Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 11 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mozilla
Mozilla 0din Scanner |
|
| CPEs | cpe:2.3:a:mozilla:0din_scanner:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mozilla
Mozilla 0din Scanner |
Sun, 10 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
0din-ai
0din-ai ai-scanner |
|
| Vendors & Products |
0din-ai
0din-ai ai-scanner |
Fri, 08 May 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 08 May 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ai-scanner is an AI model safety scanner built on NVIDIA garak. From version 1.0.0 to before version 1.4.1, there is a remote code execution vulnerability via JavaScript injection in `BrowserAutomation::PlaywrightService`. This issue has been patched in version 1.4.1. | |
| Title | Remote code execution via JavaScript injection in `BrowserAutomation::PlaywrightService` | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-08T21:27:16.514Z
Reserved: 2026-04-20T18:18:50.681Z
Link: CVE-2026-41512
Updated: 2026-05-08T17:05:07.753Z
Status : Analyzed
Published: 2026-05-08T14:16:34.433
Modified: 2026-05-11T17:20:02.550
Link: CVE-2026-41512
No data.
OpenCVE Enrichment
Updated: 2026-05-10T21:25:18Z