CVE-2026-4500 is a medium-severity injection vulnerability (CVSS 6.3) found in bagofwords1 bagofwords versions up to 0.0.297, specifically impacting the generate_df function. This flaw can be exploited remotely with low privileges and no user interaction, potentially leading to low impacts on confidentiality, integrity, and availability. While a public exploit is available, there is currently no indication of active exploitation, and community discussion or media coverage is minimal. Organizations are strongly advised to upgrade to version 0.0.298 to address this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Bagofwords1 | Bagofwords | 0.0.297CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.