Vulnerability Description
Vvveb before version 1.0.8.2 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain sensitive server information by triggering unhandled exceptions in the password-reset module. Attackers can access the admin password-reset endpoint to trigger a fatal error caused by a missing namespace import, which exposes the absolute server file path, internal class namespaces, line numbers, and source code excerpts through the debug exception handler rendered to unauthenticated requests.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/givanz/Vvveb/releases/tag/1.0.8.2
- https://github.com/givanz/Vvveb/security/advisories/GHSA-xgvg-r47g-786r
- https://www.vulncheck.com/advisories/vvveb-information-disclosure-via-debug-exce
- https://github.com/givanz/Vvveb/security/advisories/GHSA-xgvg-r47g-786r
FAQ
What is CVE-2026-41931?
CVE-2026-41931 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Vvveb before version 1.0.8.2 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain sensitive server information by triggering unhandled exceptions in the pas...
How severe is CVE-2026-41931?
CVE-2026-41931 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-41931?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.