CVE-2026-38626

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Garlic-Hub v1.0.1 is vulnerable to SQL Injection in src/Modules/Items/Repositories/ItemsRepository.php.

Published 2026-09-10. Last modified 2026-09-14.