CVE-2026-7191Disclosure

LOWCVSS 8.6 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Improper use of the static-eval npm package in the open source solution qnabot-on-aws versions 7.2.4 and earlier may allow an authenticated administrator to execute arbitrary code within the fulfillment Lambda execution context by injecting a crafted conditional chaining expression via the Content Designer interface, which bypasses the intended expression sandbox through JavaScript prototype manipulation. This may grant direct access to backend resources (Lambda environment variables, OpenSearch indices, S3 objects, DynamoDB tables) that are not exposed through normal administrative interfaces. We recommend you upgrade to version 7.3.0 or above.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-27); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-27: 2Mentions · 2026-04-30: 1PoC Mentioned / Linked · 2026-04-30: 1Technical Details · 2026-04-27: 2Technical Details · 2026-04-30: 104-2704-30
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-272
Disclosure1General1
2026-04-301
Disclosure1
Full discourse3 posts
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-7191 Improper use of the static-eval npm package in the open source solution qnabot-on-aws versions 7.2.4 and earlier may al… CVSS 7.2 Full analysis → https://sec.kaitan.id/cves/CVE-2026-7191 #AWS #CyberSecurity #InfoSec

    Post summary

    The post announces CVE‑2026‑7191, a high‑severity flaw in qnabot‑on‑aws caused by improper use of the static‑eval npm package (CVSS 7.2), but offers no PoC, exploit, or patch information.

    0001087
    141 followersView on X
  • Eyal Estrin ☁️@eyalestrin
    Disclosure

    CVE-2026-7191- Arbitrary Code Execution via Sandbox Bypass in QnABot on AWS http://dlvr.it/TSJF8Z #patchmanagement

    Post summary

    CVE-2026-7191 involves arbitrary code execution through a sandbox bypass in QnABot on AWS. No active exploitation or patch details are asserted in the text.

    0000024
    2.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-7191 Arbitrary Code Execution in QnaBot-on-AWS via Static-Eval Prototyp... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7191 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet merely announces CVE‑2026‑7191 as an arbitrary code execution vulnerability in QnaBot‑on‑AWS and directs users to a link for further details, without providing exploitation or patch information.

    0000036
    4.0K followersView on X

Explore more