ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6rc0 and prior, the /add/ endpoint (AddView in core/views.py) accepts a config JSON field that gets merged into the crawl config without validation. This config is exported as environment variables when archive plugins run, allowing injection of arbitrary tool arguments to achieve RCE. At time of publication, there are no publicly available patches.
References
| Link | Resource |
|---|---|
| https://github.com/ArchiveBox/ArchiveBox/security/advisories/GHSA-3h23-7824-pj8r | Exploit Vendor Advisory |
| https://github.com/ArchiveBox/ArchiveBox/security/advisories/GHSA-3h23-7824-pj8r | Exploit Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
14 May 2026, 17:36
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:archivebox:archivebox:0.8.6:rc0:*:*:*:*:*:* cpe:2.3:a:archivebox:archivebox:*:*:*:*:*:*:*:* |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| References | () https://github.com/ArchiveBox/ArchiveBox/security/advisories/GHSA-3h23-7824-pj8r - Exploit, Vendor Advisory | |
| First Time |
Archivebox archivebox
Archivebox |
11 May 2026, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/ArchiveBox/ArchiveBox/security/advisories/GHSA-3h23-7824-pj8r - |
09 May 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-09 20:16
Updated : 2026-05-14 17:36
NVD link : CVE-2026-42601
Mitre link : CVE-2026-42601
CVE.ORG link : CVE-2026-42601
JSON object : View
Products Affected
archivebox
- archivebox
CWE
CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
