stigmem vulnerability

stigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration flag without a second explicit acknowledgment. If that setting is carried into an environment where plugin directories are writable by less-trusted users, unsigned (potentially malicious) plugin code could be loaded and executed, resulting in arbitrary code execution. Fixed in 0.9.0a2, which requires a second explicit acknowledgment to disable signature enforcement.

Published 19 Aug 2026Updated 11 Sep 20262 sources
CVSS 7.3

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.