Loading vulnerability details...
| Property | Value |
|---|---|
| Advisory ID | SGZ-2026-E3202 |
| Severity | MEDIUM |
| CWE | CWE-754 |
| Confidence | 88% |
| Category | logic_flaw |
| Exploitability | likely |
| Package | webgestalt_rust@latest (cargo) |
| Location | src/rust/src/lib.rs:58-64 |
| Attack Vector | NETWORK |
| Attack Complexity | LOW |
| Privileges Required | NONE |
| Discovered By | SafeGuard Zero-Day AI Discovery Engine |
The nta_rust function unwraps R objects (as_list, as_string_vector) without validation. Supplying malformed R objects causes a panic, which can be leveraged to crash the host process.
The vulnerability was identified in the file src/rust/src/lib.rs at lines 58-64 within the webgestalt_rust package (version latest). Any code path that invokes these functions inherits this vulnerability.
File: src/rust/src/lib.rs (lines 58-64)
let edge_list_as_vec: Vec<Vec<String>> = edge_list
.as_list()
.unwrap()
.iter()
.map(|(_, row)| row.as_string_vector().unwrap_or(vec![]))
.filter(|x| !x.is_empty())
.collect();
The code above demonstrates the vulnerable pattern. This code is executed at runtime and can be directly exploited by an attacker with the appropriate access level.
Pass a non‑list R object or a list containing non‑string vectors to nta_rust. The unwrap() will panic, terminating the R session.
Denial of Service – crashes the R process, interrupting analysis workflows.
Check the type of edge_list and each row before unwrapping. Return a descriptive R error if validation fails.
Advisory: SGZ-2026-E3202 | Source: SafeGuard Zero-Day AI Discovery | Status: Candidate
This vulnerability was autonomously discovered by SafeGuard's AI-powered Zero-Day Discovery engine using TAOR (Think-Act-Observe-Repeat) agentic analysis on the package source code. It is not yet tracked in any public vulnerability database (CVE, NVD, GHSA, OSV). This finding should be triaged by a security engineer and, if confirmed, reported upstream to the package maintainer.
| Property | Value |
|---|---|
| Advisory ID | SGZ-2026-E3202 |
| Severity | MEDIUM |
| CWE | CWE-754 |
| Confidence | 88% |
| Category | logic_flaw |
| Exploitability | likely |
| Package | webgestalt_rust@latest (cargo) |
| Location | src/rust/src/lib.rs:58-64 |
| Attack Vector | NETWORK |
| Attack Complexity | LOW |
| Privileges Required | NONE |
| Discovered By | SafeGuard Zero-Day AI Discovery Engine |
The nta_rust function unwraps R objects (as_list, as_string_vector) without validation. Supplying malformed R objects causes a panic, which can be leveraged to crash the host process.
The vulnerability was identified in the file src/rust/src/lib.rs at lines 58-64 within the webgestalt_rust package (version latest). Any code path that invokes these functions inherits this vulnerability.
File: src/rust/src/lib.rs (lines 58-64)
let edge_list_as_vec: Vec<Vec<String>> = edge_list
.as_list()
.unwrap()
.iter()
.map(|(_, row)| row.as_string_vector().unwrap_or(vec![]))
.filter(|x| !x.is_empty())
.collect();
The code above demonstrates the vulnerable pattern. This code is executed at runtime and can be directly exploited by an attacker with the appropriate access level.
Pass a non‑list R object or a list containing non‑string vectors to nta_rust. The unwrap() will panic, terminating the R session.
Denial of Service – crashes the R process, interrupting analysis workflows.
Check the type of edge_list and each row before unwrapping. Return a descriptive R error if validation fails.
Advisory: SGZ-2026-E3202 | Source: SafeGuard Zero-Day AI Discovery | Status: Candidate
This vulnerability was autonomously discovered by SafeGuard's AI-powered Zero-Day Discovery engine using TAOR (Think-Act-Observe-Repeat) agentic analysis on the package source code. It is not yet tracked in any public vulnerability database (CVE, NVD, GHSA, OSV). This finding should be triaged by a security engineer and, if confirmed, reported upstream to the package maintainer. This vulnerability involves weaknesses in
This medium-severity vulnerability could be exploited under certain conditions to compromise security controls or access sensitive information. Should be addressed in a timely manner.
Isolate affected systems from untrusted networks until patching is complete
Implement enhanced monitoring for exploitation attempts and unusual behavior