Remote Code Execution Vulnerability in Manga Image Translator by Zyd-Dnys
⚠️ CVE-Referenzen:
CVE-2026-10042
Zyddnys - Manga-image-translator - CRITICAL - CVE-2026-10042.
Manga Image Translator is susceptible to a remote code execution flaw arising from unsafe deserialization of untrusted pickle data in its API server's shared mode. This vulnerability affects the /execute/{method_name} and /simple_execute/{method_name} endpoints, which allow the processing of attacker-supplied HTTP request bodies. By providing a specially crafted pickle payload, a remote attacker is capable of executing arbitrary code within the server process, leading to a complete compromise of the container, especially in default Docker deployments that run with root privileges.
Quelle: securityvulnerability.io