CVE 9.3 CRITICAL

ArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddView_CVE-2026-42601

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6rc0 and prior, the /add/ endpoint (AddView in core/views.py) accepts a config JSON field that gets merged into the crawl config without validation. This config is exported as environment variables when archive plugins run, allowing injection of arbitrary tool arguments to achieve RCE. At time of publication, there are no publicly available patches.

Basic Information

ID CVE-2026-42601
Source GitHub_M
Published May 9, 2026 at 19:29

Affected Product

Vendor ArchiveBox
Product ArchiveBox
Version <= 0.8.6rc0
Affected Versions ArchiveBox ArchiveBox <= 0.8.6rc0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.