Junglewise Threat Intelligence

CVE-2026-31891: Cockpit CMS has SQL Injection in MongoLite Aggregation Optimizer via toJsonExtractRaw()

CVE-2026-31891 · Severity: low · CVSS 3.1 · Published 2026-03-17

Technologies: cockpit-hq/cockpit (Packagist). Vendors: Packagist.

Executive brief

Cockpit CMS has SQL Injection in MongoLite Aggregation Optimizer via toJsonExtractRaw()

Affected products

  • Packagist cockpit-hq/cockpit

Related threats