
CVE-2026-26215 - Unauthenticated RCE in manga-image-translator (9.3k stars) Two FastAPI endpoints call pickle.loads() on raw HTTP bodies. Auth exists but defaults to an empty string, which is falsy in Python, so the check never runs. First reported by sud0why in May 2025, auto-closed by a stale bot. Still unpatched. https://chocapikk.com/posts/2026/manga-image-translator-pickle-rce/
Post summary
The post discloses an unauthenticated RCE in manga-image-translator caused by insecure pickle.loads() usage; no patch or PoC is provided, and no active exploitation is reported.



