What is CVE-2026-69116?
FlyEnv versions before 4.18.0 fail to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives, allowing attackers to inject malicious scripts that execute in the Electron renderer process with access to Node.js APIs and the filesystem. The vulnerability can be exploited through markdown sources or chat messages. Users should upgrade to FlyEnv 4.18.0 or later to mitigate the risk.
Azərbaycanca: FlyEnv 4.18.0-dan əvvəlki versiyalarda, markdown renderləmə və AI söhbət məzmununda HTML sanitizasiyası edilmədiyi üçün Electron renderer prosesinə Node.js API-ləri və fayl sisteminə girişlə zərərli skriptlər yeridilə bilər. Bu boşluq hücumçulara markdown mənbələri və ya söhbət mesajları vasitəsilə Vue `v-html` direktivlərini istismar etməyə imkan verir. Təhlükəsizlik üçün dərhal FlyEnv-i 4.18.0 və ya daha yüksək versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of FlyEnv are vulnerable to CVE-2026-69116?
All versions of FlyEnv before 4.18.0 are vulnerable.
What action should be taken to mitigate CVE-2026-69116?
Upgrade FlyEnv to version 4.18.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.