CVE-2026-43979
📛 CVE Title
(no title)
Description
local-deep-research is Vulnerable to HTML Injection via Unescaped User Input in PDF Export (`pdf_service.py:_markdown_to_html`)
Description (MITRE) cveawg.mitre.org
Pulled from cveawg.mitre.org/api/cve/CVE-2026-43979 on 2026-07-04. Shown when MITRE's text differs from the cvelistV5 mirror.
Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.0, PDFService._markdown_to_html() constructs an HTML document by interpolating user-controlled values — specifically title (sourced from research.title or research.query) and metadata key-value pairs — directly into an f-string without any HTML escaping. An authenticated attacker can craft a research query containing HTML special characters to inject arbitrary HTML tags into the document processed by WeasyPrint during PDF export. This injection can be chained to trigger a Server-Side Request Forgery (SSRF), bypassing the application's existing SSRF defenses in ssrf_validator.py. This vulnerability is fixed in 1.6.0.
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- medium
- CVSS score
- —
- CVSS vector
AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N- Effective score
- no score available from CNA, NVD, or AI yet
- CWE(s)
- —
- Reserved
- —
- Published
- —
- Last updated
- —
- Source
- https://www.tenable.com/cve/CVE-2026-43979
NVD / KEV / EPSS data refreshed 2026-05-24 23:57 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
AI-forensic CVSS estimate
Used only when a CVE has no official CVSS from its CNA or NVD. An LLM estimates the v3.1 base score from the description; a HIGH/CRITICAL estimate promotes the CVE to a Threat.
AI could not derive a confident score from this record (likely RESERVED / REJECTED or too sparse).
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-32978 - Assigner
- GitHub_M
- Published
- May 28, 2026, 5:59:19 PM
- Updated
- May 28, 2026, 7:33:58 PM
- EUVD base score (CVSS 3.1)
-
5.0 / 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N - EUVD-reported EPSS
- 0.2600
- Vendors
- LearningCircuit
- Products
-
local-deep-research (< 1.6.0)
- Aliases
-
GHSA-fj2m-qvh9-jq4q
ENISA description: Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.0, PDFService._markdown_to_html() constructs an HTML document by interpolating user-controlled values — specifically title (sourced from research.title or research.query) and metadata key-value pairs — directly into an f-string without any HTML escaping. An authenticated attacker can craft a research query containing HTML special characters to inject arbitrary HTML tags into the document processed by WeasyPrint during PDF export. This injection can be chained to trigger a Server-Side Request Forgery (SSRF), bypassing the application's existing SSRF defenses in ssrf_validator.py. This vulnerability is fixed in 1.6.0.
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (6)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://github.com/LearningCircuit/local-deep-research/pull/3082 tenable:github.com
- https://github.com/LearningCircuit/local-deep-research/pull/3613 tenable:github.com
- https://github.com/LearningCircuit/local-deep-research/security/advisories/GHSA-fj2m-qvh9-jq4q tenable:github.com
- https://www.first.org/epss/ tenable:www.first.org
- https://nvd.nist.gov/vuln/detail/CVE-2026-43979 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2026-43979 tenable:www.cve.org
Remediations (10)
-
web:blackbeltsecure.com
Discover what businesses must do about the critical Microsoft Exchange Server zero-day CVE - 2026 -42897 actively exploited in the wild. This guide details immediate mitigations for Exchange Server 2016/2019, long-term recommendations, and how to protect your organization from this XSS vulnerability in OWA. Don't wait for the patch — act now.
2026-05-26 03:07 UTC -
web:cybersecuritynews.com
Microsoft Exchange Server spoofing flaw, is being actively exploited against on-premises systems before a permanent patch is available.
2026-05-26 03:07 UTC -
web:purple-ops.io
While the current mitigation addresses CVE - 2026 -42897, an older vulnerability like CVE - 2026 -32201 SharePoint Spoofing demonstrates the recurring nature of spoofing attacks across Microsoft products and the importance of a complete update strategy. Remediation Actions
2026-05-26 03:07 UTC -
web:securityaffairs.com
Microsoft warned that attackers are exploiting a new Exchange Server zero-day vulnerability, tracked as CVE - 2026 -42897, in the wild.
2026-05-26 03:07 UTC -
web:socprime.com
CVE - 2026 -42897 Mitigation Microsoft's immediate CVE - 2026 -42897 mitigation guidance is to rely on the Exchange Emergency Mitigation Service, which applies protection automatically through a URL Rewrite configuration and is enabled by default on supported on-prem Exchange deployments.
2026-05-26 03:07 UTC -
web:techcommunity.microsoft.com
We wanted to tell you how to address the Exchange Server May 2026 vulnerability CVE - 2026 -42897.
2026-05-26 03:07 UTC -
web:windowsforum.com
Microsoft's Fastest Fix Is a Mitigation , Not a Patch The important detail in Microsoft's May 14 notice is that there is no permanent Exchange security update available yet for CVE - 2026 -42897. Microsoft says it is working on one and will release it later for affected supported paths, but today's defensive action is mitigation .
2026-05-26 03:07 UTC -
web:www.helient.com
All servers: Get-ExchangeServer | Where-Object { $_.ServerRole -ne "Edge" } | .\EOMT.ps1 - CVE " CVE - 2026 -42897" Important Note:Microsoft is actively working on a security patch to resolve this vulnerability for the impacted versions of Exchange Server. Meanwhile, organizations are requested to perform the emergency mitigation as a temporary ...
2026-05-26 03:07 UTC -
web:www.oracle.com
This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.
2026-05-26 03:07 UTC -
web:www.penligent.ai
CVE - 2026 -42897 is an actively exploited Microsoft Exchange Server OWA XSS flaw. Learn what is known, how EEMS and EOMT mitigations work, what to verify, and how defenders should hunt, harden, and prepare for the permanent patch .
2026-05-26 03:07 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.