CVE-2026-4500Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in bagofwords1 bagofwords up to 0.0.297. This impacts the function generate_df of the file backend/app/ai/code_execution/code_execution.py. Such manipulation leads to injection. The attack may be launched remotely. The exploit is publicly available and might be used. Upgrading to version 0.0.298 will fix this issue. The name of the patch is 47b20bcda31264635faff7f6b1c8095abe1861c6. It is recommended to upgrade the affected component.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-707

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-03-21)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-20: 1Mentions · 2026-03-21: 2Technical Details · 2026-03-21: 103-2003-21
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-201
General1
2026-03-212
Disclosure2
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-4500 A vulnerability was identified in bagofwords1 bagofwords up to 0.0.297. This impacts the function generate_df of the file backend/app/ai/code_execution/code_execution.p… https://www.cve.org/CVERecord?id=CVE-2026-4500 ----- Traducción: CVE-2026-4500 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑4500, identifies the affected function in bagofwords, and links to the CVE record, but offers no evidence of exploitation, PoC, or remediation.

    0000031
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4500 A vulnerability was identified in bagofwords1 bagofwords up to 0.0.297. This impacts the function generate_df of the file backend/app/ai/code_execution/code_execution.p… https://www.cve.org/CVERecord?id=CVE-2026-4500

    Post summary

    The text announces CVE-2026-4500 in the bagofwords package (up to 0.0.297), detailing that the generate_df function is vulnerable.

    00000256
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4500 - bagofwords1 bagofwords code_execution.py generate_df injection Intel Report: https://ift.tt/XmM0Z89

    Post summary

    The post only references CVE-2026-4500 and an Intel report, with no actionable details on exploitation, mitigation or confirmation of the vulnerability.

    0000066
    334 followersView on X

Explore more