LOWVulnerability

CVE-2026-76241

stigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration flag without a second explicit acknowledgment. If that setting is carried into an environment where plugin directories are writable by less-trusted users, unsigned (potentially malicious) plugin code could be loaded and executed, resulting in arbitrary code execution. Fixed in 0.9.0a2, which requires a second explicit acknowledgment to disable signature enforcement.

Properties

epss_score
0.00088
cve_id
CVE-2026-76241
signal_observed_at
2026-09-11T21:54:11+00:00
published_at
2026-08-19T14:17:56.430
last_modified
2026-09-11T18:28:15.520
epss_percentile
0.00444

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Download of Code Without Integrity Check

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-76241 — Ninja Signal Threat Intelligence | Ninja Signal