CVE-2026-40035
Critical · CVSS 9.1- CVSS
- 9.1
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-489
Description
Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by default. The debug configuration value is read as a string and passed directly to app.run(), causing any non-empty string to evaluate truthy, allowing attackers to access the Werkzeug debugger and disclose sensitive information or achieve remote code execution.
Affected packages
| PyPI | dfir-unfurl | 0 → ∞ |
References
Status: profiled · ingested 2026-07-25T00:00:18.000Z