← Back to browse · API

CVE-2026-21628

Severity
CRITICAL
CVSS
10.0
EPSS
0.00471
Risk score
40.16
CISA KEV
No
PoC
Yes
Published
2026-03-05
Modified
2026-03-05
First seen
2026-08-07
Aliases
EUVD-2026-9816, GHSA-9G4R-RVQ7-7XRQ
Products
astroidframe.work:Astroid Template Framework 2.0.0-3.3.10
Sources
euvd EUVD-2026-9816
packetstorm 123a4ae0b0904fbec6fd1c90|CVE-2026-21628

Description

A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading to remote code execution.

References