7.8
CVE-2026-18286
- EPSS -
- Veröffentlicht 20.08.2026 16:20:29
- Zuletzt bearbeitet 20.08.2026 17:17:25
- CVE-Watchlists
- Unerledigt
Aeon load_human_activity_segmentation_datasets Code Injection Remote Code Execution Vulnerability
Aeon load_human_activity_segmentation_datasets Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aeon. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the load_human_activity_segmentation_datasets method. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29160.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstelleraeon
≫
Produkt
aeon
Default Statusunknown
Version
1.3.0
Status
affected
VulnDex Vulnerability Enrichment
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Trend Micro | 7.8 | 1.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-94 Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
https://github.com/aeon-toolkit/aeon/commit/751918052c0cce266b4f7cd4b084408526efc015
https://www.zerodayinitiative.com/advisories/ZDI-26-469/