CVE-2026-3813 is a critical injection vulnerability (CVSS 9.8) affecting the Calculate function in opencc JFlow up to version 5badc00db382d7cb82dad231e6a866b18e0addfe. This flaw allows for remote, unauthenticated attacks with low complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. A public exploit is available and could be used, indicating a high potential for exploitation. Despite this, there is no evidence of active exploitation, and community discussion or media coverage is currently absent. The project has been informed but has not yet responded to the reported problem.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:opencc:jflow:-:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.