CVE-2026-61536 | masci banks up to 2.4.2 Completion completion.py importlib.import_module/getattr import_path code injection

SecurityVulns

A vulnerability was found in masci banks up to 2.4.2. It has been declared as problematic. Affected by this issue is the function importlib.import_module/getattr of the file src/banks/extensions/completion.py of the component Completion. Executing a manipulation of the argument import_path can lead to code injection.

This vulnerability is registered as CVE-2026-61536. It is possible to launch the attack remotely. No exploit is available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More