CVE-2026-57586 | naranor agent-coderag up to 1.3.0 Gradle Sync code_rag/core/utils.py validate_path os command injection

SecurityVulns

A vulnerability has been found in naranor agent-coderag up to 1.3.0 and classified as critical. Affected by this vulnerability is the function validate_path of the file code_rag/core/utils.py of the component Gradle Sync. This manipulation causes os command injection.

The identification of this vulnerability is CVE-2026-57586. It is possible to initiate the attack remotely. There is no exploit available.

The affected component should be upgraded.VulDB Recent EntriesRead More