OVERVIEW CVE-2026-6576 is a command injection vulnerability identified in liangliangyy DjangoBlog versions up to 2.1.0.0, specifically within the CommandHandler function of the WeChat Bot Interface component (servermanager/api/commonapi.py). The vulnerability allows attackers to manipulate the Source argument to execute arbitrary commands on affected systems. SEVERITY The vulnerability carries a CVSS score of 6.3 (MEDIUM), reflecting a network-based attack vector with low complexity and no user interaction required. It affects confidentiality, integrity, and availability equally, though authentication is required to exploit the vulnerability. The FAUCET Risk Score of 44.0/100 indicates moderate concern, though the EPSS score of 0.0025 suggests relatively low prevalence in active threat landscapes compared to other CVEs. EXPLOITATION STATUS Public exploit code is available for this vulnerability, and the attack vector has been disclosed publicly. While the vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog, it appears on the Active Hot List, indicating ongoing attention from security researchers and potential threat actors. The vendor was contacted early in the disclosure process but has not responded or provided patches.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Liangliangyy | DjangoBlog | 2.1.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.