CVE-2026-3965 is a medium-severity vulnerability affecting whyour qinglong versions up to 2.20.1, specifically within its API Interface component (back/loaders/express.ts). This flaw allows a remote attacker with low privileges to bypass protection mechanisms by manipulating a command argument. The attack has low complexity and can lead to low impacts on confidentiality, integrity, and availability. While a public exploit has been disclosed, there is no evidence of active exploitation in the wild (not in KEV), and exploit code is not available in major frameworks. Users are strongly advised to upgrade to version 2.20.2 to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Whyour | Qinglong | 2.20.0, 2.20.1CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.