CVE-2026-42796: Arelle Webserver Plugins From Request Query Rce
An HTTP request query parameter is assigned directly to options.plugins without validating that it is not a remote URL. Arelle's plugin manager loads `http(s)://` (and `+`/`-`/`~` prefixed) entries as remote Python modules to download and execute, which becomes an unauthenticated remote code execution vector when exposed over HTTP (CVE-2026-42796, CWE-306).
greprules fetch cve-2026-42796-arelle-webserver-plugins-from-request-query-rce --engine opengrepDescription
An HTTP request query parameter is assigned directly to options.plugins without validating that it is not a remote URL. Arelle's plugin manager loads `http(s)://` (and `+`/`-`/`~` prefixed) entries as remote Python modules to download and execute, which becomes an unauthenticated remote code execution vector when exposed over HTTP (CVE-2026-42796, CWE-306).
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.