{"id":"CVE-2026-76191","title":"Animate is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user","summary":"Animate is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerabilit…","severity":"high","cvss":8.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","cwe":["CWE-94"],"vendor":"adobe","product":"animate","affected":["animate >= 23.0.0, < 23.0.17","animate >= 24.0.0, < 24.0.14"],"patched":["animate 24.0.14"],"published":"2026-09-08","updated":"2026-09-15","sourceUpdated":"2026-09-15T13:44:36.537","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-76191","references":[{"url":"https://helpx.adobe.com/security/products/animate/apsb26-132.html","label":"psirt@adobe.com"}],"tags":["nvd","cve.org"],"epss":0.00253,"epssPercentile":0.17059,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-08T17:35:04.006655Z"},"ingestedAt":"2026-09-08T19:08:49.627Z","slug":"CVE-2026-76191","body":"## Overview\n\nAnimate is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.\n\n## Affected\n\n- `animate >= 23.0.0, < 23.0.17`\n- `animate >= 24.0.0, < 24.0.14`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `animate 24.0.14`","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":45.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}