CVE-2026-4191 is an unrestricted file upload vulnerability found in the Profile Picture Handler component of JawherKl node-api-postgres up to version 2.5, specifically within the path.extname function in index.js. This remotely exploitable flaw has a CVSS v3.1 score of 7.3 (High), indicating low attack complexity and potential for low impact on confidentiality, integrity, and availability. An exploit for this vulnerability has been published, making it readily usable. However, it is not currently listed in CISA's KEV catalog and shows no active community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| JawherKl | Node-Api-Postgres | 2.0, 2.1, 2.2, 2.3, 2.4, 2.5CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.