{"success":true,"data":{"threats":[{"id":"f3aa2a85-c55b-4744-995e-c006de139176","slug":"cve-2026-107336","externalId":"CVE-2026-107336","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107336 — Malcolm's front nginx reverse proxy defines a \"Dashboards → Arkime shortcut\" location using a case-insensitive regex matcher but a case-sensitive r…","description":"Malcolm's front nginx reverse proxy defines a \"Dashboards → Arkime shortcut\" location using a case-insensitive regex matcher but a case-sensitive rewrite. A request whose path segment is not exact-lowercase (for example /IDDASH2ARK/...) enters the location (the matcher fires) but evades the rewrite (no redirect is issued), so nginx falls through to the location's proxy_pass to the Arkime backend. That location is the one proxied location in the shipped config that does not include the per-location authentication file, so the request reaches Arkime unauthenticated. The same location also forwards a client-supplied X-Forwarded-User header un-overwritten, and Arkime is configured to trust X-Forwarded-User as the authenticated username — so an unauthenticated network caller can reach the Arkime backend while supplying a forged, auto-provisioned identity.","cveId":"CVE-2026-107336","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-290","CWE-441","CWE-863"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-280-01.json","type":"advisory","title":"ics-cert@hq.dhs.gov"},{"url":"https://github.com/cisagov/Malcolm/security/advisories/GHSA-7j32-cf27-cp6h","type":"advisory","title":"ics-cert@hq.dhs.gov"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T18:17:20.177Z","addedAt":"2026-10-08T18:39:31.853Z","updatedAt":"2026-10-08T23:06:38.714Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107336","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107336","note":"authoritative record"}]},{"id":"a828b3e6-168f-41ac-b3c2-30ec5857b27c","slug":"cve-2026-107589","externalId":"CVE-2026-107589","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107589 — Insufficient job validation for service accounts in Jacamar CI prior to v0.30.0 allows authenticated CI users to generate arbitrary account names.","description":"Insufficient job validation for service accounts in Jacamar CI prior to v0.30.0 allows authenticated CI users to generate arbitrary account names.","cveId":"CVE-2026-107589","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-290"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://ecp-ci.gitlab.io/docs/releasenotes/jacamar/jacamar_0.30.0.html","type":"advisory","title":"cve@gitlab.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:45.153Z","addedAt":"2026-10-08T16:39:35.763Z","updatedAt":"2026-10-08T23:06:38.249Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107589","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107589","note":"authoritative record"}]},{"id":"18c45821-2049-43bc-a780-6923e5394498","slug":"cve-2026-4894","externalId":"CVE-2026-4894","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-4894 — A vulnerability has been identified regarding insufficient validation in the Frappe Cloud/ERPNext authentication process, which allows multiple ema…","description":"A vulnerability has been identified regarding insufficient validation in the Frappe Cloud/ERPNext authentication process, which allows multiple email addresses to be accepted by manipulating the email field in the /api/method/press.api.account.signup endpoint. The vulnerability occurs when an unauthenticated remote attacker adds more than one email address.\nThe service processes the entire value as a valid list of recipients and sends the OTP code to all addresses without proper validation of all added emails (only one of them needs to be valid). Exploiting this vulnerability would allow an attacker to:\n\n  *  Obtain the authentication OTP;\n  *  Impersonate someone else in the registration process;\n  *  Register accounts using other people's email addresses without access to the mailbox;\n  *  Indirectly confirm the existence of already registered email addresses.","cveId":"CVE-2026-4894","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-290"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.incibe.es/en/incibe-cert/notices/aviso/authentication-bypass-multiple-products-frappe-technologies","type":"advisory","title":"cve-coordination@incibe.es"}],"epssScore":0.00379,"epssPercentile":0.29788,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T09:16:41.477Z","addedAt":"2026-10-08T10:39:34.921Z","updatedAt":"2026-10-08T23:06:37.277Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4894","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-4894","note":"authoritative record"}]},{"id":"84df7922-87a0-45f4-aeee-203aab2af2dc","slug":"cve-2026-87663","externalId":"CVE-2026-87663","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87663 — An authentication bypass and command injection vulnerability exists in the inter-switch remote execution service of Brocade Fabric OS versions befo…","description":"An authentication bypass and command injection vulnerability exists in the inter-switch remote execution service of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When processing remote command execution IPC frames across the fabric, the receiving switch processes these commands at an elevated processing level without proper verification of transmitted parameters. This allows an attacker on a single fabric-connected switch to escalate privileges and execute arbitrary root commands locally or across other managed fabric members where remote execution functionality is enabled.","cveId":"CVE-2026-87663","cvssScore":7.1,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-290"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/39163","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.00735,"epssPercentile":0.53033,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T05:17:05.567Z","addedAt":"2026-10-08T06:39:29.517Z","updatedAt":"2026-10-08T21:05:46.358Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87663","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87663","note":"authoritative record"}]},{"id":"544250a4-1509-4875-9134-8e8aa03f5411","slug":"cve-2026-87686","externalId":"CVE-2026-87686","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87686 — An authentication and access control bypass vulnerability exists in the web server management interface of Brocade Fabric OS versions before 10.0.1.","description":"An authentication and access control bypass vulnerability exists in the web server management interface of Brocade Fabric OS versions before 10.0.1. The web dispatcher routine evaluates internal management VLAN trust decisions using the client-supplied HTTP host header instead of the actual socket transport layer source IP address. Successful exploitation allows the attacker to bypass IP-filtering access control lists (ACLs) and obtain sensitive device metadata (such as model, serial number, hardware revision, and firmware version) without authentication.","cveId":"CVE-2026-87686","cvssScore":5.3,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-290"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/39080","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.00201,"epssPercentile":0.09087,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T03:16:37.390Z","addedAt":"2026-10-08T04:39:32.959Z","updatedAt":"2026-10-08T21:05:45.728Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87686","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87686","note":"authoritative record"}]},{"id":"d63597ce-0e6e-466d-8579-9cadc5549891","slug":"cve-2026-87670","externalId":"CVE-2026-87670","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87670 — An authorization logic vulnerability exists in the Brocade Fabric OS versions before 10.0.1 REST API gateway.","description":"An authorization logic vulnerability exists in the Brocade Fabric OS versions before 10.0.1 REST API gateway. The internal gate guarding restricted management endpoints relies exclusively on client-controlled HTTP headers. An authenticated user with any valid REST session can spoof these headers to gain unauthorized access to internal management endpoints. This allows low-privilege users to view sensitive chassis metadata, hardware memory patrolling state, and firmware integrity audit logs.","cveId":"CVE-2026-87670","cvssScore":5.1,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-290"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/39140","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.00139,"epssPercentile":0.0282,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T03:16:36.403Z","addedAt":"2026-10-08T04:39:32.913Z","updatedAt":"2026-10-08T21:05:45.557Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87670","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87670","note":"authoritative record"}]},{"id":"40b4f470-bb4e-431b-9d84-1758fcf60d5e","slug":"cve-2026-92542","externalId":"CVE-2026-92542","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-92542 — The firewall rules which mark VXLAN datagrams for encryption indiscriminately match both authentic VXLAN datagrams sent from the kernel and forged …","description":"The firewall rules which mark VXLAN datagrams for encryption indiscriminately match both authentic VXLAN datagrams sent from the kernel and forged datagrams sent by user processes. Any packet sent from the host network namespace of a Linux Swarm node is encrypted with the overlay-network IPsec parameters which meets the following criteria:\n\n- UDP datagram\n- Destination port is the Swarm data-path port\n- Datagram starts with a VXLAN header for the VNI of an encrypted overlay network which any running container on the node is connected to","cveId":"CVE-2026-92542","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-290"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/moby/moby/security/advisories/GHSA-6m9p-4h64-m6vh","type":"advisory","title":"security@docker.com"}],"epssScore":0.00066,"epssPercentile":0.00017,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T17:17:02.580Z","addedAt":"2026-10-07T18:39:31.588Z","updatedAt":"2026-10-08T21:05:43.251Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92542","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-92542","note":"authoritative record"}]},{"id":"dce5e97f-9ce1-4a80-9aef-58b94f07d04a","slug":"cve-2026-33586","externalId":"CVE-2026-33586","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-33586 — Authenticated users are able to manipulate both the SMTP\nenvelope “Envelope-from” and “From” fields when sending\nemails through OVH mail servers.","description":"Authenticated users are able to manipulate both the SMTP\nenvelope “Envelope-from” and “From” fields when sending\nemails through OVH mail servers.\n\n\n\nDue to OVH's default SPF configuration, which\ncommonly includes include:mx.ovh.com, any authenticated user with a\nvalid OVH email account can send messages that appear to originate from any\nOVH-hosted domains using the default SPF record. Since the SPF policy\nexplicitly authorizes OVH mail servers (mx.ovh.com) to send mail on behalf of\nthese domains, forged messages successfully pass SPF validation despite\nnot being authorized by the impersonated domain owner.","cveId":"CVE-2026-33586","cvssScore":6.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-290","CWE-346","CWE-1188"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://docs.ovhcloud.com/en/guides/web-cloud/email-and-collaborative-solutions/troubleshooting/email-rejected-cross-domain-spoofing","type":"advisory","title":"a6d3dc9e-0591-4a13-bce7-0f5b31ff6158"}],"epssScore":0.00139,"epssPercentile":0.02813,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T16:17:47.643Z","addedAt":"2026-10-07T16:39:32.781Z","updatedAt":"2026-10-08T23:06:36.659Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33586","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-33586","note":"authoritative record"}]},{"id":"dfe7ffbd-dbd8-431d-9e3b-d9ffeda91b85","slug":"cve-2026-61428","externalId":"GHSA-qj9c-59p6-8cgx","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"PraisonAI: AgentMail webhook lacks signature verification, allowing unauthenticated message injection and sender spoofing","description":"## Summary\n\nPraisonAI's AgentMail bot, when run in webhook (or hybrid) mode, starts an aiohttp webhook server bound to `0.0.0.0` and processes inbound `message.received` events **without verifying any signature/HMAC and without authentication**. The sender address and message body are taken directly from the attacker-controlled request body, so any network peer can inject messages into the agent with a spoofed sender (bypassing sender allow/block lists) and have the agent process the content and reply to an attacker-chosen address. Sibling bots (`linear.py`, `whatsapp.py`) fail closed when no secret is configured; AgentMail omits the check entirely. Runtime-confirmed; severity Medium.\n\n## Details\n\n### Affected component\n- Package: `praisonai` 4.6.63. File: `src/praisonai/praisonai/bots/agentmail.py` (`AgentMailBot`, webhook/hybrid mode).\n\n### Vulnerable code / root cause\n\nPath:\n`src/praisonai/praisonai/bots/agentmail.py`\n\nFunction:\n`_start_webhook_mode` / `_handle_email_webhook` / `_handle_message`\n\nSnippet:\n```python\n# _start_webhook_mode: binds all interfaces\nself._webhook_site = web.TCPSite(self._webhook_runner, \"0.0.0.0\", self._webhook_port)\n\n# _handle_email_webhook: no signature/HMAC check, no auth\nbody = await request.json()\nif body.get(\"type\") != \"message.received\":\n    return web.Response(status=200, text=\"OK\")\nasyncio.create_task(self._process_webhook_payload(body))   # dispatch attacker body\nreturn web.Response(status=200, text=\"OK\")\n\n# _handle_message: agent processes content, replies to attacker-controlled sender\nresponse = await self._session.chat(self._agent, sender_id, body, ...)\nawait self.send_message(channel_id=sender_id, ...)\n```\nIssue: attacker-controlled input is the raw webhook JSON (`from`, `extracted_text`, `subject`). The guard that *should* exist is provider signature verification — there is **none** here (no svix/HMAC, no `webhooks_require_verification()` call). The sink is `self._session.chat(self._agent, ...)` (agent invocation) and `send_message(channel_id=sender_id, ...)` (reply to the spoofed sender). Sibling handlers `src/praisonai/praisonai/bots/linear.py` and `bots/whatsapp.py` call `webhooks_require_verification()` and reject when no secret is set — AgentMail does not, so it fails open.\n\n### Attack flow\n1. Operator runs the AgentMail bot in webhook/hybrid mode (documented; binds `0.0.0.0`, default path `/webhook`, default port 8080).\n2. Attacker POSTs a crafted `message.received` event with a spoofed `from` and arbitrary `extracted_text`.\n3. The agent processes the content; any reply is sent to the attacker-chosen `sender_id`.\n\n### Why existing protection is bypassed\nThere is no protection on this handler: no signature verification, no `webhooks_require_verification()` gate, no auth. Sender allow/block lists are bypassed because `from` is attacker-controlled.\n\n### Security boundary\nUnauthenticated network peer → agent message pipeline + reply destination. Crosses the bot's inbound trust boundary (provider webhooks are expected to be signed/authenticated).\n\n## Proof of Concept\n\n### Environment\nReal `AgentMailBot._handle_email_webhook` mounted in a local runtime (`127.0.0.1:18080`); the agent layer is a canary recorder (`/webhook-log`). No real email is sent. Runnable assets: `PraisonAI-Runtime-Repro\\runtime-files\\`.\n\n### Steps to reproduce\n1. `PRAI-03-01-Webhook-Spoofed-Sender`:\n```http\nPOST /webhook HTTP/1.1\nHost: 127.0.0.1:18080\nContent-Type: application/json\n\n{\"type\":\"message.received\",\"data\":{\"from\":\"attacker@evil.example\",\"extracted_text\":\"PRAISONAI_WEBHOOK_INJECT_CANARY_7f3a91 ...\",\"subject\":\"hello\",\"headers\":{}}}\n```\n2. `PRAI-03-02-Agent-Reached-Response`: `GET /webhook-log`.\n\n### Expected result\nThe webhook should reject unsigned/unauthenticated events; spoofed senders should not reach the agent.\n\n### Actual result\n- `POST /webhook` → `200 OK` (no auth/signature).\n- `GET /webhook-log` → `{\"reached_agent\":[{\"sender\":\"attacker@evil.example\",\"content\":\"...PRAISONAI_WEBHOOK_INJECT_CANARY_7f3a91...\",\"source\":\"webhook\"}],\"count\":1}`.\n\n## Impact\nUnauthenticated message injection into the agent; sender spoofing (access-control bypass); agent reply/exfiltration to an attacker-chosen address; prompt-injection surface; LLM cost abuse. If the agent has dangerous tools, escalation via prompt injection is possible.","cveId":"CVE-2026-61428","cvssScore":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","severity":"high","vendor":"PyPI","product":"praisonai","affectedVersions":["pkg:pypi/praisonai < 4.6.78"],"cwes":["CWE-290","CWE-345","CWE-862"],"tags":["osv","osv:ghsa-qj9c-59p6-8cgx","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-qj9c-59p6-8cgx","type":"advisory","title":"OSV GHSA-qj9c-59p6-8cgx"},{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-qj9c-59p6-8cgx","type":"other","title":"OSV web"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61428","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/MervinPraison/PraisonAI","type":"vendor","title":"OSV package"},{"url":"https://www.vulncheck.com/advisories/praisonai-agentmail-before-message-injection-via-webhook","type":"other","title":"OSV web"}],"epssScore":0.00373,"epssPercentile":0.29118,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T14:06:56.000Z","addedAt":"2026-10-07T18:42:45.500Z","updatedAt":"2026-10-07T18:42:45.500Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61428","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-61428","note":"authoritative record"},{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-qj9c-59p6-8cgx"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-qj9c-59p6-8cgx"}]},{"id":"317e745e-8181-4dde-b567-e20e4a0bd5dc","slug":"cve-2026-97146","externalId":"CVE-2026-97146","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-97146 — Apache YuniKorn 1.9.0 and earlier allows bypassing the check for the user annotation by setting a secondary label on the pod.","description":"Apache YuniKorn 1.9.0 and earlier allows bypassing the check for the user annotation by setting a secondary label on the pod. If the pod has the label 'app=yunikorn' the checks limiting the user annotation content are not run. The label is used to identify the YuniKorn application itself in the deployments.\n\n\nThe bypass allows any user to specify an arbitrary user info annotation. The arbitrary user information could allow access to a queue that the user normally would not have access to. Quota usage for the queue might be impacted if the application runs in the incorrect queue. User based quota enforcement is also based on the user annotation. User quota tracking could be side stepped even if the application runs in the correct queue.\n\n\n\n\nUsers are recommended to upgrade to version 1.10.0, which fixes this issue.","cveId":"CVE-2026-97146","cvssScore":4.8,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-290"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread.html/nds5ct9xzlo4fp0jfr1rx6jxm03g0jro","type":"advisory","title":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/07/26","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"}],"epssScore":0.00347,"epssPercentile":0.26151,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T10:17:43.693Z","addedAt":"2026-10-07T10:39:38.914Z","updatedAt":"2026-10-07T18:39:30.875Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97146","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-97146","note":"authoritative record"}]},{"id":"68a9f3c9-616d-40a6-83c0-aa808610c795","slug":"cve-2026-102161","externalId":"CVE-2026-102161","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102161 — An unauthenticated attacker located on an adjacent private network (or any attacker routed through a reverse proxy/load balancer that forwards clie…","description":"An unauthenticated attacker located on an adjacent private network (or any attacker routed through a reverse proxy/load balancer that forwards client headers) can forge their source IP address and gain administrative session privileges on the CV-CUE backend.","cveId":"CVE-2026-102161","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-290","CWE-798"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24806-security-advisory-0190","type":"advisory","title":"psirt@arista.com"}],"epssScore":0.00216,"epssPercentile":0.11017,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:11.230Z","addedAt":"2026-10-06T20:39:32.736Z","updatedAt":"2026-10-07T14:39:33.889Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102161","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102161","note":"authoritative record"}]},{"id":"36c07eba-13bd-4f90-9c79-7562b9e5fb04","slug":"cve-2026-105863","externalId":"CVE-2026-105863","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105863 — Payload is a free and open source headless content management system.","description":"Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, a custom field option that maps a field to a reserved authentication claim name can place unintended values in the authentication token issued at login. This issue is fixed in version 3.90.0.","cveId":"CVE-2026-105863","cvssScore":9.2,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":"npm","product":"payload","affectedVersions":["pkg:npm/payload >= 3.0.0, < 3.90.0","pkg:npm/payload >= 4.0.0-canary.0, < 4.0.0-canary.34"],"cwes":["CWE-290","CWE-915"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-66wr-7vmr-p5jq","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/payloadcms/payload/commit/56cd5cd050a57daebf33159e41e5ff9d4a45239c","type":"other","title":"OSV web"},{"url":"https://github.com/payloadcms/payload/releases/tag/v3.90.0","type":"other","title":"OSV web"},{"url":"https://github.com/payloadcms/payload/security/advisories/GHSA-66wr-7vmr-p5jq","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-66wr-7vmr-p5jq","type":"advisory","title":"OSV GHSA-66wr-7vmr-p5jq"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105863","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/payloadcms/payload","type":"vendor","title":"OSV package"}],"epssScore":0.00387,"epssPercentile":0.30627,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T17:17:22.570Z","addedAt":"2026-10-06T17:50:42.634Z","updatedAt":"2026-10-08T00:42:49.726Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105863","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105863","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-66WR-7VMR-P5JQ"}]},{"id":"3103bc0e-da3d-4f7b-9261-193735fcc675","slug":"cve-2026-97308","externalId":"CVE-2026-97308","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-97308 — Unauthenticated Bypass Vulnerability in Login Lockdown <= 2.17 versions.","description":"Unauthenticated Bypass Vulnerability in Login Lockdown <= 2.17 versions.","cveId":"CVE-2026-97308","cvssScore":4.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-290"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/login-lockdown/vulnerability/wordpress-login-lockdown-plugin-2-17-bypass-vulnerability-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":0.00193,"epssPercentile":0.08161,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T09:17:57.740Z","addedAt":"2026-10-06T09:50:44.251Z","updatedAt":"2026-10-06T15:51:00.167Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97308","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-97308","note":"authoritative record"}]},{"id":"c3374dff-6fc6-4526-ac71-9d6d6441621d","slug":"cve-2026-39772","externalId":"CVE-2026-39772","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-39772 — Unauthenticated Bypass Vulnerability in Captcha by BestWebSoft <= 5.2.8 versions.","description":"Unauthenticated Bypass Vulnerability in Captcha by BestWebSoft <= 5.2.8 versions.","cveId":"CVE-2026-39772","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-290"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/captcha-bws/vulnerability/wordpress-captcha-by-bestwebsoft-plugin-5-2-8-bypass-vulnerability-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":0.00357,"epssPercentile":0.27442,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T09:17:49.740Z","addedAt":"2026-10-06T09:50:43.930Z","updatedAt":"2026-10-06T15:50:59.861Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39772","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-39772","note":"authoritative record"}]},{"id":"7f874110-aca8-41f0-90fc-7d15b1c51225","slug":"cve-2026-105057","externalId":"CVE-2026-105057","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105057 — Unauthenticated Bypass Vulnerability in Zero Spam <= 5.7.11 versions.","description":"Unauthenticated Bypass Vulnerability in Zero Spam <= 5.7.11 versions.","cveId":"CVE-2026-105057","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-290"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/zero-spam/vulnerability/wordpress-zero-spam-plugin-5-7-11-bypass-vulnerability-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":0.00315,"epssPercentile":0.22381,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T09:17:40.133Z","addedAt":"2026-10-06T09:50:43.500Z","updatedAt":"2026-10-06T15:50:59.508Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105057","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105057","note":"authoritative record"}]},{"id":"780287dd-de20-489f-a24c-ad98542f10bd","slug":"cve-2026-41558","externalId":"CVE-2026-41558","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-41558 — Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions.","description":"Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions.","cveId":"CVE-2026-41558","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-290"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/wpsynchro/vulnerability/wordpress-wp-migration-plugin-db-files-wp-synchro-plugin-1-16-1-2fa-bypass-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":0.00259,"epssPercentile":0.16139,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T06:17:01.370Z","addedAt":"2026-10-06T07:50:40.693Z","updatedAt":"2026-10-06T15:50:59.206Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41558","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-41558","note":"authoritative record"}]},{"id":"4683757f-3414-4d49-8731-e86c5127d500","slug":"cve-2026-105741","externalId":"CVE-2026-105741","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105741 — Langflow is a tool for building and deploying AI-powered agents and workflows.","description":"Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.5.0 until 1.10.3, an IP spoofing vulnerability in the Model Context Protocol (MCP) configuration installation endpoint (POST /api/v1/mcp/project/{project_id}/install) allowed authenticated remote attackers to bypass the \"local-only\" access restriction. By sending a spoofed X-Forwarded-For: 127.0.0.1 header, an attacker could make the server treat the request as originating from localhost, letting them write/overwrite an MCP client configuration file on the server's filesystem. This vulnerability is fixed in 1.10.3.","cveId":"CVE-2026-105741","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L","severity":"high","vendor":"PyPI","product":"langflow","affectedVersions":["pkg:pypi/langflow >= 1.5.0, < 1.10.3"],"cwes":["CWE-290","CWE-345"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-4f6c-2vvp-gw82","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/langflow-ai/langflow/commit/1f39a4b9d62c9dfa1b21fa7f85e23a180c351b72","type":"other","title":"OSV web"},{"url":"https://github.com/langflow-ai/langflow/commit/94859df33acd70b2a1f816e26d68f5e89a7e5639","type":"other","title":"OSV web"},{"url":"https://github.com/langflow-ai/langflow/pull/13915","type":"other","title":"OSV web"},{"url":"https://github.com/langflow-ai/langflow/releases/tag/v1.10.3","type":"other","title":"OSV web"},{"url":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-4f6c-2vvp-gw82","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-4f6c-2vvp-gw82","type":"advisory","title":"OSV GHSA-4f6c-2vvp-gw82"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105741","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/langflow-ai/langflow","type":"vendor","title":"OSV package"}],"epssScore":0.00212,"epssPercentile":0.1053,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T21:16:35.740Z","addedAt":"2026-10-05T21:50:41.187Z","updatedAt":"2026-10-07T18:42:44.973Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105741","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105741","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-4F6C-2VVP-GW82"}]},{"id":"3f5f8058-d1d9-4692-afec-341172f311b4","slug":"cve-2026-105640","externalId":"CVE-2026-105640","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105640 — Plane is an open-source project management tool.","description":"Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by Gitea OAuth and by self-managed GitLab OAuth deployments where email confirmation is disabled, without verifying that the provider authenticated ownership of the address. An attacker can set an OAuth identity's unverified provider email to a victim's address, which Plane matches directly to the victim's existing local account. The attacker can then log in to the victim's Plane account without knowing the victim's password. GitHub, GitLab.com, and Google are not affected because those providers return verified email addresses. This issue is fixed in 1.4.0.","cveId":"CVE-2026-105640","cvssScore":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-287","CWE-290"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/makeplane/plane/commit/b91b61c379908d9e451613dbca23fc3803e926d2","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/makeplane/plane/pull/9289","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/makeplane/plane/releases/tag/v1.4.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/makeplane/plane/security/advisories/GHSA-7j95-vh8g-f365","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/makeplane/plane/security/advisories/GHSA-7j95-vh8g-f365","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00384,"epssPercentile":0.3031,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T19:17:18.383Z","addedAt":"2026-10-05T19:50:42.799Z","updatedAt":"2026-10-05T19:50:42.799Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105640","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105640","note":"authoritative record"}]},{"id":"d275c414-09e0-420d-acb8-24e540f7931e","slug":"cve-2026-104891","externalId":"CVE-2026-104891","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104891 — mppx-condition-gate provides conditional free-access wrappers for mppx payment methods.","description":"mppx-condition-gate provides conditional free-access wrappers for mppx payment methods. Prior to @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4, the packages read a wallet address from the client-supplied credential.source, checked whether that public address met configured on-chain conditions, and returned a successful free-access receipt without invoking the wrapped payment verifier or proving that the caller controlled the wallet. An unauthenticated attacker could name any qualifying wallet and obtain content that should require payment, and cached grants could be reused for the configured cache lifetime. The corrected packages prevent free-access authorization unless payer control has been established. These issues are fixed in @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4.","cveId":"CVE-2026-104891","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","severity":"high","vendor":"npm","product":"@insumermodel/mppx-condition-gate","affectedVersions":["pkg:npm/%40insumermodel/mppx-condition-gate < 3.0.0","pkg:npm/%40insumermodel/mppx-token-gate < 1.0.4"],"cwes":["CWE-290","CWE-863"],"tags":["nvd","status:received","status:deferred","osv","osv:ghsa-jg6q-3qfh-r9f8","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/insumerapi/mppx-condition-gate/commit/b1d9935a57ba6d32da49eead1bfb459ad0cd55ab","type":"other","title":"OSV web"},{"url":"https://github.com/insumerapi/mppx-condition-gate/commit/ec43a2fcd443a0fa102b6d4203abed2b785bd954","type":"other","title":"OSV web"},{"url":"https://github.com/insumerapi/mppx-condition-gate/security/advisories/GHSA-jg6q-3qfh-r9f8","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-jg6q-3qfh-r9f8","type":"advisory","title":"OSV GHSA-jg6q-3qfh-r9f8"},{"url":"https://github.com/douglasborthwick-crypto/mppx-condition-gate/security/advisories/GHSA-jg6q-3qfh-r9f8","type":"other","title":"OSV web"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104891","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/douglasborthwick-crypto/mppx-condition-gate","type":"vendor","title":"OSV package"}],"epssScore":0.00282,"epssPercentile":0.18986,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T16:17:06.447Z","addedAt":"2026-10-05T17:50:42.879Z","updatedAt":"2026-10-07T18:42:42.780Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104891","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104891","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-JG6Q-3QFH-R9F8"}]},{"id":"348dfba8-74b5-484a-bf45-d88bb64e54e2","slug":"cve-2026-103512","externalId":"CVE-2026-103512","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-103512 — Perforce P4 Search prior to 2026.4.2 trusts a client-supplied address when validating certain authentication requests.","description":"Perforce P4 Search prior to 2026.4.2 trusts a client-supplied address when validating certain authentication requests. An attacker holding a stolen P4 Server ticket can bypass host-based ticket restrictions and trusted-address controls, gaining access to P4 Search as the ticket's owner.","cveId":"CVE-2026-103512","cvssScore":5.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-290"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://portal.perforce.com/s/cve/a91Qi000003FDo1IAG/ticket-hostbinding-bypass-via-spoofed-client-ip-in-p4search","type":"advisory","title":"security@puppet.com"}],"epssScore":0.00374,"epssPercentile":0.29259,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T09:17:07.247Z","addedAt":"2026-10-05T09:50:40.777Z","updatedAt":"2026-10-06T15:50:57.306Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103512","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-103512","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":239,"totalPages":12,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:47:12.023Z","durationMs":26,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-290"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}