
Security Advisory - CVE-2026-41512 We've disclosed and patched a critical vulnerability (CVSS 9.9) in 0DIN AI Scanner affecting versions 1.0.0 through 1.4.0. A JavaScript injection flaw in our PlaywrightService allowed an authenticated user to execute arbitrary code in the scanner's Node.js runtime via a crafted URL - breaking tenant isolation and exposing application secrets. Fixed in v1.4.1 - Please upgrade today. Huge thanks to @aussinfosec for the responsible disclosure and an outstanding technical write-up. This is what good security collaboration looks like and it's exactly why we open-sourced the scanner. Full advisory: https://github.com/0din-ai/ai-scanner/security/advisories/GHSA-r27j-xxgx-f5vr
Post summary
The advisory discloses a critical JavaScript injection vulnerability in 0DIN AI Scanner, provides patch details, and directs users to upgrade immediately.



