{"id":"CVE-2026-94588","published":"2026-09-21T21:17:22.343","lastModified":"2026-09-21T21:17:22.343","description":"In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This is caused by improper handling of user-supplied input passed to the underlying apt-get command when fetching package changelogs. It requires authentication but can be exploited in a CSRF-style attack.","cvssScore":4.4,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N","cwes":["CWE-88"],"vendors":[],"products":[],"references":[{"url":"https://forum.proxmox.com/threads/proxmox-mail-gateway-security-advisories.149333/post-831054","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows for argument injection in package changelog retrieval through improperly handled user input, posing a medium security risk.","exploitability":"Exploitation requires authentication and can be executed via CSRF, making it moderately difficult to exploit.","blast_radius":"If exploited, this vulnerability could lead to unauthorized changes or access to package information, impacting system integrity.","remediation":"Update Proxmox pmg-api to the latest version to address the argument injection vulnerability.","tags":["injection","auth-required","api","changelog"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:31:03.923Z"}}