the Next One

Get instant alerts for scrapegraphai scrapegraph-ai

Be the first to know when new medium vulnerabilities affecting scrapegraphai scrapegraph-ai are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

ScrapeGraphAI / scrapegraph-ai
1.0 1.1 1.2 1.3 1.4 1.5 1.6 1.7 1.8 1.9 1.10 1.11 1.12 1.13 1.14 1.15 1.16 1.17 1.18 1.19 1.20 1.21 1.22 1.23 1.24 1.25 1.26 1.27 1.28 1.29 1.30 1.31 1.32 1.33 1.34 1.35 1.36 1.37 1.38 1.39 1.40 1.41 1.42 1.43 1.44 1.45 1.46 1.47 1.48 1.49 1.50 1.51 1.52 1.53 1.54 1.55 1.56 1.57 1.58 1.59 1.60 1.61 1.62 1.63 1.64 1.65 1.66 1.67 1.68 1.69 1.70 1.71 1.72 1.73 1.74.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/355285 vuldb.com: https://vuldb.com/vuln/355285/cti vuldb.com: https://vuldb.com/submit/782169 github.com: https://github.com/August829/CVEP/issues/19

Credits

๐Ÿ” Yu Bao (VulDB User) VulDB CNA Team