CVE-2026-41512Disclosure(mozilla / 0din_scanner)

HIGHCVSS 9.9 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch mozilla 0din_scanner systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

ai-scanner is an AI model safety scanner built on NVIDIA garak. From version 1.0.0 to before version 1.4.1, there is a remote code execution vulnerability via JavaScript injection in `BrowserAutomation::PlaywrightService`. This issue has been patched in version 1.4.1.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 0din_scanner

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 8 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 3 mentions (2026-05-12); latest day: 2
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
0din_scanner

Deep dive

Activity timeline8 mentions / 4d
01223Mentions · 2026-05-08: 2Mentions · 2026-05-12: 3Mentions · 2026-05-13: 1Mentions · 2026-05-17: 2PoC Mentioned / Linked · 2026-05-12: 1Exploit Tool / Code · 2026-05-12: 1Active Exploitation · 2026-05-12: 1Patch / Workaround · 2026-05-08: 1Patch / Workaround · 2026-05-13: 1Patch / Workaround · 2026-05-17: 2Technical Details · 2026-05-08: 2Technical Details · 2026-05-12: 3Technical Details · 2026-05-13: 1Technical Details · 2026-05-17: 205-0805-1205-1305-17
Signal classification4 categories
Disclosure
337.5%
Patch
337.5%
Exploit
112.5%
General
112.5%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-082
Disclosure2
2026-05-123
Disclosure1Exploit1General1
2026-05-131
Patch1
2026-05-172
Patch2
Full discourse8 posts
  • 0DIN.ai@0dinai
    Patch

    Security Advisory - CVE-2026-41512 We've disclosed and patched a critical vulnerability (CVSS 9.9) in 0DIN AI Scanner affecting versions 1.0.0 through 1.4.0. A JavaScript injection flaw in our PlaywrightService allowed an authenticated user to execute arbitrary code in the scanner's Node.js runtime via a crafted URL - breaking tenant isolation and exposing application secrets. Fixed in v1.4.1 - Please upgrade today. Huge thanks to @aussinfosec for the responsible disclosure and an outstanding technical write-up. This is what good security collaboration looks like and it's exactly why we open-sourced the scanner. Full advisory: https://github.com/0din-ai/ai-scanner/security/advisories/GHSA-r27j-xxgx-f5vr

    Post summary

    The advisory discloses a critical JavaScript injection vulnerability in 0DIN AI Scanner, provides patch details, and directs users to upgrade immediately.

    0902041.4K
    1.5K followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    CVE-2026-41512: Security Advisory - CVE-2026-41512 We've disclosed and patched a critical vulnerability (CVSS 9.9) in 0DIN AI Scanner affecting versions 1.0.0 through 1.4.0. A JavaScript injection flaw in our PlaywrightService allowed an authenticated user to execute…

    Post summary

    The advisory confirms a CVE-2026-41512 JavaScript injection flaw, details its severity, and announces a patch, with no evidence of exploitation or PoC.

    1000061
    226 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Source: X search for CVE-2026 critical Posted: 2026-05-13T15:36:12.000Z Likes: 15 Security Advisory - CVE-2026-41512 We've disclosed and patched a critical vulnerability (CVSS 9.9) in 0DIN AI Scanner affecting versions 1.0.0 through 1.4.0.

    Post summary

    The advisory announces the disclosure and patch of CVE-2026-41512 in 0DIN AI Scanner, noting a CVSS score of 9.9 and affected versions 1.0.0–1.4.0.

    1000062
    226 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVSS 9.9 CRITICAL · CVE-2026-41512 · 9.9 → 1.0.0 CVE: CVE-2026-41512 CVSS: 9.9 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces CVE-2026-41512 as a critical vulnerability with a CVSS 9.9 score but does not provide any PoC, exploitation details, or patch information.

    1000029
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE: CVE-2026-41512 CVSS: 9.9 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory ai-scanner is an AI model safety scanner built on NVIDIA garak.

    Post summary

    The passage lists basic vulnerability details and severity but lacks any exploit, PoC, or mitigation information.

    1000031
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Exploit

    https://lyrie.ai/research/research/cve-2026-41512-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The advisory for CVE-2026-41512 indicates an available PoC, exploit details, and hints at active use in the wild, but it does not yet provide a patch or remediation information.

    0000016
    210 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41512 ai-scanner is an AI model safety scanner built on NVIDIA garak. From version 1.0.0 to before version 1.4.1, there is a remote code execution vulnerability via JavaScr… https://www.cve.org/CVERecord?id=CVE-2026-41512

    Post summary

    The text announces a remote code execution vulnerability in ai-scanner (versions 1.0.0 to before 1.4.1) affecting JavaScript, without providing a PoC, exploit code, or patch information.

    00000101
    57.5K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-41512 ai-scanner is an AI model safety scanner built on NVIDIA garak. From version 1.0.0 to before version 1.4.1, there is a … CVSS 9.9 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-41512 #NVIDIA #CyberSecurity #InfoSec

    Post summary

    The text announces the critical CVE‑2026‑41512 with a CVSS score of 9.9, notes that no patch is available, and links to a detailed analysis.

    0000036
    516 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmozilla0din_scanner---

Explore more