HIGH
absmach
CVE published 2026-08-05
CVE-2026-71235
Authenticated low-privileged users can create rules with embedded Go or Lua scripts, potentially leading to arbitrary file read/write, environment variable leakage, database access, and SSRF against internal microservices due to limited validation in the Go script engine and no input validation in the Lua script engine. This vulnerability exists in Magistrala's Rules Engine, allowing users to execute scri [truncated]