CVE-2026-76191: Animate | Improper Control of Generation of Code ('Code Injection') (CWE-94)
Animate is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Users of Animate are exposed if they open a malicious file. The vulnerability allows a low-privileged attacker to execute arbitrary code in the context of the current user.
What does an attacker need to exploit this issue?
The attacker needs a victim to interact with a malicious file by opening it in Animate. The supplied data does not indicate that exploitation can occur without this user action.
What is the potential impact after successful exploitation?
Successful exploitation can result in arbitrary code execution with the privileges of the current user. The vulnerability is also marked as having changed scope.