CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-40035

Critical · CVSS 9.1
CVSS
9.1
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-489

Description

Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by default. The debug configuration value is read as a string and passed directly to app.run(), causing any non-empty string to evaluate truthy, allowing attackers to access the Werkzeug debugger and disclose sensitive information or achieve remote code execution.

Affected packages

PyPI dfir-unfurl 0 → ∞

References

Status: profiled · ingested 2026-07-25T00:00:18.000Z