CVE detail
CVE-2026-3965
A security vulnerability has been detected in whyour qinglong up to 2.20.1. Affected is an unknown function of the file back/loaders/express.ts of the component API Interface. The manipulation of the argument command leads to protection mechanism failure. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 2.20.2 is able to address this issue. The identifier of the patch is 6bec52dca158481258315ba0fc2f11206df7b719. It is advisable to upgrade the affected component. The code maintainer was informed beforehand about the issues. He reacted very fast and highly professional.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.0 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
10 source links · newest first
- In Other News: Scattered Spider Hacker Arrested, SOC Effectiveness Metrics, NSA Tool VulnerabilitySecurityWeek
Other noteworthy stories that might have slipped under the radar: OFAC hits Iranian central bank crypto reserves, ADT data leak, CISA guidance for zero trust in OT.
newswww.securityweek.comMay 1, 2026, 3:01 PM - https://vuldb.com/?submit.768861vuldb.com
No excerpt available.
Exploitvuldb.comMar 12, 2026, 12:16 AM - https://vuldb.com/?id.350394vuldb.com
No excerpt available.
Exploitvuldb.comMar 12, 2026, 12:16 AM - https://vuldb.com/?ctiid.350394vuldb.com
No excerpt available.
Exploitvuldb.comMar 12, 2026, 12:16 AM No excerpt available.
Exploitgithub.comMar 12, 2026, 12:16 AMNo excerpt available.
Exploitgithub.comMar 12, 2026, 12:16 AMNo excerpt available.
Exploitgithub.comMar 12, 2026, 12:16 AM- https://github.com/whyour/qinglong/github.com
No excerpt available.
Exploitgithub.comMar 12, 2026, 12:16 AM No excerpt available.
Exploitgithub.comMar 12, 2026, 12:16 AM- https://github.com/A7cc/cve/issues/6github.com
No excerpt available.
Exploitgithub.comMar 12, 2026, 12:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-48037CVSS 6.3 · Medium
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, AccountFoundation reuse paths silent…
- CVE-2026-48033CVSS 8.4 · High
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, policy packs can be bypassed by a fo…
- CVE-2026-65899CVSS 5.1 · Medium
DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy when clearConfig() is called, so a DOMPurify instance reused across trust boundaries stays bound to a…
- CVE-2025-50330CVSS 8.8 · High
An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe.
- CVE-2025-50329CVSS 9.8 · Critical
An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe.
- CVE-2025-50327CVSS 8.8 · High
An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of the Mark-of-the-Web protection m…