CVE-2026-3965 is a remotely exploitable vulnerability in whyour/qinglong affecting versions up to 2.20.1. The flaw is rooted in incorrect API protection logic in the Express-based backend, particularly in back/loaders/express.ts, where authorization checks can be bypassed due to path-handling inconsistencies. Available reporting indicates that protected API routes can be reached through alternate path forms, including rewritten or case-variant request paths, allowing requests to evade intended authentication controls. In the vulnerable code path, a system command execution endpoint exposed by the API accepts attacker-controlled input and passes the command argument into command execution logic without adequate sanitization. The command execution path ultimately invokes shell execution through promisified exec functionality, enabling arbitrary command execution on the host. Public discussion also describes the issue as exposing protected administrative functionality through misrouted or insufficiently guarded paths, and notes that it has been used in real-world attack chains against internet-exposed Qinglong instances.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prior Qinglong vulnerability referenced as the original issue for which CVE-2026-55445 is an incomplete fix.
An authentication bypass vulnerability in Qinglong affecting version 2.20.1 and older; it can be chained with CVE-2026-4047 to achieve remote code execution and has been actively exploited to deploy cryptominers.
An authentication bypass vulnerability in Qinglong caused by a URL rewrite rule that maps /open/* requests to protected /api/* endpoints, allowing unauthenticated attackers to reset administrative credentials.
An authentication bypass vulnerability in Qinglong caused by a misconfigured rewrite rule that exposes protected admin endpoints via an unauthenticated path; it can be chained with another flaw to achieve remote code execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.