CVE-2026-31861 | siteboon claudecodeui up to 1.23.x Git Configuration Endpoint /api/user/git-config exec gitEmail code injection (GHSA-7fv4-fmmc-86g2)
A vulnerability labeled as critical has been found in siteboon claudecodeui up to 1.23.x. Affected is the function exec of the file /api/user/git-config of the component Git Configuration Endpoint. The manipulation of the argument gitEmail results in code injection.
This vulnerability is cataloged as CVE-2026-31861. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.