{"success":true,"data":{"threats":[{"id":"4b5efcaa-3414-4ec1-af12-7e20c3bf2a00","slug":"cve-2026-19482","externalId":"CVE-2026-19482","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-19482 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to …","description":"IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of command arguments.","cveId":"CVE-2026-19482","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-88"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7291628","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T21:17:56.930Z","addedAt":"2026-10-08T23:06:39.740Z","updatedAt":"2026-10-08T23:06:39.740Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19482","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-19482","note":"authoritative record"}]},{"id":"ad08ebcc-25a4-44d6-8f09-86eb0b46a2d5","slug":"cve-2026-18740","externalId":"CVE-2026-18740","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-18740 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to …","description":"IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to perform unauthorized actions due to argument injection.","cveId":"CVE-2026-18740","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-88"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7291628","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T21:17:56.777Z","addedAt":"2026-10-08T23:06:39.724Z","updatedAt":"2026-10-08T23:06:39.724Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18740","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-18740","note":"authoritative record"}]},{"id":"a6fa9b7d-e915-43ae-8d2c-984d41342de0","slug":"cve-2026-11939","externalId":"CVE-2026-11939","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-11939 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 may be vulnerable to audit log forgery.","description":"IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 may be vulnerable to audit log forgery.","cveId":"CVE-2026-11939","cvssScore":2.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-88"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7291628","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T21:17:54.803Z","addedAt":"2026-10-08T23:06:39.594Z","updatedAt":"2026-10-08T23:06:39.594Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-11939","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-11939","note":"authoritative record"}]},{"id":"0059930a-921e-4ae4-ae9d-476175654753","slug":"cve-2026-107639","externalId":"CVE-2026-107639","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107639 — ILIAS before 9.24, 10.x before 10.12 and 11.x before 11.5 contains an argument injection vulnerability in assImagemapQuestionGUI that allows questi…","description":"ILIAS before 9.24, 10.x before 10.12 and 11.x before 11.5 contains an argument injection vulnerability in assImagemapQuestionGUI that allows question authors to inject ImageMagick convert options via uploaded image filenames. Attackers can embed tab-separated options, which escapeshellcmd() does not neutralise, to write a PHP file under the web root and achieve remote code execution.","cveId":"CVE-2026-107639","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-88"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://docu.ilias.de/go/blog/15821/950","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://docu.ilias.de/go/blog/15821/951","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://docu.ilias.de/go/blog/15821/952","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/ILIAS-eLearning/ILIAS","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/ILIAS-eLearning/ILIAS/blob/v10.11/components/ILIAS/TestQuestionPool/classes/class.assImagemapQuestion.php#L290-L306","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/ILIAS-eLearning/ILIAS/blob/v10.11/components/ILIAS/TestQuestionPool/classes/class.assImagemapQuestionGUI.php#L130","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/ILIAS-eLearning/ILIAS/blob/v10.11/components/ILIAS/TestQuestionPool/classes/class.ilImagemapPreview.php#L208-L238","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/ILIAS-eLearning/ILIAS/commit/ad1423c365a7ffd25bac711d995c643ce2af65c6","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/ilias-before-9.24-10.12-and-11.5-argument-injection-via-image-map-question-upload-filename","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:47.117Z","addedAt":"2026-10-08T16:39:35.834Z","updatedAt":"2026-10-08T16:39:35.834Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107639","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107639","note":"authoritative record"}]},{"id":"ba5e1a18-54bb-4a96-a783-f43d712867a7","slug":"cve-2026-107510","externalId":"CVE-2026-107510","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107510 — An authenticated high privilege user can inject arguments in troubleshooting commands resulting in privilege escalation.","description":"An authenticated high privilege user can inject arguments in troubleshooting commands resulting in privilege escalation.","cveId":"CVE-2026-107510","cvssScore":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-88","CWE-269","CWE-284"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.infoblox.com/s/article/Security-Advisory-NIOS-Maintenance-Mode-Permits-Root-Shell","type":"advisory","title":"f84ca5ce-fbe7-4668-8724-994599108a02"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T10:17:09.553Z","addedAt":"2026-10-08T10:39:34.992Z","updatedAt":"2026-10-08T23:06:37.387Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107510","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107510","note":"authoritative record"}]},{"id":"21efd3ee-10a3-4a37-91a8-bb5f840881d0","slug":"cve-2026-93699","externalId":"CVE-2026-93699","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-93699 — Argument injection in WP Toolkit for cPanel allows local users to execute arbitrary code as other accounts on the same server.","description":"Argument injection in WP Toolkit for cPanel allows local users to execute arbitrary code as other accounts on the same server.","cveId":"CVE-2026-93699","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-88"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.cpanel.net/hc/en-us/articles/43874620756759-Security-CVE-2026-93699-Vulnerability-in-WP-Toolkit-s-Handler-September-30-2026","type":"advisory","title":"support@hackerone.com"}],"epssScore":0.00134,"epssPercentile":0.02488,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T08:16:34.367Z","addedAt":"2026-10-08T08:39:29.380Z","updatedAt":"2026-10-08T23:06:37.217Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93699","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-93699","note":"authoritative record"}]},{"id":"3af01e6e-833e-419e-b18a-fe46fcc232b6","slug":"cve-2026-87687","externalId":"CVE-2026-87687","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87687 — An authorization and input validation vulnerability exists in Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1.","description":"An authorization and input validation vulnerability exists in Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user with restricted privileges in one Virtual Fabric can exploit this issue by submitting a specially crafted request containing an arbitrary fabric identifier. This allows the user to perform unauthorized cross-fabric operations and view configuration details within tenants/Virtual Fabrics to which they have not been granted access.","cveId":"CVE-2026-87687","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-88"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/39081","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.0019,"epssPercentile":0.07917,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T04:17:56.360Z","addedAt":"2026-10-08T04:39:33.085Z","updatedAt":"2026-10-08T21:05:46.092Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87687","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87687","note":"authoritative record"}]},{"id":"803bb406-6293-498f-a56b-8bb6e63c4b33","slug":"cve-2026-87667","externalId":"CVE-2026-87667","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87667 — An argument injection vulnerability exists in the configuration management command-line utility of Brocade Fabric OS versions before 9.2.2d and 10.…","description":"An argument injection vulnerability exists in the configuration management command-line utility of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When executing configuration viewing commands with search pattern filters, the utility fails to sanitize user-supplied search string options before passing them to internal search commands. An authenticated user with low-privilege administrative access can exploit this vulnerability to read arbitrary files on the local operating system, including sensitive configuration files, system password hashes and system secrets.","cveId":"CVE-2026-87667","cvssScore":8.4,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-88"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/39151","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.00189,"epssPercentile":0.07796,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T04:17:52.843Z","addedAt":"2026-10-08T04:39:33.048Z","updatedAt":"2026-10-08T21:05:45.937Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87667","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87667","note":"authoritative record"}]},{"id":"0f8fa8dd-869c-4c79-a4e9-7b81e3bf97b5","slug":"cve-2026-105791","externalId":"CVE-2026-105791","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105791 — Microsoft UFO is an open-source framework for intelligent automation across devices and platforms.","description":"Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the run_shell tool in the CommandLineExecutor component of ufo/client/mcp/local_servers/cli_mcp_server.py validates only the first token of the bash_command parameter and permits explorer.exe. On Windows, explorer.exe delegates its following path argument to ShellExecute, so an attacker-influenced agent call can launch an arbitrary executable or script as the desktop user even though the subprocess uses shell=False. Exploitation depends on a user running an affected agent workflow and on inducing the tool call, but successful execution can access or modify that user's files, tokens, and sessions. This issue is fixed in version 3.0.9.","cveId":"CVE-2026-105791","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-88","CWE-184"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/microsoft/UFO/commit/3e1262fc091eb319253b7a1338b63f62cc6c82b1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/microsoft/UFO/releases/tag/v3.0.9","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/microsoft/UFO/security/advisories/GHSA-cmq9-vqjf-4q2q","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00621,"epssPercentile":0.48153,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T15:17:15.840Z","addedAt":"2026-10-06T15:51:00.400Z","updatedAt":"2026-10-06T15:51:00.400Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105791","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105791","note":"authoritative record"}]},{"id":"0dd72801-06c6-4a52-a1f7-67281b77c3d1","slug":"cve-2026-105789","externalId":"CVE-2026-105789","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105789 — Microsoft UFO is an open-source framework for intelligent automation across devices and platforms.","description":"Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the execute_command tool in ufo/client/mcp/http_servers/linux_mcp_server.py treats sort and uniq as read-only commands while the free-form command parameter can select their file-output forms. An authenticated caller can use sort -o or the optional second uniq operand to create or overwrite files writable by the UFO server process without shell metacharacters, because the allowed binary opens the destination itself and the argument policy does not reject the operation. This can corrupt configuration or other writable data and disrupt the service, but the demonstrated primitive does not directly disclose files or establish arbitrary code execution. This issue is fixed in version 3.0.9.","cveId":"CVE-2026-105789","cvssScore":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:L","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-88","CWE-184"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/microsoft/UFO/commit/4f793622794f5d47810d54bed431c61f6a781dd6","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/microsoft/UFO/pull/349","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/microsoft/UFO/releases/tag/v3.0.9","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/microsoft/UFO/security/advisories/GHSA-85w2-wggf-rw49","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.007,"epssPercentile":0.517,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T14:17:40.270Z","addedAt":"2026-10-06T15:51:00.236Z","updatedAt":"2026-10-06T15:51:00.236Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105789","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105789","note":"authoritative record"}]},{"id":"d4733eb1-fa7c-4f7a-a824-a378da8c9747","slug":"cve-2026-105788","externalId":"CVE-2026-105788","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105788 — Microsoft UFO is an open-source framework for intelligent automation across devices and platforms.","description":"Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.10, the type_text and launch_app tools in ufo/client/mcp/http_servers/mobile_mcp_server.py pass the authenticated caller-controlled text and package_name parameters into adb shell command argument positions without comprehensive validation. The adb client joins those arguments into a remote command string that the Android shell reparses, allowing shell metacharacters to execute additional commands on an authorized connected device as the Android shell user. Exploitation requires a valid Mobile MCP API key and a reachable device authorized for ADB, and it does not establish host operating-system execution, Android root execution, or access beyond the Android shell-user privileges. This issue is fixed in version 3.0.10.","cveId":"CVE-2026-105788","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-78","CWE-88"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/microsoft/UFO/commit/214443218bf4a3b8de798fd44e7fd770afefee83","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/microsoft/UFO/commit/a538791043327a0c33731d5be428867a5fd71794","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/microsoft/UFO/releases/tag/v3.0.10","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/microsoft/UFO/security/advisories/GHSA-6ppj-5886-4f26","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.01055,"epssPercentile":0.63365,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T14:17:40.077Z","addedAt":"2026-10-06T15:51:00.230Z","updatedAt":"2026-10-06T17:50:42.353Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105788","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105788","note":"authoritative record"}]},{"id":"2a35934b-9310-400f-bea7-b732f2da1e22","slug":"ghsa-w2vw-w76x-qr89","externalId":"GHSA-w2vw-w76x-qr89","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"Nx: OS command injection via git revisions and remote refs","description":"## Summary\n\nNx core builds several `git` invocations as shell command strings with untrusted values interpolated into them, so a value that should be a git revision or ref is parsed by `/bin/sh` instead. Two entry points are reachable by an attacker: `affected` commands, where `defaultBase` / `affected.defaultBase` from `nx.json` (and the `NX_BASE` / `NX_HEAD` environment variables) reach `git merge-base` and `git diff`; and `nx import`, where a branch name advertised by a remote repository reaches `git fetch`, `git checkout`, and `git config`. In both cases an attacker who controls a repository — or who opens a pull request against one — gets arbitrary command execution on the machine of anyone who runs an ordinary Nx command against it, including CI runners.\n\nThe `affected` path is the more serious of the two. `nx affected` and `nx show projects --affected` run constantly in CI, so a pull request that changes nothing but `nx.json` is enough to execute code on the runner with whatever credentials that job holds.\n\n## Severity\n\nExploitable by anyone who controls repository content — a fork's pull request, or a repository the victim clones — that the victim then runs an ordinary `nx affected` or `nx import` against; no access to the victim's machine is required. We have no evidence of exploitation in the wild.\n\n## Affected & Patched Versions\n\n| Package | Vulnerable | Patched |\n| --- | --- | --- |\n| `nx` | `>= 14.0.0, < 22.7.8`; `>= 23.0.0, < 23.1.1` | `22.7.8`, `23.1.1` |\n\nTreat every version below the patched ones as affected.\n\n## Remediation\n\nUpgrade to **22.7.8** (22.x line) or **23.1.1** (23.x line) or later:\n\n```\nnx migrate 23.1.1\n```\n\nThe fix is a drop-in — no configuration changes are required. If you cannot upgrade, treat `nx.json` from untrusted sources as executable content, do not run `affected` commands against pull requests you have not reviewed, and do not run `nx import` against repositories you do not trust.\n\n## Details\n\n### `affected` commands\n\nNx computes the merge base and the changed-file set by building `git merge-base` and `git diff` command lines as strings and running them through a shell. The base and head revisions in those strings come from `nx.json`'s `defaultBase` / `affected.defaultBase` or from the `NX_BASE` / `NX_HEAD` environment variables, and a related code path reads file contents with `git show <revision>:<path>` the same way. Because a shell parses the whole line, a revision value containing shell syntax is executed rather than passed to `git`.\n\nThe revisions are wrapped in double quotes, which looks protective but is not: POSIX shells still perform command substitution inside double quotes, so a value of `$(…)` runs without needing to break out of the quotes.\n\n### `nx import`\n\nThe `GitRepository` helper runs every git operation — `fetch`, `checkout`, `reset`, `config`, and others — by interpolating its arguments into a shell command string. The untrusted argument is a branch name: `nx import` lists the branches a remote advertises, offers them to the user to choose from, and feeds the chosen name back into those commands. A hostile repository controls the names of its own branches, so it controls the command that runs when one is selected.\n\n\n## Credits\n\n- **Arkadiusz Marta** (RE:SOURCE) — Reporter","cveId":null,"cvssScore":null,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","severity":"high","vendor":"npm","product":"nx","affectedVersions":["pkg:npm/nx >= 14.0.0, < 22.7.8","pkg:npm/nx >= 23.0.0, < 23.1.1"],"cwes":["CWE-78","CWE-88"],"tags":["osv","osv:ghsa-w2vw-w76x-qr89","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-w2vw-w76x-qr89","type":"advisory","title":"OSV GHSA-w2vw-w76x-qr89"},{"url":"https://github.com/nrwl/nx/security/advisories/GHSA-w2vw-w76x-qr89","type":"other","title":"OSV web"},{"url":"https://github.com/nrwl/nx/pull/36348","type":"other","title":"OSV web"},{"url":"https://github.com/nrwl/nx/pull/36379","type":"other","title":"OSV web"},{"url":"https://github.com/nrwl/nx/commit/11ab38573478172109bb5306cb30ca4af246caf0","type":"other","title":"OSV web"},{"url":"https://github.com/nrwl/nx/commit/4159295a037fdbd8e7f44a33a19d85ab3792415b","type":"other","title":"OSV web"},{"url":"https://github.com/nrwl/nx/commit/9ce184a04d2098a4797c8b0d6877ee079b751abf","type":"other","title":"OSV web"},{"url":"https://github.com/nrwl/nx/commit/c12850ce7b364db08e325c13541641d754db7123","type":"other","title":"OSV web"},{"url":"https://github.com/nrwl/nx/commit/cd9b3c068e17adc9c1722b35b9ca962b98542c20","type":"other","title":"OSV web"},{"url":"https://github.com/nrwl/nx/commit/cf996496bbad727362d48292b50fafc8c3665847","type":"other","title":"OSV web"},{"url":"https://github.com/nrwl/nx","type":"vendor","title":"OSV package"},{"url":"https://github.com/nrwl/nx/releases/tag/22.7.8","type":"other","title":"OSV web"},{"url":"https://github.com/nrwl/nx/releases/tag/23.1.1","type":"other","title":"OSV web"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T23:29:06.000Z","addedAt":"2026-10-06T01:54:26.933Z","updatedAt":"2026-10-06T01:54:26.933Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-w2vw-w76x-qr89"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-w2vw-w76x-qr89"}]},{"id":"a390d24a-7c85-4139-87d8-753b7c342a5c","slug":"cve-2026-105326","externalId":"CVE-2026-105326","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105326 — An argument injection flaw was found in CUPS.","description":"An argument injection flaw was found in CUPS. When email notification is configured, the CUPS scheduler accepts printer subscription requests that supply a mailto notify-recipient-uri. The mailto notifier passes the recipient address to the configured sendmail program without ensuring it cannot be interpreted as command-line options. A remote attacker who can reach the CUPS service could supply a crafted recipient value starting with \"-\" to influence sendmail behavior. Successful exploitation depends on the installed mail transfer agent and CUPS network exposure, and may lead to execution of attacker-controlled commands with the privileges of the CUPS service user.","cveId":"CVE-2026-105326","cvssScore":2.5,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-88"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-105326","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2545835","type":"advisory","title":"secalert@redhat.com"},{"url":"https://github.com/OpenPrinting/cups/commit/1244ed9","type":"advisory","title":"secalert@redhat.com"},{"url":"https://github.com/OpenPrinting/cups/commit/611d1bd","type":"advisory","title":"secalert@redhat.com"},{"url":"https://github.com/OpenPrinting/cups/security/advisories/GHSA-r4wf-366f-f6g3","type":"advisory","title":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:77638","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.00217,"epssPercentile":0.11094,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T19:17:16.393Z","addedAt":"2026-10-05T19:50:42.748Z","updatedAt":"2026-10-07T18:39:30.303Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105326","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105326","note":"authoritative record"}]},{"id":"c05c0172-9526-409e-bcd6-b745b3e7ea98","slug":"cve-2026-12171","externalId":"CVE-2026-12171","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-12171 — auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.…","description":"auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.json) into its options, and honors security-sensitive options from that untrusted source. The handlebarsSetup option is passed to require(), so running auto-changelog over attacker-controlled repository content (for example, in a CI workflow that checks out an untrusted pull request head, or locally on a forked or third-party repository) executes attacker-chosen code with the privileges of the invoking user or CI job, including access to workflow secrets, without the repository dependencies ever being installed. The plugins option similarly loads attacker-controlled modules from the repository. Under the same conditions, appendGitLog/appendGitTag allow git argument injection (e.g. --output= to write arbitrary files), output allows writing attacker-influenced content to arbitrary paths, and template causes an outbound request to an attacker-chosen URL. Version 2.6.1 treats in-repository configuration as untrusted and refuses to run when it sets these options, unless the new --unsafe-config flag is passed.","cveId":"CVE-2026-12171","cvssScore":8.4,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-22","CWE-88","CWE-94","CWE-829","CWE-918"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/cookpete/auto-changelog/commit/1d02a48a0a57c69a3cd268aca375d64d50877c1a","type":"advisory","title":"7ffcee3d-2c14-4c3e-b844-86c6a321a158"},{"url":"https://github.com/cookpete/auto-changelog/security/advisories/GHSA-xpvr-2hvx-m8q4","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00218,"epssPercentile":0.11251,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T17:17:14.510Z","addedAt":"2026-10-05T17:50:43.068Z","updatedAt":"2026-10-06T17:50:42.093Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12171","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-12171","note":"authoritative record"}]},{"id":"f18408fd-d8bf-46d4-8af3-9226e80b91a9","slug":"cve-2026-91784","externalId":"CVE-2026-91784","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-91784 — cjbassi/gotop is vulnerable to local argument injection via process termination functionality.","description":"cjbassi/gotop is vulnerable to local argument injection via process termination functionality. The process name is passed directly to pkill without sanitization. A local attacker can create a process with a crafted name beginning with -- (e.g. containing a target user's UID). When the user running gotop invokes the kill feature on that process, pkill interprets the crafted name as a command-line option, terminating all processes owned by the targeted user.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\nProduct is no longer actively supported and the vulnerabilities have not been fixed. Vulnerability was confirmed at version 3.0.0; other versions were not tested but may also be affected.","cveId":"CVE-2026-91784","cvssScore":4.8,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-88"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://cert.pl/en/posts/2026/10/CVE-2026-91784","type":"advisory","title":"cvd@cert.pl"},{"url":"https://github.com/cjbassi/gotop","type":"advisory","title":"cvd@cert.pl"}],"epssScore":0.00154,"epssPercentile":0.03975,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T09:16:45.117Z","addedAt":"2026-10-02T09:50:39.766Z","updatedAt":"2026-10-02T19:50:41.022Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91784","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-91784","note":"authoritative record"}]},{"id":"21daa62e-fe5a-44e1-b9e1-f54861f2060e","slug":"cve-2026-97662","externalId":"CVE-2026-97662","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-97662 — An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat a…","description":"An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to create, overwrite, or truncate arbitrary files on the host outside the intended workspace directory via a crafted reference value supplied to the diff scan operation.\n\n\n\nTo remediate this issue, users should upgrade to version 0.2.0.","cveId":"CVE-2026-97662","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-73","CWE-88"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-121-aws/","type":"advisory","title":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://pypi.org/project/awslabs.security-agent-mcp-server/0.2.0/","type":"advisory","title":"ff89ba41-3aa1-4d27-914a-91399e9639e5"}],"epssScore":0.00142,"epssPercentile":0.03045,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T18:17:29.230Z","addedAt":"2026-10-01T19:50:41.130Z","updatedAt":"2026-10-01T21:50:40.597Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97662","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-97662","note":"authoritative record"}]},{"id":"a292c45e-7a03-40b5-9bf3-f9a3773a92d5","slug":"cve-2026-103505","externalId":"CVE-2026-103505","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-103505 — Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) v3.1.0 through v3.4.2 mi…","description":"Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) v3.1.0 through v3.4.2 might allow remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma-separated values in the mounttargetipmap volumeAttribute.\n\n\n\nTo remediate this issue, users should upgrade to version v3.5.0 or later.","cveId":"CVE-2026-103505","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-88"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-120-aws/","type":"advisory","title":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/kubernetes-sigs/aws-efs-csi-driver/releases/tag/v3.5.0","type":"advisory","title":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/kubernetes-sigs/aws-efs-csi-driver/security/advisories/GHSA-pv26-6q9q-5773","type":"advisory","title":"ff89ba41-3aa1-4d27-914a-91399e9639e5"}],"epssScore":0.00432,"epssPercentile":0.35545,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T16:17:36.627Z","addedAt":"2026-10-01T17:50:42.716Z","updatedAt":"2026-10-02T15:50:40.307Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103505","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-103505","note":"authoritative record"}]},{"id":"ce4c1d6d-1950-41e5-865f-17445d5d2f5f","slug":"cve-2026-102904","externalId":"CVE-2026-102904","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102904 — JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture.","description":"JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.0.0 until 4.5.11 and 4.6.4, the PyPI Extension Manager uninstall request reaches ExtensionHandler.post, which validates extension names for installation but passes uninstall names to PyPIExtensionManager.uninstall and python -m pip uninstall without rejecting option-like values. The security impact requires that the PyPI Extension Manager is enabled, the account can call the extension API, and kernels and terminals are disabled or delegated to remote hosts; otherwise the user can already read files and make outbound requests directly. An authenticated user with extension API access can supply a pip requirements option to make the server read a local file or fetch an internal URL, and reflected parse errors can return the first unparsable line or response content. A pip log option can also create or corrupt a chosen path with pip-generated log text, but the requester cannot select an arbitrary disclosed line or arbitrary file content, and the injection does not add code execution or availability impact beyond ordinary package removal. This issue is fixed in JupyterLab 4.5.11 and 4.6.4.","cveId":"CVE-2026-102904","cvssScore":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","severity":"medium","vendor":"PyPI","product":"jupyterlab","affectedVersions":["pkg:pypi/jupyterlab >= 4.6.0, < 4.6.4","pkg:pypi/jupyterlab >= 4.0.0, < 4.5.11","pkg:pypi/jupyterlab >= 4.0.0, < 4.5.11 || >= 4.6.0, < 4.6.4"],"cwes":["CWE-88","CWE-209","CWE-918"],"tags":["nvd","status:awaiting-analysis","osv","osv:ghsa-3325-v43h-43rv","ecosystem:pypi","osv:pysec-2026-4055"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/jupyterlab/jupyterlab/commit/a274a8276b9185d03efd4c3c20713d3137ac49e6","type":"other","title":"OSV web"},{"url":"https://github.com/jupyterlab/jupyterlab/commit/e277bc958e737130ac47b6c5078d08b29298828f","type":"other","title":"OSV web"},{"url":"https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.11","type":"other","title":"OSV web"},{"url":"https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.4","type":"other","title":"OSV web"},{"url":"https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-3325-v43h-43rv","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-3325-v43h-43rv","type":"advisory","title":"OSV GHSA-3325-v43h-43rv"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102904","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/jupyterlab/jupyterlab/commit/9e1951e57da499ca66ef5e0caf68e71ad2e3d1a5","type":"other","title":"OSV web"},{"url":"https://github.com/jupyterlab/jupyterlab","type":"vendor","title":"OSV package"},{"url":"https://osv.dev/vulnerability/PYSEC-2026-4055","type":"advisory","title":"OSV PYSEC-2026-4055"},{"url":"https://pypi.org/project/jupyterlab","type":"vendor","title":"OSV package"},{"url":"https://github.com/advisories/GHSA-3325-v43h-43rv","type":"advisory","title":"OSV advisory"}],"epssScore":0.00206,"epssPercentile":0.09723,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-29T21:17:18.423Z","addedAt":"2026-09-29T21:50:42.822Z","updatedAt":"2026-10-06T18:41:23.644Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102904","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102904","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-3325-V43H-43RV"}]},{"id":"abfef9ef-4918-4f01-a3ad-75cab807748f","slug":"cve-2026-102827","externalId":"CVE-2026-102827","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102827 — simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript.","description":"simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin compares parsed option names with literal dangerous option spellings while Git accepts unambiguous long-option abbreviations. Attacker-influenced push arguments such as abbreviated --receive-pack or --exec forms can therefore bypass detectVulnerableFlags, reach git push against a local or file remote or an attacker-influenced receive-pack target, and cause Git to invoke an attacker-selected command in consumers that expose those arguments. The clone-side abbreviation handling does not protect the push path. This issue is fixed in 4.0.0.","cveId":"CVE-2026-102827","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":"simple-git project","product":"simple-git","affectedVersions":["pkg:npm/simple-git < 4.0.0","< 4.0.0"],"cwes":["CWE-77","CWE-88"],"tags":["nvd","status:received","status:undergoing-analysis","osv","osv:ghsa-858h-whjf-mvg5","ecosystem:npm","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/steveukx/git-js/commit/98864c678444d9336357c844efa4fd5a7984c0d7","https://github.com/steveukx/git-js/pull/1193"],"references":[{"url":"https://github.com/steveukx/git-js/commit/98864c678444d9336357c844efa4fd5a7984c0d7","type":"patch","title":"Patch"},{"url":"https://github.com/steveukx/git-js/pull/1193","type":"patch","title":"Patch"},{"url":"https://github.com/steveukx/git-js/releases/tag/simple-git@4.0.0","type":"advisory","title":"Release Notes"},{"url":"https://github.com/steveukx/git-js/security/advisories/GHSA-858h-whjf-mvg5","type":"vendor","title":"Exploit"},{"url":"https://osv.dev/vulnerability/GHSA-858h-whjf-mvg5","type":"advisory","title":"OSV GHSA-858h-whjf-mvg5"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102827","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/steveukx/git-js","type":"vendor","title":"OSV package"}],"epssScore":0.00363,"epssPercentile":0.28066,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-29T19:17:25.050Z","addedAt":"2026-09-29T19:50:42.366Z","updatedAt":"2026-10-08T21:05:41.624Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102827","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102827","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-858H-WHJF-MVG5"}]},{"id":"e0793148-126b-4297-bc28-4a0f71ec6c7a","slug":"cve-2026-86035","externalId":"CVE-2026-86035","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-86035 — Weblate is a web-based continuous localization platform used to manage software translations.","description":"Weblate is a web-based continuous localization platform used to manage software translations. Weblate 4.11.1 through 2026.7.1 contains an argument-injection vulnerability in its Mercurial backend. Repository filenames beginning with - could be interpreted as Mercurial options instead of literal paths. An authenticated user with project-scoped component.edit permission could exploit this through a Mercurial-backed RESX component using the Update RESX files add-on. A later repository update could execute arbitrary commands with the privileges of the Weblate service account. This is a residual incomplete fix for CVE-2022-23915. This issue has been patched in version 2026.8.","cveId":"CVE-2026-86035","cvssScore":8.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-78","CWE-88"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/WeblateOrg/weblate/commit/f60a9759a6d851bd10ccdefe9b1b7f0cdb9e9bbd","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/WeblateOrg/weblate/pull/20768","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/WeblateOrg/weblate/releases/tag/weblate-2026.8","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/WeblateOrg/weblate/security/advisories/GHSA-327h-qqgm-qv55","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00366,"epssPercentile":0.28423,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-29T15:17:30.407Z","addedAt":"2026-09-29T15:50:41.449Z","updatedAt":"2026-10-02T13:50:39.696Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86035","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-86035","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":161,"totalPages":9,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:51:52.307Z","durationMs":71,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-88"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}