CVE-2026-3992Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A weakness has been identified in CodeGenieApp serverless-express up to 4.17.1. This affects an unknown part of the file utils/dynamodb.ts of the component Users Endpoint. This manipulation of the argument filter causes injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-707

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-12: 2Technical Details · 2026-03-12: 203-12
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3992 - CodeGenieApp serverless-express Users Endpoint dynamodb.ts injection Intel Report: https://ift.tt/JGHLteW

    Post summary

    The tweet announces a new vulnerability, CVE‑2026‑3992, in CodeGenieApp’s serverless‑express Users Endpoint involving a DynamoDB injection. No exploit or mitigation details are shared.

    0000042
    342 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3992 A weakness has been identified in CodeGenieApp serverless-express up to 4.17.1. This affects an unknown part of the file utils/dynamodb.ts of the component Users Endpoi… https://www.cve.org/CVERecord?id=CVE-2026-3992

    Post summary

    The post announces CVE‑2026‑3992, a weakness in CodeGenieApp serverless‑express up to v4.17.1 affecting the utils/dynamodb.ts file, with no mention of exploits, patches, or active use.

    00000112
    56.7K followersView on X

Explore more