Arbitrary Argument Injection Affecting archivebox package, versions [0,0.9.31rc1)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.06% (20th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-ARCHIVEBOX-16428729
  • published6 May 2026
  • disclosed4 May 2026
  • creditq1uf3ng

Introduced: 4 May 2026

NewCVE-2026-42601  (opens in a new tab)
CWE-88  (opens in a new tab)

How to fix?

Upgrade archivebox to version 0.9.31rc1 or higher.

Overview

archivebox is a The self-hosted internet archive.

Affected versions of this package are vulnerable to Arbitrary Argument Injection via the AddView class. An attacker can execute arbitrary code on the server by submitting specially crafted configuration overrides to the /add/ endpoint, which are merged without validation and exported as environment variables to downstream plugins.

Note: This is only exploitable if the PUBLIC_ADD_VIEW setting is enabled, allowing unauthenticated access to the endpoint.

CVSS Base Scores

version 4.0
version 3.1