CVE-2026-58449: Improper Control of Generation of Code ('Code Injection') in neuml txtai
txtai through 9.10.0, fixed in commit 11b32da, exposes an API /reindex endpoint whose function body parameter is resolved through txtai.util.Resolver, which performs __import__ and getattr on the caller-supplied dotted path with no allowlist. When the API is exposed with no TOKEN configured (authentication is opt-in, so all endpoints are unauthenticated) and the index is configured writable, a remote attacker can set function to an arbitrary callable such as subprocess.getoutput, achieving remote code execution as the server process during reindexing. Exploitation requires those deployment conditions (API exposed, no TOKEN, writable index); it is not the default configuration. The fix gates the endpoint behind a new reindex configuration flag.
AI Analysis
Technical Summary
CVE-2026-58449 is a critical code injection vulnerability in neuml's txtai product affecting versions up to 9.10.0. The /reindex API endpoint accepts a function parameter resolved via txtai.util.Resolver, which uses __import__ and getattr on user-supplied input without an allowlist. When the API is exposed without a configured TOKEN (authentication is opt-in) and the index is writable, an attacker can specify an arbitrary callable such as subprocess.getoutput, leading to remote code execution as the server process during reindexing. The vulnerability is mitigated by a fix that restricts access to the endpoint behind a new reindex configuration flag.
Potential Impact
Successful exploitation allows unauthenticated remote attackers to execute arbitrary code on the server process running txtai, resulting in full compromise of confidentiality, integrity, and availability of the affected system. This can lead to complete system takeover, data theft, or service disruption. However, exploitation requires the API to be exposed without authentication and the index to be writable, which are not default settings.
Mitigation Recommendations
A fix is available that restricts access to the /reindex endpoint behind a new reindex configuration flag. Users should apply this fix by updating txtai to a version including the commit 11b32da or later. Additionally, configuring authentication tokens (TOKEN) to protect the API and ensuring the index is not writable unless necessary will mitigate the risk. Patch status is not explicitly confirmed in the advisory, so users should check the vendor repository or release notes for the fixed version containing commit 11b32da.
CVE-2026-58449: Improper Control of Generation of Code ('Code Injection') in neuml txtai
Description
txtai through 9.10.0, fixed in commit 11b32da, exposes an API /reindex endpoint whose function body parameter is resolved through txtai.util.Resolver, which performs __import__ and getattr on the caller-supplied dotted path with no allowlist. When the API is exposed with no TOKEN configured (authentication is opt-in, so all endpoints are unauthenticated) and the index is configured writable, a remote attacker can set function to an arbitrary callable such as subprocess.getoutput, achieving remote code execution as the server process during reindexing. Exploitation requires those deployment conditions (API exposed, no TOKEN, writable index); it is not the default configuration. The fix gates the endpoint behind a new reindex configuration flag.
CVSS v3.1
Score 9.8critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-58449 is a critical code injection vulnerability in neuml's txtai product affecting versions up to 9.10.0. The /reindex API endpoint accepts a function parameter resolved via txtai.util.Resolver, which uses __import__ and getattr on user-supplied input without an allowlist. When the API is exposed without a configured TOKEN (authentication is opt-in) and the index is writable, an attacker can specify an arbitrary callable such as subprocess.getoutput, leading to remote code execution as the server process during reindexing. The vulnerability is mitigated by a fix that restricts access to the endpoint behind a new reindex configuration flag.
Potential Impact
Successful exploitation allows unauthenticated remote attackers to execute arbitrary code on the server process running txtai, resulting in full compromise of confidentiality, integrity, and availability of the affected system. This can lead to complete system takeover, data theft, or service disruption. However, exploitation requires the API to be exposed without authentication and the index to be writable, which are not default settings.
Mitigation Recommendations
A fix is available that restricts access to the /reindex endpoint behind a new reindex configuration flag. Users should apply this fix by updating txtai to a version including the commit 11b32da or later. Additionally, configuring authentication tokens (TOKEN) to protect the API and ensuring the index is not writable unless necessary will mitigate the risk. Patch status is not explicitly confirmed in the advisory, so users should check the vendor repository or release notes for the fixed version containing commit 11b32da.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-06-30T19:09:07.025Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a4436ef27e9c797196d42b7
Added to database: 06/30/2026, 21:36:47 UTC
Last enriched: 07/16/2026, 09:16:41 UTC
Last updated: 08/13/2026, 00:41:13 UTC
Views: 82
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.