


Perceptive Security
SOC/SIEM Consultancy

A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an unknown function of the file /code of the …
Published:
3 augustus 2026 om 22:00:00
Alert date:
4 augustus 2026 om 16:02:00
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
A code injection vulnerability has been identified in vibesurf-ai VibeSurf up to commit cd6e519d507cdd4d63061300bf60fb176e1f57e0. The flaw resides in an unknown function within the /code file of the Python Validation Handler component. An attacker can manipulate input to trigger code injection remotely. The product uses a rolling release model, making specific version tracking difficult. The vulnerability is remotely exploitable, raising the severity of the issue. No patch or version fix details are available due to the continuous delivery approach. The vendor was notified prior to public disclosure but did not respond. This lack of vendor response leaves users without an official fix or mitigation guidance. The vulnerability is tracked as CVE-2026-18770 and is listed on NVD.
Technical details
Mitigation steps:
Affected products:
vibesurf-ai VibeSurf
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-18770
https://asciinema.org/a/1230301
https://vuldb.com/cve/CVE-2026-18770
https://vuldb.com/submit/856224
https://vuldb.com/vuln/385776
https://vuldb.com/vuln/385776/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
