CVE-2026-19360: Wongcyrus Excellexbot
Medium severity, CVSS 4.7. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability was detected in wongcyrus ExcelLexBot up to 0.0.3. This affects the function ExcelLexBotS3TriggerFunction of the component Lambda Function Handler. Performing a manipulation results in improper privilege management. The attack may be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.
Affected products
- Wongcyrus Excellexbot: version 0.0.1 only; version 0.0.2 only; version 0.0.3 only
Published 2026-08-09. Last modified 2026-08-12.