CVE-2026-108944 | repository RAE up to a4d18c4db766419cbe7cb8c02cd9f7ceb0ec9041 Config-Driven Model Instantiation src/utils/model_utils.py get_obj_from_str target code injection (Issue 82)
A vulnerability, which was classified as problematic, was found in repository RAE up to a4d18c4db766419cbe7cb8c02cd9f7ceb0ec9041. Affected by this vulnerability is the function get_obj_from_str of the file src/utils/model_utils.py of the component Config-Driven Model Instantiation. Such manipulation of the argument Target leads to code injection.
This vulnerability is listed as CVE-2026-108944. The attack must be carried out locally. There is no available exploit.
This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More