CVE-2026-7595Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this vulnerability is the function _format_plugins of the file .claude/skills/ui-styling/scripts/tailwind_config_gen.py of the component Tailwind Config Generator. This manipulation causes code injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-01); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-01: 2Mentions · 2026-05-02: 1Technical Details · 2026-05-01: 2Technical Details · 2026-05-02: 105-0105-02
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-012
Disclosure2
2026-05-021
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-7595 A flaw has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this vulnerability is the function _format_plugins of the file .claude/skills/ui-… https://www.cve.org/CVERecord?id=CVE-2026-7595

    Post summary

    The text reports the discovery of a flaw in nextlevelbuilder ui-ux-pro-max-skill up to version 2.5.0, specifically affecting the _format_plugins function in the .claude/skills/ui file. No evidence of exploitation or mitigation is provided.

    00010283
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7595 Code Injection in NextLevelBuilder UI-UX-Pro-Max-Skill Up To 2.5.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7595 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet announces CVE‑2026‑7595, describing a code injection vulnerability in NextLevelBuilder UI‑UX‑Pro‑Max‑Skill up to v2.5.0 and links to a details page, but offers no PoC, exploit code, or patch information.

    0000064
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7595 A flaw has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this vulnerability is the function _format_plugins of the file .claude/skills/ui-… https://www.cve.org/CVERecord?id=CVE-2026-7595 ----- Traducción: CVE-2026-7595 Se … http://infoflow.cloud`

    Post summary

    A new CVE-2026-7595 has been announced for nextlevelbuilder ui-ux-pro-max-skill, detailing a flaw in the _format_plugins function; no proof of concept, exploit code, patch, or evidence of active exploitation is provided.

    0000037
    75 followersView on X

Explore more