{"id":"CVE-2026-40035","summary":"Unfurl - Werkzeug Debugger Exposure via String Config Parsing","details":"Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by default. The debug configuration value is read as a string and passed directly to app.run(), causing any non-empty string to evaluate truthy, allowing attackers to access the Werkzeug debugger and disclose sensitive information or achieve remote code execution.","aliases":["GHSA-vg9h-jx4v-cwx2"],"modified":"2026-08-12T03:51:09.324607214Z","published":"2026-04-08T21:35:27.703Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-489"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40035.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40035.json"},{"type":"ADVISORY","url":"https://github.com/obsidianforensics/unfurl/security/advisories/GHSA-vg9h-jx4v-cwx2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40035"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/dfir-unfurl-werkzeug-debugger-exposure-via-string-config-parsing"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/RyanDFIR/unfurl","events":[{"introduced":"0"},{"last_affected":"f0d0a7c350d482bcd5de75fa542c7189126cf71a"}],"database_specific":{"cpe":"cpe:2.3:a:ryandfir:unfurl:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"2025.08"}],"source":["AFFECTED_FIELD","CPE_RANGE"]}}],"versions":["v2025.08","v2025.03","v2025.02","v2024.11","v2024.11.20","v2024.06.27","v2024.06.26","v2024.06","v2023.09.05","v2023.09.04","v2023.09.03","v2023.09.02","v2023.09.01","v2023.09","v2022.11.01","v2022.11","v2022.02","v2021.06.15","v2021.03.11","20201102","20200812"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40035.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}