HarborGuard / CVE
Back to search
CRITICALCVE-2026-44262Published Modified CNA GitHub_M

CVE-2026-44262: Scramble: Remote code execution via evaluation of user-controlled input in validation rules

Scramble generates API documentation for Laravel project. From 0.13.2 to before 0.13.22, when documentation endpoints are publicly accessible and validation rules reference user-controlled input, request supplied data may be evaluated during documentation generation, leading to execution of arbitrary PHP code in the application context. This vulnerability is fixed in 0.13.22.

Metrics

CVSS v3.1
9.4
Severity
CRITICAL
Fixed in
Affected Products
1
Affected packages
  • dedoc / scramble
    >= 0.13.2, < 0.13.22
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L