Security Advisory

CVE-2026-69116

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-10 19:35:54
Last updated 2026-08-11 14:35:46
Assigner VulnCheck
CVSS score not scored
State PUBLISHED

Description

FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives. Attackers can inject malicious scripts through markdown sources or chat messages that execute in the Electron renderer process with access to Node.js APIs and the filesystem.