AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-27T20:16:40.017Z and has not been modified since then. The NVD entry is currently Analyzed. CVE-2026-56748 is a high-severity vulnerability in Cribl Stream's Pack Git import feature. An improper validation of symbolic links allows remote authenticated attackers with Pack import and pipeline preview [truncated]
The JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 has an improper control of code generation vulnerability. This allows a remote authenticated attacker with edit privileges to execute arbitrary JavaScript on the server via crafted database connection identifiers or pack configuration values. The vulnerability affects Cribl Stream deployments, particularly those with edit privileges enabl [truncated]