LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-26215

CVE-2026-26215 - Vulnerability Analysis

N/a

Last Updated: February 12, 2026

manga-image-translator - Remote Code Execution

Published: February 11, 2026Updated: February 12, 2026PoC Available

Overview

manga-image-translator beta-0.3 and prior in shared API mode contains an insecure deserialization vulnerability caused by unvalidated use of pickle.loads() in FastAPI endpoints, letting unauthenticated remote attackers execute arbitrary code by sending crafted payloads.

Severity & Score

Severity: N/a

Impact

Unauthenticated remote attackers can execute arbitrary code on the server, potentially leading to full system compromise.

Mitigation

Update to the latest version that fixes the insecure deserialization vulnerability.

Details

CVE ID
CVE-2026-26215
Severity
N/a
Type
insecure_deserialization
Status
unconfirmed

CWE

  • CWE-502

CVSS Metrics

N/A