validate_plugin_code of the file plugin_system.py of the component API Call Handler. This manipulation causes incomplete blacklist.This vulnerability is tracked as CVE-2026-33139. The attack is restricted to local execution. No exploit exists.
The affected component should be upgraded.
SOCIAL SHARE CARD GENERATOR