CVE-2023-26266: Afl++ Project Afl++
High severity, CVSS 7.3. EPSS: 0.4% chance of exploitation in the next 30 days.
In AFL++ 4.05c, the CmpLog component uses the current working directory to resolve and execute unprefixed fuzzing targets, allowing code execution.
Affected products
- Afl++ Project Afl++: version 4.05c only
Published 2023-02-21. Last modified 2026-06-17.