peter bassill · operator
$ cve CVE-2026-44262 JSON

CVE-2026-44262 EXPLOIT

9.4
CRITICAL · CVSS 3.1 · EPSS 3.9% (pctl 90)

Patch early

A public exploit exists.

Description

Scramble generates API documentation for Laravel project. From 0.13.2 to before 0.13.22, when documentation endpoints are publicly accessible and validation rules reference user-controlled input, request supplied data may be evaluated during documentation generation, leading to execution of arbitrary PHP code in the application context. This vulnerability is fixed in 0.13.22.

Scoring

CVSS9.4 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
EPSS3.87% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2026-05-12
Last modified2026-06-17

Public exploits

SourceTitleDate
exploit-dbscramble - Remote Code Execution2026-05-27

References

→ the Explorer  ·  watch your stack  ·  NVD