WhisperX tag archive

#CVE candidate

This page collects WhisperX intelligence signals tagged #CVE candidate. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-04-28 19:54:17 · GitHub Issues

1. Shell Injection Vulnerability in Chat Application Docker Entrypoint Exposes BACKEND_URL to Arbitrary Nginx Config Injection

A high-severity shell injection vulnerability has been identified in the Docker entrypoint script of a chat application's frontend Nginx container. The flaw, tracked in `src/chat-app/frontend/docker-entrypoint.sh` (lines 11–14), allows an attacker who controls the `BACKEND_URL` environment variable to inject arbitrary ...