Description
FinRobot v1.0.0 is vulnerable to Code Injection in CodingUtils.modify_code.
Published: 2026-10-02
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

FinRobot version 1.0.0 contains a code injection flaw in the CodingUtils.modify_code function. The flaw allows a malicious actor to inject and execute arbitrary code at runtime, giving full control over the application and its underlying system. This results in compromise of confidentiality, integrity and availability of the asset running the application.

Affected Systems

The vulnerability is present in the FinRobot v1.0.0 product. No vendor or product variants are listed, indicating that only this specific release is affected.

Risk and Exploitability

Without an EPSS score or CVSS rating, the exact exploitation probability and severity are not quantified, but code injection is a well‑known high‑risk weakness. The vulnerability is not listed in CISA’s KEV catalog, so no known exploits have been reported yet. However, the attack vector is likely local or remote if the application is exposed to untrusted input. An attacker would need to supply crafted input to the modify_code function; once triggered, code runs with the application’s privileges.

Generated by OpenCVE AI on October 2, 2026 at 17:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade FinRobot to a version where the CodingUtils.modify_code issue is fixed.
  • If an upgrade is unavailable, disable or remove usage of CodingUtils.modify_code from the codebase.
  • Validate or sanitize all input passed to modify_code, restricting it to a predefined whitelist of safe code snippets.
  • Implement logging and monitoring for suspicious modification attempts to detect potential exploitation attempts.

Generated by OpenCVE AI on October 2, 2026 at 17:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Title Code Injection in FinRobot's CodingUtils.modify_code
Weaknesses CWE-74

Fri, 02 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Description FinRobot v1.0.0 is vulnerable to Code Injection in CodingUtils.modify_code.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-02T15:46:16.590Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51917

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T16:16:50.877

Modified: 2026-10-02T18:47:49.947

Link: CVE-2026-51917

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T17:45:17Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')