← Back to search

CVE-2026-94588

4.4 MEDIUM

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
The flaw allows for argument injection in package changelog retrieval through improperly handled user input, posing a medium security risk.
Exploitability
Exploitation requires authentication and can be executed via CSRF, making it moderately difficult to exploit.
Blast radius
If exploited, this vulnerability could lead to unauthorized changes or access to package information, impacting system integrity.
Prioritized remediation
Update Proxmox pmg-api to the latest version to address the argument injection vulnerability.
injectionauth-requiredapichangelog

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This is caused by improper handling of user-supplied input passed to the underlying apt-get command when fetching package changelogs. It requires authentication but can be exploited in a CSRF-style attack.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N

Weaknesses

CWE-88

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.