Metrics
Affected Vendors & Products
Fri, 29 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zyddnys
Zyddnys manga-image-translator |
|
| Vendors & Products |
Zyddnys
Zyddnys manga-image-translator |
Fri, 29 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deserialization of untrusted pickle data in the share.py module, where the /execute/{method_name} and /simple_execute/{method_name} endpoints deserialize attacker-controlled HTTP request bodies using pickle.loads(). A remote attacker can supply a crafted pickle payload to these endpoints to execute arbitrary code in the server process, resulting in full container compromise when running in the default Docker deployment as root. | |
| Title | manga-image-translator RCE via Unsafe Pickle Deserialization in Share Model | |
| Weaknesses | CWE-502 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-29T14:29:21.547Z
Reserved: 2026-05-28T20:43:23.374Z
Link: CVE-2026-10042
Updated: 2026-05-29T15:03:55.546Z
Status : Received
Published: 2026-05-29T15:16:21.843
Modified: 2026-05-29T15:16:21.843
Link: CVE-2026-10042
No data.
OpenCVE Enrichment
Updated: 2026-05-29T15:30:03Z