---
id: CVE-2026-90843
title: >-
  A security vulnerability has been detected in SabyasachiRana WebMap up to
  8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25
summary: >-
  A security vulnerability has been detected in SabyasachiRana WebMap up to
  8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25. This affects the function
  nmap_newscan of the file functions_nmap.py of the component New Nmap Scan
  Handler. Such manipul…
severity: high
cvss: 8.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L'
cwe:
  - CWE-77
  - CWE-78
vendor: SabyasachiRana
product: WebMap
affected:
  - WebMap 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25
published: '2026-09-15'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T17:18:18.230'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90843'
references:
  - url: 'https://calledstriker.gitbook.io/blog/security-research/webmap'
    label: cna@vuldb.com
  - url: 'https://github.com/SabyasachiRana/WebMap/'
    label: cna@vuldb.com
  - url: >-
      https://github.com/SabyasachiRana/WebMap/commit/3d52f65803a2716bff14d938352c6fef45b0cfb6
    label: cna@vuldb.com
  - url: >-
      https://raw.githubusercontent.com/CalledSTRIKER/CalledSTRIKER-gitbook/refs/heads/main/security-research/2026-05-30_12-29.png
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90843'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/925586'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403395'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403395/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-16T16:50:37.666552Z'
epss: 0.02179
epssPercentile: 0.81557
ingestedAt: '2026-09-15T01:18:29.934Z'
---

## Overview

A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25. This affects the function nmap_newscan of the file functions_nmap.py of the component New Nmap Scan Handler. Such manipulation of the argument target/params leads to os command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The name of the patch is 3d52f65803a2716bff14d938352c6fef45b0cfb6. A patch should be applied to remediate this issue. This issue got fixed with a silent patch.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
