{"success":true,"data":{"threats":[{"id":"22d02698-7738-45d6-9c28-f6c8c25ff9db","slug":"cve-2026-61437","externalId":"GHSA-4gfv-wg42-7jw5","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"PraisonAI: Unsafe Dynamic Module Loading Leads to Arbitrary Code Execution via tools.py in AgentFlow","description":"### Summary\nAn unsafe dynamic module loading vulnerability allows an attacker who can control a workflow file and a sibling `tools.py` to execute arbitrary Python code when the workflow is executed.\n\n### Details\nThe vulnerability is located in the workflow structured output resolution logic.\n\nFile: src/praisonai-agents/praisonaiagents/workflows/workflows.py\n\nMethod: AgentFlow._resolve_pydantic_class\n\n```python\nif self.file_path:\n    workflow_dir = Path(self.file_path).parent\n    tools_path = workflow_dir / \"tools.py\"\n\n    if tools_path.exists():\n        spec = importlib.util.spec_from_file_location(\"tools\", tools_path)\n        tools_module = importlib.util.module_from_spec(spec)\n        spec.loader.exec_module(tools_module)   # Arbitrary code execution\n```\n\nThis code is reached during step execution when a step uses a string `output_pydantic`:\n\n```python\nstep_output_pydantic = getattr(step, '_output_pydantic', None)\nif step_output_pydantic and isinstance(step_output_pydantic, str):\n    resolved_class = self._resolve_pydantic_class(step_output_pydantic)\n```\n\n`file_path` is set automatically by:\n- `WorkflowManager._load_workflow()` (used by workspace discovery)\n- `WorkflowManager.create_workflow()`\n\nIt can also be set manually after `load_yaml()`:\n```python\nwf = mgr.load_yaml(\"workflow.yaml\")\nwf.file_path = \"workflow.yaml\"\n```\n\nThe `exec_module()` call has no sandboxing and ignores the `PRAISONAI_ALLOW_*_TOOLS` environment variables used elsewhere in the project.\n\n\n### PoC\nCreate the following two files in the same directory:\n\n`/tmp/attack/attack.yaml`\n```yaml\nname: AttackWorkflow\nsteps:\n  - name: generate\n    action: \"Produce structured output\"\n    output_pydantic: MaliciousModel\n```\n\n`/tmp/attack/tools.py`\n```python\nprint(\"[RCE] Arbitrary code executed from tools.py\")\n\nimport os\nwith open(\"/tmp/rce_success.txt\", \"w\") as f:\n    f.write(f\"RCE executed by PID {os.getpid()}\")\n\nclass MaliciousModel:\n    @classmethod\n    def model_json_schema(cls):\n        return {\"type\": \"object\"}\n```\n\nRun the following Python code (adjust the path to your PraisonAI source):\n\n```python\nimport sys\nsys.path.insert(0, \"/home/user/praisonai/src/praisonai-agents\")\n\nfrom praisonaiagents.workflows import WorkflowManager\nfrom praisonaiagents.agent.agent import Agent\n\nmgr = WorkflowManager()\nwf = mgr.load_yaml(\"/tmp/attack/attack.yaml\")\n\nwf.file_path = \"/tmp/attack/attack.yaml\"\n\nfor step in wf.steps:\n    step.output_pydantic = \"MaliciousModel\"\n    step._output_pydantic = \"MaliciousModel\"\n    if not getattr(step, \"agent\", None):\n        step.agent = Agent(\n            name=\"researcher\",\n            role=\"Researcher\",\n            goal=\"Generate output\",\n            instructions=\"Return structured data\"\n        )\n\nwf.start(\"trigger\")\n```\n\n### Impact\nType: Execution of Untrusted Local Code via Unsafe Dynamic Module Loading.\n\nAffected users include:\n\n- Users of `WorkflowManager(workspace_path=...)`, where workflow discovery automatically sets `file_path`.\n- Users of `WorkflowManager.create_workflow()`.\n- Applications that load workflows from repositories, templates, shared workflow collections, CI/CD artifacts, or other directories that may contain untrusted files.\n\nDuring workflow execution, a string `output_pydantic` reference causes the framework to automatically locate, import, and execute a sibling `tools.py` file.\n\nAs a result, code contained in `tools.py` executes with the privileges of the workflow runner without requiring an explicit import or user approval step.\n\nSuccessful exploitation results in arbitrary Python code execution within the workflow process. An attacker may be able to read local files, access secrets available to the process, modify workflow behavior, perform network operations, or execute additional system commands.\n\nThis behavior also bypasses the `PRAISONAI_ALLOW_TEMPLATE_TOOLS` / `PRAISONAI_ALLOW_LOCAL_TOOLS` protections used elsewhere in the project, allowing code execution through a separate workflow-resolution path.","cveId":"CVE-2026-61437","cvssScore":null,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"PyPI","product":"praisonaiagents","affectedVersions":["pkg:pypi/praisonaiagents < 1.6.78"],"cwes":["CWE-693","CWE-829"],"tags":["osv","osv:ghsa-4gfv-wg42-7jw5","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-4gfv-wg42-7jw5","type":"advisory","title":"OSV GHSA-4gfv-wg42-7jw5"},{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-4gfv-wg42-7jw5","type":"other","title":"OSV web"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61437","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/MervinPraison/PraisonAI","type":"vendor","title":"OSV package"},{"url":"https://www.vulncheck.com/advisories/praisonai-before-remote-code-execution-via-tools-py","type":"other","title":"OSV web"}],"epssScore":0.00174,"epssPercentile":0.0624,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:48:57.000Z","addedAt":"2026-10-08T18:42:42.684Z","updatedAt":"2026-10-08T18:42:42.684Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61437","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-61437","note":"authoritative record"},{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-4gfv-wg42-7jw5"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-4gfv-wg42-7jw5"}]},{"id":"7ac00845-383f-4437-bd85-0866f0e48f9f","slug":"cve-2026-105331","externalId":"CVE-2026-105331","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105331 — Local privilege escalation in Checkmk 2.5.0 before 2.5.0p10 allows a user with access to edit the Oracle Instant Client referenced by the agent plu…","description":"Local privilege escalation in Checkmk 2.5.0 before 2.5.0p10 allows a user with access to edit the Oracle Instant Client referenced by the agent plugin 'mk-oracle' to escalate their privileges if an agent has this plugin enabled.","cveId":"CVE-2026-105331","cvssScore":5.2,"cvssVector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-426","CWE-829"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://checkmk.com/werk/22619","type":"advisory","title":"security@checkmk.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:32.530Z","addedAt":"2026-10-08T16:39:35.584Z","updatedAt":"2026-10-08T16:39:35.584Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105331","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105331","note":"authoritative record"}]},{"id":"0cfa0b29-b568-433e-aaec-896ecffe231a","slug":"cve-2026-105745","externalId":"CVE-2026-105745","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105745 — Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem.","description":"Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.27.0 until 2.131.0, Docling plugin factories in docling/models/factories/base_factory.py call load_setuptools_entrypoints() before applying the allow_external_plugins setting, so every module registered in the Docling entry-point group is imported even when external plugins are disabled. An installed third-party or compromised package can therefore execute import-time code when Docling starts, while the subsequent namespace filter misleadingly reports that the plugin was not loaded. This issue is fixed in 2.131.0.","cveId":"CVE-2026-105745","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"docling","product":"docling","affectedVersions":[">= 2.27.0, < 2.131.0","pkg:pypi/docling >= 2.27.0, < 2.131.0","pkg:pypi/docling-slim >= 2.92.0, < 2.131.0"],"cwes":["CWE-696","CWE-829"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed","osv","osv:ghsa-9jxx-vjrv-h2rq","ecosystem:pypi","osv:pysec-2026-4192"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/docling-project/docling/commit/0f443b3786e98688a2da3b7c8f56fe5e46af876c","https://github.com/docling-project/docling/pull/4413","https://github.com/docling-project/docling/security/advisories/GHSA-9jxx-vjrv-h2rq"],"references":[{"url":"https://github.com/docling-project/docling/commit/0f443b3786e98688a2da3b7c8f56fe5e46af876c","type":"patch","title":"OSV fix"},{"url":"https://github.com/docling-project/docling/pull/4413","type":"patch","title":"OSV fix"},{"url":"https://github.com/docling-project/docling/releases/tag/v2.131.0","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/docling-project/docling/security/advisories/GHSA-9jxx-vjrv-h2rq","type":"patch","title":"OSV fix"},{"url":"https://osv.dev/vulnerability/GHSA-9jxx-vjrv-h2rq","type":"advisory","title":"OSV GHSA-9jxx-vjrv-h2rq"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105745","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/docling-project/docling","type":"vendor","title":"OSV package"},{"url":"https://osv.dev/vulnerability/PYSEC-2026-4192","type":"advisory","title":"OSV PYSEC-2026-4192"}],"epssScore":0.0012,"epssPercentile":0.01667,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T22:16:57.330Z","addedAt":"2026-10-05T23:50:40.383Z","updatedAt":"2026-10-08T12:42:40.377Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105745","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105745","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-9JXX-VJRV-H2RQ"}]},{"id":"d935c90d-aea6-48c6-a9b4-ef8fefe7a32d","slug":"cve-2026-105677","externalId":"CVE-2026-105677","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105677 — Ghost is a Node.js content management system.","description":"Ghost is a Node.js content management system. From 6.10.3 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to execute arbitrary code on the server via a crafted theme. This issue is fixed in version 6.64.0.","cveId":"CVE-2026-105677","cvssScore":7.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-22","CWE-94","CWE-829"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/TryGhost/Ghost/commit/d2f498694be549074dd5817fd0e8a1371b65df02","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/TryGhost/Ghost/issues/30635","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/TryGhost/Ghost/releases/tag/v6.64.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/TryGhost/Ghost/security/advisories/GHSA-jj74-hc2q-xrvm","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00523,"epssPercentile":0.42584,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T20:17:14.733Z","addedAt":"2026-10-05T21:50:40.972Z","updatedAt":"2026-10-06T15:50:58.469Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105677","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105677","note":"authoritative record"}]},{"id":"c05c0172-9526-409e-bcd6-b745b3e7ea98","slug":"cve-2026-12171","externalId":"CVE-2026-12171","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-12171 — auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.…","description":"auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.json) into its options, and honors security-sensitive options from that untrusted source. The handlebarsSetup option is passed to require(), so running auto-changelog over attacker-controlled repository content (for example, in a CI workflow that checks out an untrusted pull request head, or locally on a forked or third-party repository) executes attacker-chosen code with the privileges of the invoking user or CI job, including access to workflow secrets, without the repository dependencies ever being installed. The plugins option similarly loads attacker-controlled modules from the repository. Under the same conditions, appendGitLog/appendGitTag allow git argument injection (e.g. --output= to write arbitrary files), output allows writing attacker-influenced content to arbitrary paths, and template causes an outbound request to an attacker-chosen URL. Version 2.6.1 treats in-repository configuration as untrusted and refuses to run when it sets these options, unless the new --unsafe-config flag is passed.","cveId":"CVE-2026-12171","cvssScore":8.4,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-22","CWE-88","CWE-94","CWE-829","CWE-918"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/cookpete/auto-changelog/commit/1d02a48a0a57c69a3cd268aca375d64d50877c1a","type":"advisory","title":"7ffcee3d-2c14-4c3e-b844-86c6a321a158"},{"url":"https://github.com/cookpete/auto-changelog/security/advisories/GHSA-xpvr-2hvx-m8q4","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00218,"epssPercentile":0.11251,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T17:17:14.510Z","addedAt":"2026-10-05T17:50:43.068Z","updatedAt":"2026-10-06T17:50:42.093Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12171","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-12171","note":"authoritative record"}]},{"id":"f86edaab-4514-40d6-91da-b37b79529351","slug":"cve-2026-63277","externalId":"CVE-2026-63277","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-63277 — LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document.","description":"LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location. In fixed versions an entry in a Java class path has to be a file URL.","cveId":"CVE-2026-63277","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-829"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.libreoffice.org/about-us/security/advisories/cve-2026-63277","type":"advisory","title":"security@documentfoundation.org"}],"epssScore":0.00145,"epssPercentile":0.03238,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T12:17:11.253Z","addedAt":"2026-10-05T13:50:41.003Z","updatedAt":"2026-10-06T15:50:57.696Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63277","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-63277","note":"authoritative record"}]},{"id":"d6bab3fb-7d29-4ac5-82a8-7ac9f150dffa","slug":"cve-2026-104811","externalId":"CVE-2026-104811","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104811 — DigitalCanion SA has discovered a vulnerability that allows remote attackers to execute arbitrary code on affected installations of the product.","description":"DigitalCanion SA has discovered a vulnerability that allows remote attackers to execute arbitrary code on affected installations of the product. Authentication may be required to exploit this vulnerability.\n\n\n\n\nThe specific flaw exists within the Configuration → Services → Music on Hold functionality of the web portal listening on TCP port 443. The application is intended to allow users to upload WAV audio files but fails to properly validate the uploaded file type. An attacker can exploit this behavior to upload a malicious shared object (.so) instead of a WAV file. When the uploaded file is subsequently processed by the affected component, attacker-controlled code is loaded and executed in the context of the affected process. This can result in remote code execution and potentially full compromise of the underlying Linux system.","cveId":"CVE-2026-104811","cvssScore":8.4,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Amber","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-20","CWE-94","CWE-434","CWE-829"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://digitalcanion.com/en/security-research/#vendor=mitel&status=cna","type":"advisory","title":"vulnerability@ncsc.ch"}],"epssScore":0.00195,"epssPercentile":0.08367,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T09:17:10.290Z","addedAt":"2026-10-05T09:50:40.909Z","updatedAt":"2026-10-06T15:50:57.460Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104811","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104811","note":"authoritative record"}]},{"id":"421ecc28-84d1-42c9-95d5-11059c8bdf33","slug":"cve-2026-104809","externalId":"CVE-2026-104809","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104809 — DigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load an attacker-controlled .so file instead of the exp…","description":"DigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load an attacker-controlled .so file instead of the expected legitimate module. The loading mechanism relies on a predictable module name without adequately verifying the file’s origin or integrity. A malicious shared object using the expected name can therefore be loaded by a privileged process. The module code then executes within the context and privileges of that process. This results in arbitrary code execution and full compromise of the Mitel Linux virtual machine.","cveId":"CVE-2026-104809","cvssScore":8.4,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Amber","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-73","CWE-426","CWE-427","CWE-494","CWE-829"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://digitalcanion.com/en/security-research/#vendor=mitel&status=cna","type":"advisory","title":"vulnerability@ncsc.ch"}],"epssScore":0.00087,"epssPercentile":0.00329,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T09:17:10.007Z","addedAt":"2026-10-05T09:50:40.896Z","updatedAt":"2026-10-06T15:50:57.446Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104809","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104809","note":"authoritative record"}]},{"id":"931a678a-bea0-49b8-8660-0dbae2a9d165","slug":"cve-2026-105080","externalId":"CVE-2026-105080","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105080 — In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre.","description":"In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects executable code in a .recipe or .downloaded_recipe file.","cveId":"CVE-2026-105080","cvssScore":9.4,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-829"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/C4illin/ConvertX/commit/0ca17dad7fa65e2e34823b59b95dd00bb1066b66","type":"advisory","title":"cve@mitre.org"},{"url":"https://github.com/C4illin/ConvertX/releases/tag/v0.19.0","type":"advisory","title":"cve@mitre.org"},{"url":"https://github.com/C4illin/ConvertX/security/advisories/GHSA-m4hh-rqmf-c8hw","type":"advisory","title":"cve@mitre.org"}],"epssScore":0.00333,"epssPercentile":0.24452,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-03T01:17:23.650Z","addedAt":"2026-10-03T03:50:40.212Z","updatedAt":"2026-10-06T17:50:41.820Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105080","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105080","note":"authoritative record"}]},{"id":"5b456c46-d066-4f0e-b279-bdd449568276","slug":"cve-2026-104418","externalId":"CVE-2026-104418","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104418 — Ghost from 6.10.3 before 6.64.0 contains a remote code execution vulnerability that allows authenticated administrators to run code by abusing them…","description":"Ghost from 6.10.3 before 6.64.0 contains a remote code execution vulnerability that allows authenticated administrators to run code by abusing theme translation file loading. Attackers with administrator access can upload a crafted theme containing malicious translation files to execute arbitrary code on the Ghost server.","cveId":"CVE-2026-104418","cvssScore":8.6,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"npm","product":"ghost","affectedVersions":["pkg:npm/ghost >= 6.10.3, < 6.64.0"],"cwes":["CWE-22","CWE-829","CWE-94"],"tags":["nvd","status:received","status:deferred","osv","osv:ghsa-jj74-hc2q-xrvm","ecosystem:npm"],"relatedCves":["CVE-2026-105677"],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/TryGhost/Ghost/security/advisories/GHSA-jj74-hc2q-xrvm","type":"other","title":"OSV web"},{"url":"https://www.vulncheck.com/advisories/ghost-from-6.10.3-before-6.64.0-rce-via-theme-translation-files","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://osv.dev/vulnerability/GHSA-jj74-hc2q-xrvm","type":"advisory","title":"OSV GHSA-jj74-hc2q-xrvm"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105677","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/TryGhost/Ghost/issues/30635","type":"other","title":"OSV web"},{"url":"https://github.com/TryGhost/Ghost/commit/d2f498694be549074dd5817fd0e8a1371b65df02","type":"other","title":"OSV web"},{"url":"https://github.com/TryGhost/Ghost","type":"vendor","title":"OSV package"},{"url":"https://github.com/TryGhost/Ghost/releases/tag/v6.64.0","type":"other","title":"OSV web"}],"epssScore":0.00654,"epssPercentile":0.49788,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T12:17:11.710Z","addedAt":"2026-10-02T13:50:40.423Z","updatedAt":"2026-10-08T00:42:49.936Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104418","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104418","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-JJ74-HC2Q-XRVM"}]},{"id":"8e8eefc0-4aac-4303-9995-3d6c6a0be712","slug":"cve-2026-55251","externalId":"CVE-2026-55251","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-55251 — NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox.","description":"NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. Prior to commit f41fc1e, the CI workflow .github/workflows/validation.yml runs on pull_request and executes code supplied by the pull request before any maintainer review. Three PR-editable files drive this: \"requirements.txt\", \".pre-commit-hooks-config.yaml\" / \".pre-commit-yamlfmt-config.yaml\", and \".gitmodules\". A contributor with no special repository access could open a pull request that modifies these files and have their code run on the CI runner. This issue has been patched via commit f41fc1e.","cveId":"CVE-2026-55251","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-94","CWE-494","CWE-829"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/netbox-community/devicetype-library/commit/f41fc1e48dec8d7d31afba5f13a8c73652ff5796","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/netbox-community/devicetype-library/security/advisories/GHSA-5x2m-x42f-g4cm","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00107,"epssPercentile":0.01087,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T20:17:25.957Z","addedAt":"2026-10-01T21:50:40.734Z","updatedAt":"2026-10-05T21:50:40.469Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55251","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-55251","note":"authoritative record"}]},{"id":"f9df8c2d-ba7f-4a50-b095-2b0d35075ec1","slug":"cve-2026-104056","externalId":"CVE-2026-104056","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104056 — Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding.","description":"Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This allows a poisoned discovery response to replace all endpoint values with attacker-controlled values rather than endpoint URLs that share the origin of the configured server metadata URL.","cveId":"CVE-2026-104056","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-345","CWE-346","CWE-829"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://uziii2208.github.io/post/cve-2026-104056/","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00167,"epssPercentile":0.05481,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T19:17:19.033Z","addedAt":"2026-10-01T19:50:41.143Z","updatedAt":"2026-10-05T19:50:42.258Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104056","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104056","note":"authoritative record"}]},{"id":"870f9c07-a06e-4010-82d0-7ef225f704f0","slug":"cve-2026-100256","externalId":"CVE-2026-100256","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-100256 — In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projects","description":"In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projects","cveId":"CVE-2026-100256","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"jetbrains","product":"intellij idea","affectedVersions":["< 2026.2.3"],"cwes":["CWE-829"],"tags":["nvd","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.jetbrains.com/privacy-security/issues-fixed/","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00133,"epssPercentile":0.02447,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T16:16:56.243Z","addedAt":"2026-09-30T17:50:47.639Z","updatedAt":"2026-10-02T21:50:39.949Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100256","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-100256","note":"authoritative record"}]},{"id":"948d8ea3-c341-4b2a-86b4-93e4e5fd14e4","slug":"cve-2026-97150","externalId":"CVE-2026-97150","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-97150 — When converting baserCMS4-style addons to baserCMS5-style ones,\r\nBcAddonMigrator includes \"config.php\" from the addon, which means the PHP code in …","description":"When converting baserCMS4-style addons to baserCMS5-style ones,\r\nBcAddonMigrator includes \"config.php\" from the addon, which means the PHP code in the file is executed.\r\nArbitrary files on the system may be read or deleted by an administrative user.","cveId":"CVE-2026-97150","cvssScore":8.6,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-829"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://basercms.net/security/JVN_21754394","type":"advisory","title":"vultures@jpcert.or.jp"},{"url":"https://github.com/baserproject/BcAddonMigrator/commit/e836bc875e26910e1b5862f96cf280b4f064c104","type":"advisory","title":"vultures@jpcert.or.jp"},{"url":"https://jvn.jp/en/jp/JVN21754394","type":"advisory","title":"vultures@jpcert.or.jp"}],"epssScore":0.00336,"epssPercentile":0.24934,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T08:16:36.230Z","addedAt":"2026-09-30T09:50:38.905Z","updatedAt":"2026-09-30T17:50:47.121Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97150","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-97150","note":"authoritative record"}]},{"id":"63e9b61b-8ca3-4959-892f-62f81e8b36f9","slug":"cve-2026-86131","externalId":"CVE-2026-86131","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-86131 — A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote …","description":"A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.","cveId":"CVE-2026-86131","cvssScore":9.2,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":"watchguard","product":"fireware","affectedVersions":[">= 12.0, < 12.5.21",">= 12.12, < 12.12.3",">= 2025.0, < 2026.2.3",">= 2026.3, < 2026.3.2"],"cwes":["CWE-94","CWE-295","CWE-829"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://psirt.watchguard.com/CVE-2026-86131"],"references":[{"url":"https://psirt.watchguard.com/CVE-2026-86131","type":"patch","title":"Patch"}],"epssScore":0.0042,"epssPercentile":0.34336,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T00:16:36.817Z","addedAt":"2026-09-30T01:50:39.481Z","updatedAt":"2026-10-06T22:39:31.966Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86131","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-86131","note":"authoritative record"}]},{"id":"2ded9b8f-0e0f-40b3-800b-f501bbcdb489","slug":"cve-2026-87114","externalId":"CVE-2026-87114","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87114 — A flaw was found in kube-compare.","description":"A flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrectly executes an untrusted container image's entrypoint instead of merely extracting data from a stopped container. This allows a remote attacker to achieve arbitrary code execution on the operator's workstation. If the Docker daemon requires elevated privileges, the untrusted code may execute with root-mediated daemon privileges, posing a significant security risk.","cveId":"CVE-2026-87114","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-829"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-87114","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2522945","type":"advisory","title":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:74384","type":"advisory","title":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:74430","type":"advisory","title":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:74381","type":"advisory","title":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:74435","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.00202,"epssPercentile":0.09318,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-28T17:17:51.530Z","addedAt":"2026-09-28T17:50:41.441Z","updatedAt":"2026-10-07T16:39:30.159Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87114","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87114","note":"authoritative record"}]},{"id":"7bd8b184-84bb-4662-bdc3-cb4f84b83654","slug":"cve-2026-54160","externalId":"CVE-2026-54160","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-54160 — Network UPS Tools is a collection of programs which provide a common interface for monitoring and administering UPS, PDU and SCD hardware.","description":"Network UPS Tools is a collection of programs which provide a common interface for monitoring and administering UPS, PDU and SCD hardware. Prior to commits 658b24e and 1aa31d1, the GitHub Actions script used to prepare NUT tarballs and update GitHub Checks statuses and PR comments about it was mis-structured in terms of mixing code running with higher privileges (single-use token generated with write permissions) and untrusted inputs (PR source branch). A malicious PR run from a fork could extract the GITHUB_TOKEN value. It could potentially be abused while it was valid (while the GHA job ran) to manipulate Git repository contents, commit checks/statuses, or issue/PR comments, according to permissions it was issued with. This issue has been patched via commits 658b24e and 1aa31d1.","cveId":"CVE-2026-54160","cvssScore":8.2,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-829"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/networkupstools/nut/commit/658b24ef8410648ceca6d5a59e8690efbc8c36bc","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/networkupstools/nut/security/advisories/GHSA-w6wj-3r73-fxmh","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00198,"epssPercentile":0.0884,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-28T17:17:49.833Z","addedAt":"2026-09-28T17:50:41.416Z","updatedAt":"2026-09-30T21:50:42.927Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54160","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-54160","note":"authoritative record"}]},{"id":"9be69ba9-1fe9-485a-aabc-8177793a92ef","slug":"cve-2026-95985","externalId":"CVE-2026-95985","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-95985 — The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the ag…","description":"The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global configuration paths.\n\n\n\nWe recommend you upgrade to Kiro IDE version 1.0.242 or later. Users who ran the agent in an untrusted workspace on an earlier version should also review the global Kiro configuration directory (~/.kiro) for entries they did not create.","cveId":"CVE-2026-95985","cvssScore":8.6,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-349","CWE-829"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-117-aws/","type":"advisory","title":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://kiro.dev/changelog/ide/1-0-242/","type":"advisory","title":"ff89ba41-3aa1-4d27-914a-91399e9639e5"}],"epssScore":0.00135,"epssPercentile":0.0255,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-24T18:19:08.357Z","addedAt":"2026-09-24T19:50:39.432Z","updatedAt":"2026-09-24T19:50:39.432Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-95985","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-95985","note":"authoritative record"}]},{"id":"faa56ba7-30e6-40a0-a2d3-8cbbd702bf6d","slug":"cve-2026-96443","externalId":"CVE-2026-96443","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-96443 — Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to achieve remote code execution on the FE.","description":"Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to achieve remote code execution on the FE.","cveId":"CVE-2026-96443","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-829"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/vv9o8sxpt8kkd7nznhovn9qjojn2wyv9","type":"advisory","title":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/23/11","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"}],"epssScore":0.00336,"epssPercentile":0.2492,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-23T10:17:08.943Z","addedAt":"2026-09-23T11:50:37.851Z","updatedAt":"2026-09-23T19:50:41.164Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-96443","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-96443","note":"authoritative record"}]},{"id":"adbad33b-0046-4f4a-a037-19796d429cb0","slug":"cve-2026-17647","externalId":"CVE-2026-17647","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-17647 — IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to execute arbitrary commands due to the inclusion of fun…","description":"IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to execute arbitrary commands due to the inclusion of functionality from an untrusted control sphere.","cveId":"CVE-2026-17647","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","severity":"high","vendor":"ibm","product":"financial transaction manager","affectedVersions":[">= 4.0.7.0, < 4.0.11.0","4.0.6.0"],"cwes":["CWE-829"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7288641","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00218,"epssPercentile":0.11249,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-22T22:17:08.983Z","addedAt":"2026-09-22T23:50:37.380Z","updatedAt":"2026-10-08T14:40:00.675Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-17647","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-17647","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":118,"totalPages":6,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T01:17:20.084Z","durationMs":69,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-829"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}