{"success":true,"data":{"threats":[{"id":"54b1ab83-1409-4f15-af0a-9e95904df9df","slug":"cve-2026-106566","externalId":"CVE-2026-106566","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106566 — ImageMagick is free and open-source software used for editing and manipulating digital images.","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, delegate symlink cleanup does not check the MAGICK_SHRED_PASSES environment variable, allowing a local privileged workflow to overwrite a file with random data. This issue is fixed in version 7.1.2-32.","cveId":"CVE-2026-106566","cvssScore":4,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-61"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ImageMagick/ImageMagick/commit/48e5ce1779fc640a389f0020fd7d965d0c08236e","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-54hm-vrmh-75qj","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick6/commit/11d2af00a948e9ca2919d9a8684d335a48484094","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.0012,"epssPercentile":0.01673,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T16:17:40.800Z","addedAt":"2026-10-07T16:39:32.554Z","updatedAt":"2026-10-08T21:05:41.936Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106566","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106566","note":"authoritative record"}]},{"id":"92c04a6c-8867-40d5-94d7-3d9683518c58","slug":"cve-2026-107174","externalId":"CVE-2026-107174","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107174 — A flaw was found in source-to-image.","description":"A flaw was found in source-to-image. When unpacking archive files, the application fails to properly sanitize symbolic links pointing to absolute file paths. An attacker who supplies a malicious builder image can exploit this vulnerability by embedding links pointing outside the extraction directory. This allows the attacker to bypass sandbox boundaries, potentially leading to unauthorized information disclosure or file modification on the host system.","cveId":"CVE-2026-107174","cvssScore":6.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-61"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-107174","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2547419","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.00285,"epssPercentile":0.193,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T15:17:19.190Z","addedAt":"2026-10-07T16:39:32.498Z","updatedAt":"2026-10-07T18:39:31.063Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107174","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107174","note":"authoritative record"}]},{"id":"1651320f-aa6f-4cee-87cc-fd181f5a0a37","slug":"cve-2026-103435","externalId":"CVE-2026-103435","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-103435 — Claude Code validated that a target file path resided within the project working directory at permission-check time, but re-resolved the path at wr…","description":"Claude Code validated that a target file path resided within the project working directory at permission-check time, but re-resolved the path at write time without repeating that validation. This time-of-check to time-of-use (TOCTOU) gap allowed an attacker who could write to the workspace to atomically replace a project file with a symlink, causing Claude Code to follow the symlink and write its output to an arbitrary file outside the project sandbox. Exploitation required the ability to win a race condition against the write operation and write access to the shared workspace, enabling a lower-privileged attacker to redirect benign edits to sensitive files (e.g., shell configuration) in a higher-privileged session.\n\nUsers on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version.\n\nThank you to hackerone.com/c_h4ck_0 for reporting this issue.","cveId":"CVE-2026-103435","cvssScore":7.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-22","CWE-61","CWE-367"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/anthropics/claude-code/security/advisories/GHSA-5j29-h97v-84ch","type":"advisory","title":"98a01053-8a31-4f6d-9aa9-252be161adc6"}],"epssScore":0.00251,"epssPercentile":0.15086,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T13:17:16.690Z","addedAt":"2026-10-07T14:39:35.072Z","updatedAt":"2026-10-07T16:39:32.117Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103435","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-103435","note":"authoritative record"}]},{"id":"7e52e0d6-8641-4a5d-8c35-a09a50ab5266","slug":"cve-2026-106507","externalId":"CVE-2026-106507","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106507 — Backstage is an open framework for building developer portals.","description":"Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by techdocs arbitrary file read via mkdocs snippets. Unsafe path resolution in TechDocs source tree handling allows an authenticated user who can register documentation sources to include content from outside the intended documentation boundary. Depending on deployment, this may expose files readable by the build process. This issue is fixed in version 1.15.4.","cveId":"CVE-2026-106507","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-59","CWE-61"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/backstage/backstage/commit/911ca36f10e654c5517da029129230fc05a4f580","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.54.6","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/backstage/backstage/security/advisories/GHSA-vmqh-7cj9-mvcj","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00283,"epssPercentile":0.19039,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T22:17:06.153Z","addedAt":"2026-10-06T22:39:33.249Z","updatedAt":"2026-10-07T16:39:31.372Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106507","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106507","note":"authoritative record"}]},{"id":"6efc432e-d9ba-49e4-8310-c369b435127f","slug":"cve-2026-105712","externalId":"CVE-2026-105712","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105712 — gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive.","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk.","cveId":"CVE-2026-105712","cvssScore":3.6,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-61"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","type":"advisory","title":"cve@mitre.org"},{"url":"https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","type":"advisory","title":"cve@mitre.org"},{"url":"https://static.dev.gnupg.org/T8159.html","type":"advisory","title":"cve@mitre.org"}],"epssScore":0.00123,"epssPercentile":0.01853,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T19:17:19.527Z","addedAt":"2026-10-05T19:50:42.839Z","updatedAt":"2026-10-06T17:50:42.118Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105712","note":"authoritative record"}]},{"id":"f80f0281-2f05-4e43-98c1-8c47e85875d6","slug":"ghsa-8w8g-wq8h-fq33","externalId":"GHSA-8w8g-wq8h-fq33","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"Dulwich: Symlink write-through in checkout(paths=[]) via raw os.open bypasses all symlink protections","description":"## Summary\n\nDulwich's `porcelain.checkout(paths=[...])` code path writes files using raw `os.open(file_path, O_WRONLY|O_CREAT|O_TRUNC, mode)` followed by `f.write(obj.data)`. This code path does NOT call `build_file_from_blob()` at all, completely bypassing any symlink protections (including the unreleased d09f8af fix). `os.open` without `O_NOFOLLOW` follows symlinks at both the target file and intermediate directories, allowing arbitrary file writes.\n\n## Root Cause\n\nAt `dulwich/porcelain/__init__.py:5661-5675`, the `checkout(paths=[...])` implementation:\n\n```python\nfile_path = _checked_worktree_path(r, path)\nos.makedirs(os.path.dirname(file_path), exist_ok=True)\nflags = os.O_WRONLY | os.O_CREAT | os.O_TRUNC\nwith os.fdopen(os.open(file_path, flags, mode), \"wb\") as f:\n    f.write(obj.data)\n```\n\n`_checked_worktree_path()` (line 601-631) only performs name validation — checking that the path doesn't start with `/` or `\\\\` and that components pass `INVALID_DOTNAMES` checks. It performs zero filesystem symlink detection.\n\n## Impact\n\nAn attacker can craft a malicious repository that, when a victim clones it and runs `checkout(paths=[...])`, writes attacker-controlled content (with attacker-controlled permissions) to any filesystem location accessible to the user. Writing to `.git/hooks/post-checkout` achieves RCE on the next git checkout.\n\n## Attack Scenario\n\n1. Attacker creates a repository where HEAD has `trigger` as a symlink (mode 120000, content `../../.git/hooks/post-checkout`), and tag `v1.0` has `trigger` as an executable file (mode 100755, content `#!/bin/sh\\nmalicious_payload`)\n2. Victim clones the repository — worktree has `trigger` → `../../.git/hooks/post-checkout` (a symlink)\n3. Victim runs `porcelain.checkout(repo, target=\"v1.0\", paths=[\"trigger\"])` to restore a specific file from a tag\n4. `_checked_worktree_path(r, \"trigger\")` passes — name validation only, no symlink check\n5. `os.open(\"trigger\", O_WRONLY|O_CREAT|O_TRUNC, 0o755)` follows the symlink → opens `.git/hooks/post-checkout` for writing\n6. `f.write(obj.data)` writes the malicious payload to the hook\n7. Next checkout operation triggers the hook → RCE\n\n## Suggested Fix\n\nReplace the raw `os.open` path with a call to `build_file_from_blob` (once that function is hardened against intermediate symlinks), or add explicit symlink detection: resolve the path with `os.path.realpath()` and verify it stays within the worktree root before opening.\n\nReported by **zx (Jace)**","cveId":null,"cvssScore":null,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","severity":"high","vendor":"PyPI","product":"dulwich","affectedVersions":["pkg:pypi/dulwich >= 0.24.0, < 1.2.8"],"cwes":["CWE-59","CWE-61"],"tags":["osv","osv:ghsa-8w8g-wq8h-fq33","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-8w8g-wq8h-fq33","type":"advisory","title":"OSV GHSA-8w8g-wq8h-fq33"},{"url":"https://github.com/jelmer/dulwich/security/advisories/GHSA-8w8g-wq8h-fq33","type":"other","title":"OSV web"},{"url":"https://github.com/jelmer/dulwich/commit/9389fcb5cb9113adfc7f207d8be86a56904db3e8","type":"other","title":"OSV web"},{"url":"https://github.com/jelmer/dulwich","type":"vendor","title":"OSV package"},{"url":"https://github.com/jelmer/dulwich/releases/tag/dulwich-1.2.8","type":"other","title":"OSV web"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T18:53:35.000Z","addedAt":"2026-10-02T19:54:22.609Z","updatedAt":"2026-10-02T19:54:22.609Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-8w8g-wq8h-fq33"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-8w8g-wq8h-fq33"}]},{"id":"852e2a68-7f1f-4b0c-96b8-ffb37dfc416e","slug":"cve-2026-97024","externalId":"CVE-2026-97024","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-97024 — A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to cause certa…","description":"A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to cause certain host system files (such as passwd, group, machine-id, or resolv.conf) to be emptied or replaced with a symlink when the app is installed or upgraded. In system-wide installations, the write is performed as root.","cveId":"CVE-2026-97024","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-61"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-97024","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2542625","type":"advisory","title":"secalert@redhat.com"},{"url":"https://github.com/flatpak/flatpak/security/advisories/GHSA-8xgq-v545-vgvf","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.00309,"epssPercentile":0.21798,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-29T04:18:02.397Z","addedAt":"2026-09-29T05:50:38.682Z","updatedAt":"2026-09-29T21:50:40.992Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97024","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-97024","note":"authoritative record"}]},{"id":"8d1f969a-3f15-45f1-92d3-bb6a90c0719f","slug":"cve-2026-97023","externalId":"CVE-2026-97023","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-97023 — A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause dele…","description":"A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of attacker-chosen files outside the deployment directory when the app is installed or upgraded. In system-wide installations, the deletion is performed as root.","cveId":"CVE-2026-97023","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-61"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-97023","type":"advisory","title":"secalert@redhat.com"},{"url":"https://github.com/flatpak/flatpak/security/advisories/GHSA-5p67-xh8x-rq54","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.00282,"epssPercentile":0.19012,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-28T19:16:50.710Z","addedAt":"2026-09-28T19:50:39.873Z","updatedAt":"2026-09-29T21:50:40.750Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97023","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-97023","note":"authoritative record"}]},{"id":"edadc9f5-e647-4e47-9676-da8593f0179b","slug":"cve-2026-12958","externalId":"GHSA-6v3r-4p5c-mrp5","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"Language Servers for AWS vulnerable to arbitrary file write","description":"## Summary\nLanguage Servers for AWS (the aws/language-servers project) provides the Language Server Protocol implementations that power AWS developer tooling, including the Amazon Q Developer agentic chat experience, across IDEs such as VS Code, JetBrains, Visual Studio, and Eclipse.\n\nMissing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur when a local user opens a workspace containing a maliciously crafted symlink that resolves to a file path outside the workspace trust boundary.\n\n## Impact\n\nIf a user opens a maliciously crafted workspace containing a symlink that resides within the workspace but resolves to a location outside the workspace trust boundary, the agent may follow that symlink and write to the external location without prompting the user for approval. This can result in the modification of files outside the intended workspace boundary.\n\nThis issue is triggered when a user opens a workspace, trusts it, and the agent subsequently writes to a path within that workspace.\n\nImpacted versions: Language Servers for AWS version <1.69.0.\n\n## Patches\nThis issue has been addressed in AWS Language Servers version 1.69.0. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. \n\n## Workarounds\nNo workarounds are available.\n\n## References\nIf you have any questions or comments about this advisory, AWS Security ask that you contact them via their [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue.\n\n## Acknowledgement \n\nAWS Security would like to thank Wiz and Maor Dokhanian for collaborating on this issue through the coordinated vulnerability disclosure process.","cveId":"CVE-2026-12958","cvssScore":null,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","severity":"high","vendor":"npm","product":"@aws/lsp-codewhisperer","affectedVersions":["pkg:npm/%40aws/lsp-codewhisperer < 0.0.117"],"cwes":["CWE-61"],"tags":["osv","osv:ghsa-6v3r-4p5c-mrp5","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-6v3r-4p5c-mrp5","type":"advisory","title":"OSV GHSA-6v3r-4p5c-mrp5"},{"url":"https://github.com/aws/language-servers/security/advisories/GHSA-6v3r-4p5c-mrp5","type":"other","title":"OSV web"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12958","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/Amazon-Q-Developer/language-servers/pull/2742","type":"other","title":"OSV web"},{"url":"https://github.com/Amazon-Q-Developer/language-servers/commit/6c279b083cc192aa5df1f38c2c185576fd5234f5","type":"other","title":"OSV web"},{"url":"https://aws.amazon.com/security/security-bulletins/2026-047-aws","type":"other","title":"OSV web"},{"url":"https://github.com/Amazon-Q-Developer/language-servers/releases/tag/agentic-rc-1.69.0","type":"other","title":"OSV web"},{"url":"https://github.com/Amazon-Q-Developer/language-servers/releases/tag/lsp-codewhisperer/v0.0.117","type":"other","title":"OSV web"},{"url":"https://github.com/aws/language-servers","type":"vendor","title":"OSV package"}],"epssScore":0.00191,"epssPercentile":0.08033,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-24T19:15:39.000Z","addedAt":"2026-09-24T19:54:26.170Z","updatedAt":"2026-09-24T19:54:26.170Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12958","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-12958","note":"authoritative record"},{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-6v3r-4p5c-mrp5"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-6v3r-4p5c-mrp5"}]},{"id":"5776e4ad-6d24-40b7-810f-3119f3b56e0a","slug":"cve-2026-96808","externalId":"CVE-2026-96808","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-96808 — In Flatpak before 1.18.1, the revokefs writer, used by the flatpak-system-helper to receive repository data from unprivileged callers, validated fi…","description":"In Flatpak before 1.18.1, the revokefs writer, used by the flatpak-system-helper to receive repository data from unprivileged callers, validated file paths by rejecting literal .. components but did not prevent symlink traversal. A malicious local user in an active local session could obtain two revokefs sessions via the system helper, create a symlink in one session pointing into the other session's directory, and retain a file descriptor through that symlink. This allowed the attacker to modify files belonging to a different revokefs session after they had been validated and imported by the system helper. In particular, an attacker could use this to tamper with ostree commit objects in the system repository after they passed signature verification, enabling root-controlled file writes to attacker-chosen paths and local root privilege escalation.","cveId":"CVE-2026-96808","cvssScore":7.4,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-61"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/flatpak/flatpak/security/advisories/GHSA-qrwq-7qwx-q9rp","type":"advisory","title":"cve@mitre.org"}],"epssScore":0.00119,"epssPercentile":0.01626,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-23T17:17:25.860Z","addedAt":"2026-09-23T17:50:40.114Z","updatedAt":"2026-09-24T21:50:43.977Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-96808","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-96808","note":"authoritative record"}]},{"id":"dabeab70-f411-4cd7-a077-6f0018b74448","slug":"cve-2026-96807","externalId":"CVE-2026-96807","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-96807 — In Flatpak before 1.18.1, a malicious sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink, causing regenerate_ld_cache to write files…","description":"In Flatpak before 1.18.1, a malicious sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink, causing regenerate_ld_cache to write files at an arbitrary location. The filenames and content are not attacker controlled, making this hard to exploit.","cveId":"CVE-2026-96807","cvssScore":4,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-61"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/flatpak/flatpak/security/advisories/GHSA-99wv-m8rp-g58x","type":"advisory","title":"cve@mitre.org"}],"epssScore":0.00123,"epssPercentile":0.01822,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-23T17:17:25.703Z","addedAt":"2026-09-23T17:50:40.108Z","updatedAt":"2026-09-26T23:50:37.946Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-96807","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-96807","note":"authoritative record"}]},{"id":"7bbf0aa5-15ab-48bc-a80b-71503e27fdc2","slug":"cve-2026-91202","externalId":"CVE-2026-91202","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-91202 — A flaw was found in cockpit-files.","description":"A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by crafting a directory containing a symbolic link (symlink) and then using the privileged \"Paste as owner\" function. This allows for arbitrary file ownership changes outside the intended pasted directory, leading to a compromise of data integrity. In some cases, this could also lead to reduced confidentiality if the new ownership grants unauthorized read access. Exploitation requires user interaction to select a non-original owner during the paste operation.","cveId":"CVE-2026-91202","cvssScore":6.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:L","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-61"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-91202","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2465834","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.00123,"epssPercentile":0.0182,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-18T20:17:29.260Z","addedAt":"2026-09-18T21:50:39.138Z","updatedAt":"2026-09-22T19:50:40.262Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91202","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-91202","note":"authoritative record"}]},{"id":"4d5e8ede-c3cf-49be-b81c-1be600e49619","slug":"cve-2026-91099","externalId":"CVE-2026-91099","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-91099 — HP has identified and remediated multiple externally reported vulnerabilities within HPLIP.","description":"HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.","cveId":"CVE-2026-91099","cvssScore":5.1,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":"hp","product":"linux imaging and printing","affectedVersions":["< 3.26.6"],"cwes":["CWE-61"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00981,"epssPercentile":0.61117,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-16T19:18:02.490Z","addedAt":"2026-09-16T19:50:47.335Z","updatedAt":"2026-09-21T17:50:41.196Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91099","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-91099","note":"authoritative record"}]},{"id":"2d4105c0-50e6-4054-a29a-546347e86229","slug":"cve-2026-90616","externalId":"CVE-2026-90616","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-90616 — In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbi…","description":"In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulnerability than CVE-2026-76925. Flatpak creates a few app data directories (e.g., /var/cache, /var/data, /var/config, and /var/tmp) in every sandbox on every app launch where, in some cases, components of the path are attacker-controlled. Missing symlink protection can redirect the directories. Some of these directories are bind-mounted by Flatpak by passing the path (e.g., /home/user/.var/app/APP_ID/cache/tmp), which contains attacker-controlled directories (tmp) to bwrap --bind SRC DST. bwrap passes the path on to the kernel, which then follows symlinks. A malicious symlink can point to arbitrary locations on the host and it will become mounted inside the sandbox.","cveId":"CVE-2026-90616","cvssScore":7.4,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-61"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/flatpak/flatpak/security/advisories/GHSA-8688-9x26-hhxj","type":"advisory","title":"cve@mitre.org"},{"url":"https://www.openwall.com/lists/oss-security/2026/08/11/9","type":"advisory","title":"cve@mitre.org"}],"epssScore":0.00176,"epssPercentile":0.06566,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-12T20:16:30.957Z","addedAt":"2026-09-12T21:50:33.815Z","updatedAt":"2026-09-22T21:50:38.701Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90616","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-90616","note":"authoritative record"}]},{"id":"c4664fe2-78f2-4e7e-a153-abc58923bdf6","slug":"cve-2026-77159","externalId":"CVE-2026-77159","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-77159 — A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function.","description":"A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm account can replace the logfile with a symlink, causing libvirtd (running as root) to transfer ownership of an arbitrary file to the swtpm user.","cveId":"CVE-2026-77159","cvssScore":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-61"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-77159","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2531811","type":"advisory","title":"secalert@redhat.com"},{"url":"https://gitlab.com/libvirt/libvirt/-/work_items/909","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00162,"epssPercentile":0.04866,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-11T11:16:54.677Z","addedAt":"2026-09-11T11:50:34.190Z","updatedAt":"2026-09-16T19:50:38.370Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77159","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-77159","note":"authoritative record"}]},{"id":"43e948fc-b08a-4e74-96ad-c3dd9c952e30","slug":"cve-2026-57825","externalId":"CVE-2026-57825","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-57825 — In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install…","description":"In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.","cveId":"CVE-2026-57825","cvssScore":5.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-61"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ocaml/opam/releases","type":"advisory","title":"cve@mitre.org"},{"url":"https://osv.dev/vulnerability/OSEC-2026-10","type":"advisory","title":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2026/07/msg00026.html","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"}],"epssScore":0.00472,"epssPercentile":0.38873,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-09T04:18:01.720Z","addedAt":"2026-09-09T05:50:38.869Z","updatedAt":"2026-09-14T17:50:34.851Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57825","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-57825","note":"authoritative record"}]},{"id":"c5cc06a7-f428-470d-94d0-6e165cf0a7e6","slug":"cve-2026-81727","externalId":"CVE-2026-81727","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-81727 — NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods t…","description":"NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a shared downloader directory can create hardlinks pointing to outside-root files that are then overwritten during normal package extraction, mutating files outside the intended install tree.","cveId":"CVE-2026-81727","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":"nltk","product":"nltk","affectedVersions":["< 3.10.3","pkg:pypi/nltk < 3.10.3"],"cwes":["CWE-59","CWE-61","CWE-73"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed","osv","osv:pysec-2026-3741","ecosystem:pypi","osv:ghsa-f794-5jv7-7672"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/nltk/nltk/security/advisories/GHSA-f794-5jv7-7672","type":"other","title":"OSV web"},{"url":"https://www.vulncheck.com/advisories/nltk-before-3.10.3-hardlink-file-overwrite-via-downloader","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/PYSEC-2026-3741","type":"advisory","title":"OSV PYSEC-2026-3741"},{"url":"https://osv.dev/vulnerability/GHSA-f794-5jv7-7672","type":"advisory","title":"OSV GHSA-f794-5jv7-7672"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81727","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/nltk/nltk/pull/3797","type":"other","title":"OSV web"},{"url":"https://github.com/nltk/nltk/commit/9e6d5f05902b9aaa1221a0a565448d17a9c9b3e8","type":"other","title":"OSV web"},{"url":"https://github.com/nltk/nltk","type":"vendor","title":"OSV package"},{"url":"https://github.com/nltk/nltk/releases/tag/v3.10.3","type":"other","title":"OSV web"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2026-3741.yaml","type":"other","title":"OSV web"}],"epssScore":0.00187,"epssPercentile":0.07624,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-27T17:21:03.533Z","addedAt":"2026-08-27T17:50:36.118Z","updatedAt":"2026-09-04T19:54:25.421Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81727","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-81727","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/PYSEC-2026-3741"}]},{"id":"1f0bba20-a684-4f6a-a3b5-b8de0714c426","slug":"cve-2026-79939","externalId":"CVE-2026-79939","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-79939 — Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerability.","description":"Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Script injection.","cveId":"CVE-2026-79939","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"dell","product":"powerprotect cyber recovery","affectedVersions":["< 20.3.0.0"],"cwes":["CWE-61"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.dell.com/support/kbdoc/en-us/000501456/dsa-2026-370-security-update-for-dell-powerprotect-cyber-recovery-multiple-third-party-component-vulnerabilities","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.0017,"epssPercentile":0.05747,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-26T20:18:14.263Z","addedAt":"2026-08-26T21:50:31.339Z","updatedAt":"2026-09-01T17:50:31.996Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-79939","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-79939","note":"authoritative record"}]},{"id":"01a9f2a2-04ff-40be-9937-4bf9204fe1aa","slug":"cve-2026-75038","externalId":"CVE-2026-75038","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-75038 — UNIX symbolic link (symlink) following vulnerability in ilya-zlobintsev/LACT allows for local denial-of-service.","description":"UNIX symbolic link (symlink) following vulnerability in ilya-zlobintsev/LACT allows for local denial-of-service. This issue affects LACT: through 0.10.0.","cveId":"CVE-2026-75038","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-61"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://bugzilla.suse.com/show_bug.cgi?id=1276481","type":"advisory","title":"meissner@suse.de"},{"url":"https://github.com/ilya-zlobintsev/LACT","type":"advisory","title":"meissner@suse.de"}],"epssScore":0.00162,"epssPercentile":0.04865,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-25T10:18:13.267Z","addedAt":"2026-08-25T11:50:31.686Z","updatedAt":"2026-09-28T23:50:38.736Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75038","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-75038","note":"authoritative record"}]},{"id":"3c3c9be9-5c25-499e-9923-cb04952de1f8","slug":"cve-2026-55168","externalId":"CVE-2026-55168","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-55168 — Runtipi is a personal homeserver orchestrator.","description":"Runtipi is a personal homeserver orchestrator. In 4.10.0 and earlier, Runtipi accepts symbolic links from an attacker-controlled backup archive and copies them into live application paths during the backup restore flow. An authenticated attacker can plant user-config/app.env as a symlink to an arbitrary reachable path and then send PUT /api/user-config/demoapp3:_user with attacker-controlled appEnv content. FilesystemService.writeTextFile() follows the planted link, allowing content to be written outside the intended restore and user-config directory boundary with Runtipi process permissions. This issue is fixed in version 4.10.1.","cveId":"CVE-2026-55168","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-59","CWE-61"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/runtipi/runtipi/commit/df529a211b05f3a0007b209b6c337f8c1942619c","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/runtipi/runtipi/pull/2606","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/runtipi/runtipi/releases/tag/v4.10.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/runtipi/runtipi/security/advisories/GHSA-wcrf-g9p9-2wg7","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00609,"epssPercentile":0.47508,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-21T21:17:00.410Z","addedAt":"2026-08-21T21:50:28.866Z","updatedAt":"2026-09-30T21:50:42.236Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55168","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-55168","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":57,"totalPages":3,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:51:52.569Z","durationMs":24,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-61"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}