{"id":"CVE-2023-26266","details":"In AFL++ 4.05c, the CmpLog component uses the current working directory to resolve and execute unprefixed fuzzing targets, allowing code execution.","modified":"2026-08-12T03:51:41.771421618Z","published":"2023-02-21T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/26xxx/CVE-2023-26266.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/26xxx/CVE-2023-26266.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-26266"},{"type":"FIX","url":"https://github.com/AFLplusplus/AFLplusplus/pull/1643"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/aflplusplus/aflplusplus","events":[{"introduced":"3b6fcd911a860a8c823c912c4b08b423734e4cfe"},{"last_affected":"3b6fcd911a860a8c823c912c4b08b423734e4cfe"}],"database_specific":{"cpe":"cpe:2.3:a:afl\\+\\+_project:afl\\+\\+:4.05c:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.05c"},{"last_affected":"4.05c"}],"source":"CPE_STRING"}}],"versions":["4.05c"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-26266.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}]}