{"id":"CVE-2026-88405","published":"2026-09-21T21:17:14.620","lastModified":"2026-09-24T13:17:12.097","description":"A remote code execution (RCE) vulnerability in the RemoteRegisterFunctionService function (/remote/remote-register-function.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-94"],"vendors":[],"products":[],"references":[{"url":"https://github.com/czx1111/cve/issues/9","tags":[]},{"url":"https://github.com/czx1111/cve/issues/9","tags":[]}],"exploitRefs":[{"url":"https://github.com/czx1111/cve/issues/9","tags":[]},{"url":"https://github.com/czx1111/cve/issues/9","tags":[]}],"hasPoc":true,"ai":{"summary":"The vulnerability allows attackers to execute arbitrary code via a crafted payload, posing a critical risk due to remote code execution capabilities.","exploitability":"Exploitation is relatively straightforward given the remote code execution vector, requiring a crafted payload to be sent to the affected service.","blast_radius":"If exploited, the impact could be severe, potentially leading to full system compromise and data loss.","remediation":"Upgrade to Univer v1.0.0-alpha.3 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","web","remote-code-execution"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:59:25.383Z"}}