CVE-2026-8318
Last modified
CVE-2026-8318 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. A security flaw has been discovered in VectifyAI PageIndex up to f50e52975313c6716c02b20a119577a1929decba. Affected by this vulnerability is the function toc_transformer of the file pageindex/page_index.py of the component PDF Table of Contents Handler. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
A security flaw has been discovered in VectifyAI PageIndex up to f50e52975313c6716c02b20a119577a1929decba. Affected by this vulnerability is the function toc_transformer of the file pageindex/page_index.py of the component PDF Table of Contents Handler. The manipulation results in infinite loop. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-8318?
How severe is CVE-2026-8318?
How do I fix CVE-2026-8318?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-83174Vulnerability in the Oracle CRM Technical Foundation product…8.1
- CVE-2026-83175Vulnerability in the Oracle Application Object Library produ…6.5
- CVE-2026-83176Vulnerability in the Oracle Common Applications product of O…7.2
- CVE-2026-83177Vulnerability in the Oracle One-to-One Fulfillment product o…8.1
- CVE-2026-83178Vulnerability in the Oracle Application Object Library produ…8
- CVE-2026-83179Vulnerability in the Oracle Common Applications Calendar pro…7.1
- CVE-2026-83180Vulnerability in the Siebel CRM Deployment product of Oracle…8.8
- CVE-2026-83181Vulnerability in the Siebel CRM Development product of Oracl…8.2
- CVE-2026-83182Vulnerability in the Siebel CRM Development product of Oracl…7.5
- CVE-2026-83183Vulnerability in the Siebel CRM Deployment product of Oracle…7.5
- CVE-2026-83184Vulnerability in the Oracle Application Object Library produ…7.4
- CVE-2026-83185Vulnerability in the Oracle Common Applications product of O…7.3
Are you affected by CVE-2026-8318?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
