CVE-2026-40035
EUVD-2026-2077708.04.2026, 22:16
Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by default. The debug configuration value is read as a string and passed directly to app.run(), causing any non-empty string to evaluate truthy, allowing attackers to access the Werkzeug debugger and disclose sensitive information or achieve remote code execution.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ryandfir | unfurl | 𝑥 ≤ 2025.08 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration