CVE-2026-5532Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 6 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in ScrapeGraphAI scrapegraph-ai up to 1.74.0. The affected element is the function create_sandbox_and_execute of the file scrapegraphai/nodes/generate_code_node.py of the component GenerateCodeNode Component. The manipulation results in os command injection. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 6 total mentions across 1 day

Deep dive

Activity timeline6 mentions / 1d
02356Mentions · 2026-04-05: 6Patch / Workaround · 2026-04-05: 2Technical Details · 2026-04-05: 404-05
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
General
116.7%
Referenced assets5 URLs
Full discourse6 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    🔥 CVE-2026-5532: ScrapeGraphAI scrapegraph-ai <=1.74.0 RCE via remote OS command injection. Patch now! https://www.tenable.com/cve/CVE-2026-5532

    Post summary

    The tweet announces the CVE-2026-5532 vulnerability in ScrapeGraphAI (≤1.74.0), a remote OS command injection leading to RCE, and informs that a patch is now available.

    1003029
    1.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5532 A vulnerability was found in ScrapeGraphAI scrapegraph-ai up to 1.74.0. The affected element is the function create_sandbox_and_execute of the file scrapegraphai/nodes/… https://www.cve.org/CVERecord?id=CVE-2026-5532

    Post summary

    The post announces the discovery of CVE-2026-5532 in ScrapeGraphAI up to version 1.74.0, specifying the vulnerable function but providing no PoC, exploit, patch, or evidence of active exploitation.

    00010384
    56.8K followersView on X
  • NerdieNews@NewsNerdie
    Patch

    CVE-2026-5532 in ScrapeGraphAI's GenerateCodeNode allows remote OS command injection, putting systems at risk. This vulnerability can lead to full system compromise. Patch now to prevent exploitation. #CyberSecurity #InfoSec https://t.co/gs88PhNxdA

    Post summary

    The tweet alerts about a remote OS command injection flaw in ScrapeGraphAI’s GenerateCodeNode and urges users to apply the available patch to avoid full system compromise.

    0000038
    53 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-5532 📊 Severity: 6.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5532 #CVE-2026-5532 #CVE #Medium #CyberSecurity #InfoSec https://t.co/o6vGwM279V

    Post summary

    This tweet simply announces the existence of CVE-2026-5532 with a 6.3 severity rating and links to the NVD entry.

    0000032
    121 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5532 A vulnerability was found in ScrapeGraphAI scrapegraph-ai up to 1.74.0. The affected element is the function create_sandbox_and_execute of the file scrapegraphai/nodes/… https://www.cve.org/CVERecord?id=CVE-2026-5532 ----- Traducción: CVE-2026-5532 Se … http://infoflow.cloud`

    Post summary

    The tweet announces the discovery of CVE‑2026‑5532 in ScrapeGraphAI up to version 1.74.0, naming the vulnerable function, but it offers no Proof of Concept, exploit details, patch information, or evidence of active exploitation.

    0000033
    63 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5532 - ScrapeGraphAI scrapegraph-ai GenerateCodeNode generate_code_node.py create_sandbox_and_execute os command injection Intel Report: https://ift.tt/XR6elS4

    Post summary

    The alert announces CVE-2026-5532 as an OS command injection vulnerability in ScrapeGraphAI’s GenerateCodeNode, providing technical details but no proof of concept, patch, or evidence of current exploitation.

    0000038
    281 followersView on X

Explore more