CVE-2026-39911Disclosure(hedera / guardian)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Hashgraph Guardian through version 3.5.1, fixed in commit 45fbe2f, contains an unsandboxed JavaScript execution vulnerability in the Custom Logic policy block worker that allows authenticated Standard Registry users to execute arbitrary code by passing user-supplied JavaScript expressions directly to the Node.js Function() constructor without isolation. Attackers can import native Node.js modules to read arbitrary files from the container filesystem, access process environment variables containing sensitive credentials such as RSA private keys, JWT signing keys, and API tokens, and forge valid authentication tokens for any user including administrators.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-668

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • guardian

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
guardian

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-09: 1Technical Details · 2026-04-09: 104-09
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-39911: HIGH] Hashgraph Guardian v3.5.0 has a critical JavaScript vulnerability allowing code execution by authenticated users, risking sensitive data exposure & unauthorized access.#cve,CVE-2026-39911,#cybersecurity https://cvefind.com/CVE-2026-39911

    Post summary

    A new high‑severity JavaScript vulnerability (RCE) has been disclosed in Hashgraph Guardian v3.5.0, allowing authenticated users to execute code and potentially expose sensitive data; no PoC, exploit, or patch information is included.

    0000034
    619 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphederaguardian---

Explore more