{"success":true,"data":{"threats":[{"id":"2546aa8f-7947-4936-99cf-0dd19a42c12e","slug":"cve-2026-107781","externalId":"CVE-2026-107781","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107781 — Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a server-side request forgery and missing authorization vulnerabili…","description":"Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a server-side request forgery and missing authorization vulnerability in the OnlyOffice save callback editUploadOfficeFileById. Unauthenticated attackers can supply arbitrary url and key parameters to make the server fetch internal URLs and overwrite any user's stored file, then read results via queryFileToShowById.","cveId":"CVE-2026-107781","cvssScore":9.1,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-918"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/dromara/skyeye","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/dromara/skyeye/blob/003549ae5615bd114ba5bb8ddf6a8e8ead97c321/skyeye-adm/adm-pro/src/main/java/com/skyeye/eve/diskcloud/service/impl/FileConsoleServiceImpl.java#L533-L556","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/dromara/skyeye/issues/29","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/dromara-skyeye-unauthenticated-ssrf-and-file-overwrite-via-edituploadofficefilebyid","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T21:17:53.080Z","addedAt":"2026-10-08T23:06:39.512Z","updatedAt":"2026-10-08T23:06:39.512Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107781","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107781","note":"authoritative record"}]},{"id":"bd24b01c-cba8-4942-a651-8383c234cbaf","slug":"cve-2026-107394","externalId":"CVE-2026-107394","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107394 — Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask.","description":"Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, the previous fix for CVE-2026-25738 did not cover an edge case, allowing an event organizer to submit a crafted URL that points to a prohibited local target but is accepted as valid by Indico. The organizer can read data returned by the target through affected Indico features. This issue is fixed in version 3.3.13.","cveId":"CVE-2026-107394","cvssScore":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-918"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/indico/indico/commit/44540e70ab4e20a12f14ddba5218a33749a86736","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/indico/indico/pull/7573","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/indico/indico/releases/tag/v3.3.13","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/indico/indico/security/advisories/GHSA-2v95-h47v-g4x9","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:34.073Z","addedAt":"2026-10-08T21:05:53.032Z","updatedAt":"2026-10-08T21:05:53.032Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107394","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107394","note":"authoritative record"}]},{"id":"67768fc6-2778-4724-98fe-9dacd4bee188","slug":"cve-2026-107698","externalId":"CVE-2026-107698","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107698 — FFmpeg before 7.1.4 and 8.0.x before 8.0.2 contains a server-side request forgery vulnerability in ff_rtsp_connect() in libavformat/rtsp.c that fol…","description":"FFmpeg before 7.1.4 and 8.0.x before 8.0.2 contains a server-side request forgery vulnerability in ff_rtsp_connect() in libavformat/rtsp.c that follows RTSP 3xx redirects without validating the Location URL. Malicious RTSP servers can redirect FFmpeg to internal hosts and ports under other schemes, bypassing -protocol_whitelist, to probe internal network services.","cveId":"CVE-2026-107698","cvssScore":5.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-918"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22292","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/FFmpeg/FFmpeg","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/FFmpeg/FFmpeg/blob/n7.1.3/libavformat/rtsp.c#L2016","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/FFmpeg/FFmpeg/commit/2326bc5f69c9","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/FFmpeg/FFmpeg/commit/7c011995e394","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/FFmpeg/FFmpeg/commit/ea9e85e54981b8402368d0f21648836d6738f1b1","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/FFmpeg/FFmpeg/commit/f9aa8729bce1","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/ffmpeg-before-7.1.4-and-8.0.2-ssrf-via-rtsp-redirect-handling","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T18:17:26.460Z","addedAt":"2026-10-08T18:39:31.947Z","updatedAt":"2026-10-08T23:06:38.936Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107698","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107698","note":"authoritative record"}]},{"id":"9416c4c3-4c3b-4cf6-87ce-28cb2f62b3dc","slug":"cve-2026-107362","externalId":"CVE-2026-107362","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107362 — Malcolm file-upload component ships the upstream FilePond PHP server (pqina/filepond-server-php) largely unmodified: Dockerfile copies all upstream…","description":"Malcolm file-upload component ships the upstream FilePond PHP server (pqina/filepond-server-php) largely unmodified: Dockerfile copies all upstream *.php files and Malcolm only overwrites config.php and submit.php. Upstream index.php exposes a fetch API route that instructs the server to download an arbitrary URL with curl (including FOLLOWLOCATION) and, for HEAD requests, stores the fetched response body in the upload container's transfer directory and returns the transfer ID to the caller, enabling full readback of the fetched content.","cveId":"CVE-2026-107362","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-918"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-280-01.json","type":"advisory","title":"ics-cert@hq.dhs.gov"},{"url":"https://github.com/cisagov/Malcolm/security/advisories/GHSA-cvx2-hj33-vc4q","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T18:17:21.587Z","addedAt":"2026-10-08T18:39:31.875Z","updatedAt":"2026-10-08T23:06:38.770Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107362","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107362","note":"authoritative record"}]},{"id":"0d742810-8759-4994-9ae5-96c427d14e82","slug":"cve-2026-61430","externalId":"GHSA-qg25-6gc4-48mg","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"PraisonAI: DNS rebinding bypass in `web_crawl` SSRF protection allows internal response disclosure","description":"## Summary\n\nPraisonAI's `web_crawl` agent tool performs a server-side HTTP fetch of an agent/attacker-influenced URL. SSRF is meant to be prevented by `_is_safe_crawl_url()`, which resolves the hostname and rejects private/loopback/link-local IPs **at validation time**. The validated value is the URL *string* (not a pinned IP); the fetch backend then **re-resolves the hostname at connection time**. Because validation and connection perform two independent DNS resolutions, a **DNS-rebinding** domain that returns a public IP during validation and an internal IP during the fetch fully bypasses the guard, and the internal HTTP response body is returned to the caller.\n\nThis is **SSRF with internal response disclosure (read-back)** — not blind SSRF. Runtime-confirmed against PraisonAI 4.6.63; the crawl response returned the controlled internal markers `PRAISONAI_INTERNAL_SECRET_CANARY_7f3a91` / `FAKE_INTERNAL_TOKEN_DO_NOT_USE_7f3a91`. Severity High. Reachable by any actor who can influence the URL an agent crawls (e.g. a chat/bot/agent surface).\n\n## Details\n\n### Affected component\n- Package: `praisonaiagents` (PraisonAI), version **4.6.63**.\n- File: `src/praisonai-agents/praisonaiagents/tools/web_crawl_tools.py`; tool `web_crawl` / `crawl_web` (part of the default bot tool set).\n\n### Vulnerable code / root cause\n\n**Code point 1 — check-time-only DNS validation, no IP pinning**\n\nPath:\n`src/praisonai-agents/praisonaiagents/tools/web_crawl_tools.py`\n\nFunction:\n`_is_safe_crawl_url`\n\nSnippet:\n```python\nfor info in socket.getaddrinfo(hostname, None):          # resolve at CHECK time\n    ip = ipaddress.ip_address(info[4][0])\n    if (ip.is_loopback or ip.is_private or ip.is_link_local\n            or ip.is_multicast or ip.is_unspecified):\n        return False\nreturn True\n```\nIssue: the guard validates the hostname by resolving it **once at check time**. It does not pin the resolved IP and does not return/forward that IP to the HTTP client. Any later resolution can differ.\n\n**Code point 2 — guard runs, then the URL *string* is handed to the backend**\n\nFunction:\n`web_crawl`\n\nSnippet:\n```python\nfor u in raw_url_list:\n    if _is_safe_crawl_url(u):       # validate the URL string\n        url_list.append(u)\n...\nresults = _crawl_with_httpx(url_list)   # or _crawl_with_crawl4ai(url_list)\n```\nIssue: attacker-controlled input (`urls`) is validated as a string; the backend then fetches that string and **re-resolves DNS independently** of the guard. There is no shared, pinned IP between check and fetch.\n\n**Code point 3 — `_crawl_with_httpx` backend re-resolves (redirect re-validation does not stop rebinding)**\n\nFunction:\n`_crawl_with_httpx`\n\nSnippet:\n```python\nwith httpx.Client(follow_redirects=False, timeout=30.0) as client:\n    for _ in range(max_redirects + 1):\n        if not _is_safe_crawl_url(current):   # re-resolves hostname (CHECK)\n            raise ValueError(\"Redirect target failed SSRF validation\")\n        response = client.get(current)        # resolves AGAIN at CONNECT\n```\nIssue: even with per-hop redirect re-validation, `_is_safe_crawl_url(current)` and `client.get(current)` are **two separate DNS resolutions** of the same hostname. A rebinding domain answers public to the check and internal to the connect → TOCTOU bypass. No IP pinning.\n\n**Code point 4 — urllib fallback (same function), no per-hop guard**\n\nSnippet:\n```python\nimport urllib.request\nwith urllib.request.urlopen(url, timeout=30) as response:   # re-resolves + auto-follows redirects\n    content = response.read().decode('utf-8', errors='ignore')\n```\nIssue: when `httpx` is not installed, this fallback inside `_crawl_with_httpx` fetches the URL and auto-follows redirects with no per-hop/per-connect validation. (Results from this function are labelled `\"provider\": \"httpx\"` regardless of which path runs.)\n\n**Code point 5 — crawl4ai/Chromium backend (confirmed addendum)**\n\nThe crawl4ai backend (`_crawl_with_crawl4ai` → `crawler.arun(url=url)`, headless Chromium) is also runtime-confirmed affected (browser re-resolves DNS / follows redirects with no per-connect guard). To keep this report focused on the `web_crawl` SSRF guard, the backend-specific evidence is in `SSRF-04_Crawl4AI_SSRF_Backend_Addendum.md`.\n\n### Attack flow\n1. Attacker controls a hostname (e.g. `rebind.lab`) whose authoritative DNS rebinds.\n2. Lookup #1 (the guard) → a public IP → `_is_safe_crawl_url()` returns true.\n3. The backend re-resolves → the attacker's DNS now answers an internal/private IP (cloud metadata, loopback, internal service).\n4. The backend connects to the internal service and returns its body to the caller → internal data disclosure.\n\n### Why existing protection is bypassed\n- The guard validates the hostname, not a pinned IP; check and connect resolve independently → DNS rebinding (TOCTOU) defeats it on every backend.\n- Redirect re-validation (httpx path) re-checks the *hostname* but still re-resolves at connect, so it does not stop rebinding; the urllib fallback and crawl4ai backends have no per-hop guard at all.\n\n### Security boundary\nThe server-side fetch reaches internal/loopback/metadata services not exposed to the attacker and returns their content (CVSS Scope: Changed). Reachable wherever an agent can be induced to crawl an attacker-supplied URL (PR:L). An unauthenticated single-request path to `web_crawl` read-back was not found in 4.6.63 (so PR:N / Critical is not claimed).\n\n## Proof of Concept\n\n### Environment\nReal PraisonAI 4.6.63 in a local Docker runtime; a controlled internal canary service (Docker-internal only, not published) returns synthetic markers; a controlled DNS responder implements rebinding for `rebind.lab`. No public host / real metadata / real secret. Runnable assets: `PraisonAI-Runtime-Repro\\runtime-files\\`.\n\n### Steps to reproduce\n1. Burp Repeater tab `PRAI-05-01-DNS-Rebind-Trigger` → `127.0.0.1:18080`:\n```http\nPOST /tool/web_crawl HTTP/1.1\nHost: 127.0.0.1:18080\nContent-Type: application/json\n\n{\"url\":\"http://rebind.lab:8081/secret\"}\n```\n2. Send (`PRAI-05-02-DNS-Rebind-Secret-Readback` captures the response). If a send returns the \"blocked\" error, the rebinding DNS auto-resets (~3s) — resend.\n3. Redirect variant: `PRAI-05-03-Redirect-Trigger` / `PRAI-05-04-Redirect-Secret-Readback` send `{\"url\":\"http://redirector:8082/redirect-to-internal\"}`.\n\n### Expected result\nA safe SSRF guard refuses destinations that resolve to internal/private IPs regardless of DNS timing or redirects, and does not return internal content.\n\n### Actual result\nHTTP 200 with the internal body in the crawl result. Primary evidence is the `provider: \"httpx\"` backend returning the internal canary via DNS rebinding:\n```json\n{\"input_url\":\"http://rebind.lab:8081/secret\",\n \"result\":{\"content\":\"{ ... \\\"secret\\\": \\\"PRAISONAI_INTERNAL_SECRET_CANARY_7f3a91\\\", \\\"token\\\": \\\"FAKE_INTERNAL_TOKEN_DO_NOT_USE_7f3a91\\\" ... }\",\"provider\":\"httpx\"}}\n```\nThe redirect variant returns the same internal markers via a redirect chain (`provider: \"httpx\"`).\n\n### Screenshots\n\n**DNS rebinding read-back**\n\nThe attacker-controlled `rebind.lab` URL is accepted by `web_crawl`, and the PraisonAI response contains the internal canary response body.\n\n<img width=\"1543\" height=\"785\" alt=\"01-DNS-Rebind-Burp-Readback\" src=\"https://github.com/user-attachments/assets/e86e95dd-3d3a-4bef-b1c6-cb897234a212\" />\n\n**DNS rebinding runtime evidence**\n\nThe runtime log shows `rebind.lab` first resolving to an allowed/public IP during validation (`guard-pass`), then resolving to an internal Docker IP during the actual fetch (`fetch-hit`). The internal canary receives `GET /secret` from the PraisonAI container.\n\n<img width=\"1654\" height=\"828\" alt=\"02-DNS-Rebind-DNS-Log-And-Internal-Hit\" src=\"https://github.com/user-attachments/assets/f1d28046-de34-48f0-9bee-bbe26e598d5f\" />\n\n**Redirect-based SSRF read-back**\n\nThe attacker-controlled redirector URL is accepted by `web_crawl`. PraisonAI follows the redirect and returns the internal canary response body containing `PRAISONAI_INTERNAL_SECRET_CANARY_7f3a91`.\n\n<img width=\"1540\" height=\"772\" alt=\"03-Redirect-Burp-Readback\" src=\"https://github.com/user-attachments/assets/79eec159-4b9f-44be-a9eb-b15aba35ead8\" />\n\n**Redirect chain runtime evidence**\n\nThe controlled redirector returns `302 -> http://internal-canary:8081/secret`, and the internal canary receives `GET /secret`, confirming that the server-side client followed the redirect into the internal network.\n\n<img width=\"1637\" height=\"894\" alt=\"04-Redirect-Internal-Hit-Log\" src=\"https://github.com/user-attachments/assets/1c503e30-9d01-4d32-8658-497f755a969e\" />\n\n### Reproduction assets\n\nThe attached archive contains the local Docker runtime used to reproduce the issue with controlled canary services only. It does not contain real secrets, real cloud metadata access, or third-party API keys.\n\n[PraisonAI-Runtime-Repro.zip](https://github.com/user-attachments/files/29142379/PraisonAI-Runtime-Repro.zip)\n\n## Impact\nSSRF against internal/loopback/cloud-metadata endpoints with **disclosure of internal HTTP responses** (read-back) to the attacker. Bypasses the project's SSRF protection on every fetch backend.\n\n## Suggested remediation\n1. Resolve the host once, reject all returned records that are private/loopback/link-local/ULA/CGNAT/metadata, then **connect to that exact validated IP** (pin it; send the original `Host`). Do not let the HTTP client / browser re-resolve.\n2. Apply the same validation + IP pinning to every backend (httpx, urllib fallback, crawl4ai) and every redirect hop.\n3. Disable automatic redirect following (or cap + re-validate each hop with pinning).\n4. Treat IPv4-mapped IPv6, decimal/octal/hex IPs, and CGNAT/non-global ranges as unsafe.","cveId":"CVE-2026-61430","cvssScore":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","severity":"high","vendor":"PyPI","product":"praisonaiagents","affectedVersions":["pkg:pypi/praisonaiagents < 1.6.78"],"cwes":["CWE-200","CWE-367","CWE-918"],"tags":["osv","osv:ghsa-qg25-6gc4-48mg","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-qg25-6gc4-48mg","type":"advisory","title":"OSV GHSA-qg25-6gc4-48mg"},{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-qg25-6gc4-48mg","type":"other","title":"OSV web"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61430","type":"advisory","title":"OSV advisory"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62169","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/MervinPraison/PraisonAI","type":"vendor","title":"OSV package"},{"url":"https://www.vulncheck.com/advisories/praisonai-before-dns-rebinding-ssrf-via-web-crawl","type":"other","title":"OSV web"}],"epssScore":0.00348,"epssPercentile":0.26274,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:36:50.000Z","addedAt":"2026-10-08T18:42:42.814Z","updatedAt":"2026-10-08T18:42:42.814Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61430","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-61430","note":"authoritative record"},{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-qg25-6gc4-48mg"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-qg25-6gc4-48mg"}]},{"id":"03ac9e90-045a-4995-940b-17bcadc8a8bc","slug":"cve-2026-107289","externalId":"CVE-2026-107289","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107289 — Pydantic AI is a Python agent framework for building applications and workflows with Generative AI.","description":"Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.56.0 until 1.107.6 and 2.44.0, applications that opt attacker-influenced URLs into local network access through FileUrl with force_download='allow-local' or web_fetch_tool with allow_local_urls=True can bypass the cloud-metadata blocklist by appending an IPv6 zone identifier to an IPv6 metadata address. IPv6Address equality and hashing include the zone identifier, so the blocklist comparison fails even though the network stack ignores the zone on a non-link-local destination and reaches the metadata service, potentially exposing cloud IAM credentials. The opt-in settings are disabled by default, and the issue requires an IPv6-enabled environment. This issue is fixed in versions 1.107.6 and 2.44.0.","cveId":"CVE-2026-107289","cvssScore":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","severity":"medium","vendor":"PyPI","product":"pydantic-ai","affectedVersions":["pkg:pypi/pydantic-ai >= 1.56.0, < 1.107.6","pkg:pypi/pydantic-ai >= 2.0.0b1, < 2.44.0","pkg:pypi/pydantic-ai-slim >= 1.56.0, < 1.107.6","pkg:pypi/pydantic-ai-slim >= 2.0.0b1, < 2.44.0"],"cwes":["CWE-918","CWE-1289"],"tags":["nvd","status:received","osv","osv:ghsa-vmxc-h2x2-jmf3","ecosystem:pypi","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/pydantic/pydantic-ai/commit/02157e1b87bd45d3f2e111ce07afdf89f9fb0e5b","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/commit/4da70591460f51a8c4f128eaeef70a33340dbd55","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/8401","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/8402","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.6","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/releases/tag/v2.44.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-vmxc-h2x2-jmf3","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-vmxc-h2x2-jmf3","type":"advisory","title":"OSV GHSA-vmxc-h2x2-jmf3"},{"url":"https://github.com/pydantic/pydantic-ai","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:17:04.337Z","addedAt":"2026-10-08T16:39:36.025Z","updatedAt":"2026-10-08T21:05:50.771Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107289","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107289","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-VMXC-H2X2-JMF3"}]},{"id":"07e8b501-d5b4-48c7-a532-0ad4fd786942","slug":"cve-2026-107288","externalId":"CVE-2026-107288","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107288 — Pydantic AI is a Python agent framework for building applications and workflows with Generative AI.","description":"Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.6 and 2.44.0, the local web_fetch_tool and the WebFetch local fallback compare blocked_domains entries with a URL hostname before both values are normalized to the form used by getaddrinfo. An attacker-influenced model can use an equivalent IDNA spelling, non-ASCII label separator, case variation, or trailing root label that resolves to a blocked host but does not match the configured string, causing the application to fetch that host with its own privileges. allowed_domains fails closed for unmatched spellings, and private-IP and cloud-metadata protections remain effective. This issue is fixed in versions 1.107.6 and 2.44.0.","cveId":"CVE-2026-107288","cvssScore":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-918","CWE-1289"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/pydantic/pydantic-ai/commit/490335f8e2322e143a79337ddca9410e0176c812","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/commit/a9dab92099d0ef9d5d4aa34ccac8a6f1b0e51284","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/commit/c1f212a084cbfa0012f2044cdb4731d214b3b983","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/8407","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/8409","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/8421","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.6","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/releases/tag/v2.44.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-22h6-qm39-v87j","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:17:04.147Z","addedAt":"2026-10-08T16:39:36.017Z","updatedAt":"2026-10-08T21:05:50.743Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107288","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107288","note":"authoritative record"}]},{"id":"0225d74c-4189-4e03-b973-550cf865d832","slug":"cve-2026-14521","externalId":"CVE-2026-14521","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-14521 — IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to…","description":"IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.","cveId":"CVE-2026-14521","cvssScore":4.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-918"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7285636","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T13:17:15.370Z","addedAt":"2026-10-08T14:40:02.586Z","updatedAt":"2026-10-08T21:05:48.720Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14521","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-14521","note":"authoritative record"}]},{"id":"748d3c90-0ae5-4bdc-9671-9232bafa359c","slug":"cve-2026-107449","externalId":"CVE-2026-107449","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107449 — linuxserver Heimdall through 2.8.3 applies its SafeUrlFetcher SSRF protection mechanism only to ItemController; the enhanced-application test and l…","description":"linuxserver Heimdall through 2.8.3 applies its SafeUrlFetcher SSRF protection mechanism only to ItemController; the enhanced-application test and live-stats requests occur via SupportedApps::execute(), a GuzzleHttp client that lacks IP address restrictions. In some realistic installations, the POST /test_config (and GET /get_stats) endpoints are accessible through CSRF, and thus an unauthenticated attacker can force the server to send requests to arbitrary internal hosts and ports (including 169.254.169.254) and read a status/port oracle in addition to partial response data.","cveId":"CVE-2026-107449","cvssScore":3.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-918"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/kashishtopi/heimdall-unauth-ssrf","type":"advisory","title":"cve@mitre.org"},{"url":"https://github.com/linuxserver/Heimdall/blob/9ad5864a80d7025db1e6eab8eb2981c165b0ddff/app/SupportedApps.php","type":"advisory","title":"cve@mitre.org"}],"epssScore":0.00162,"epssPercentile":0.04879,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T05:17:04.297Z","addedAt":"2026-10-08T06:39:29.473Z","updatedAt":"2026-10-08T23:06:37.147Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107449","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107449","note":"authoritative record"}]},{"id":"4629ea6e-69b8-4e07-b2a7-5f1e6f38ee68","slug":"cve-2026-76286","externalId":"CVE-2026-76286","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-76286 — In Splunk MCP Server versions below 1.2.1, Splunk MCP Server could send the Splunk platform authentication token of a user who runs a custom Applic…","description":"In Splunk MCP Server versions below 1.2.1, Splunk MCP Server could send the Splunk platform authentication token of a user who runs a custom Application Programming Interface (API) tool to the URL configured for that tool. If another user controls that URL, they could capture the token and use it to access data and perform actions as the user who ran the tool. Successful exploitation requires a user who holds a role that contains the mcp_tool_execute capability to run a custom API tool configured by another user. For more information see Configure the Splunk MCP Server (https://help.splunk.com/en/splunk-enterprise/mcp-server-for-splunk-platform/1.2/configure-the-splunk-mcp-server) and Managing custom tools in Splunk MCP Server (https://help.splunk.com/en/splunk-enterprise/mcp-server-for-splunk-platform/1.2/managing-custom-tools-in-splunk-mcp-server) in the Splunk documentation.","cveId":"CVE-2026-76286","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:L","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-918"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://advisory.splunk.com/advisories/SVD-2026-1004","type":"advisory","title":"psirt@cisco.com"}],"epssScore":0.00174,"epssPercentile":0.06249,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T21:17:20.387Z","addedAt":"2026-10-07T22:39:36.738Z","updatedAt":"2026-10-08T21:05:44.939Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76286","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-76286","note":"authoritative record"}]},{"id":"07cde138-7592-4fc7-a158-cf755af09ef1","slug":"cve-2026-76274","externalId":"CVE-2026-76274","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-76274 — In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the read_o11y_content capability could redirect an o…","description":"In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the read_o11y_content capability could redirect an outbound request from Splunk App for Splunk Observability Cloud through the Representational State Transfer (REST) API to an attacker-controlled host and disclose the configured Observability Cloud Application Programming Interface (API) token. The vulnerability is possible because Splunk App for Splunk Observability Cloud does not fully validate the destination of an outbound request. For more information see Authentication tokens (https://help.splunk.com/en/splunk-observability-cloud/administer/authentication-and-security/authentication-tokens) in the Splunk documentation.\n\nSplunk Enterprise versions 9.4.x are not affected.","cveId":"CVE-2026-76274","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-918"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://advisory.splunk.com/advisories/SVD-2026-1001","type":"advisory","title":"psirt@cisco.com"}],"epssScore":0.00267,"epssPercentile":0.17325,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T21:17:18.477Z","addedAt":"2026-10-07T22:39:36.645Z","updatedAt":"2026-10-08T21:05:44.418Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76274","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-76274","note":"authoritative record"}]},{"id":"acef84cb-420c-48b9-aa2a-77d7e2bc3277","slug":"cve-2026-61429","externalId":"GHSA-6g59-gm2v-qhvq","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"PraisonAI: Crawl4AI/Chromium backend is also affected by the `web_crawl` SSRF validation bypass","description":"## Summary\n\nThe DNS-rebinding / redirect SSRF bypass in PRAI-05 is **not limited to the httpx/urllib backend**. When `crawl4ai` (headless Chromium via Playwright) is installed, `web_crawl` auto-selects `provider=crawl4ai`, and the headless browser re-resolves DNS and follows redirects on its own — with no per-connection SSRF guard. Runtime-confirmed read-back of the internal canary via both DNS rebinding and redirect (`provider: \"crawl4ai\"`). Status: runtime-confirmed addendum to PRAI-05.\n\n## Details\n\n### Affected component\n- Package `praisonaiagents` 4.6.63. Backend selected when `crawl4ai`+Playwright are installed.\n- Files: `src/praisonai-agents/praisonaiagents/tools/web_crawl_tools.py` (`_crawl_with_crawl4ai`) and `src/praisonai-agents/praisonaiagents/tools/crawl4ai_tools.py` (standalone crawl wrappers).\n\n### Vulnerable code / root cause\n\nPath:\n`src/praisonai-agents/praisonaiagents/tools/web_crawl_tools.py`\n\nFunction:\n`_crawl_with_crawl4ai`\n\nSnippet:\n```python\nasync with AsyncWebCrawler() as crawler:\n    for url in urls:\n        result = await crawler.arun(url=url)   # headless browser: re-resolves DNS, follows redirects\n```\n\nPath:\n`src/praisonai-agents/praisonaiagents/tools/crawl4ai_tools.py`\n\nFunction:\n`Crawl4AITools.crawl` / `crawl4ai`\n\nSnippet:\n```python\nresult = await crawler.arun(url=url, config=config)   # no _is_safe_crawl_url / no per-connect validation\n```\n\nIssue: the only SSRF check is the single pre-fetch `_is_safe_crawl_url()` on the initial URL string in `web_crawl()` (see PRAI-05). The headless browser then resolves and connects independently and follows redirects in-browser — no resolved-IP pinning, no per-hop/per-connect validation. Input (`urls`) is attacker/agent-controlled; the sink is `crawler.arun(url=...)`; the guard is bypassed by DNS rebinding (TOCTOU) and by redirects (followed in-browser).\n\n### Attack flow / Why bypassed / Security boundary\nIdentical to PRAI-05: TOCTOU between the guard's resolution and the browser's connection; redirects followed in-browser; internal response returned as crawl `content`. See PRAI-05.\n\n## Proof of Concept\n\n### Environment\n`crawl4ai` + Playwright Chromium installed in a dedicated runtime container (`127.0.0.1:18081`), same controlled internal canary + rebinding DNS. Runnable assets: `PraisonAI-Runtime-Repro\\runtime-files\\` (`docker-compose.crawl.yml`).\n\n### Steps to reproduce\n1. `SSRF-04-01-Crawl4AI-DNS-Rebind-Trigger` → `127.0.0.1:18081`:\n```http\nPOST /tool/web_crawl HTTP/1.1\nHost: 127.0.0.1:18081\nContent-Type: application/json\n\n{\"url\":\"http://rebind.lab:8081/secret\"}\n```\n2. Redirect variant `SSRF-04-03-Crawl4AI-Redirect-Readback`: `{\"url\":\"http://redirector:8082/redirect-to-internal\"}`.\n\n### Expected result\nThe crawl backend refuses internal destinations regardless of DNS timing/redirects.\n\n### Actual result\nHTTP 200, `\"provider\":\"crawl4ai\"`, response `content` contains `PRAISONAI_INTERNAL_SECRET_CANARY_7f3a91` + `FAKE_INTERNAL_TOKEN_DO_NOT_USE_7f3a91` for both the DNS-rebinding and the redirect payload.\n\n### Screenshots\n\n**Crawl4AI DNS rebinding read-back**\n\nThe attacker-controlled `rebind.lab` URL is accepted by the Crawl4AI-backed `web_crawl` endpoint. PraisonAI returns the internal canary response body containing `PRAISONAI_INTERNAL_SECRET_CANARY_7f3a91`.\n\n<img width=\"1542\" height=\"763\" alt=\"01-Crawl4AI-Burp-Readback\" src=\"https://github.com/user-attachments/assets/a03b3a1c-e382-4f67-8ea6-b766dceb4a69\" />\n\n**Crawl4AI DNS rebinding runtime evidence**\n\nThe runtime log shows the Crawl4AI/Chromium backend resolving `rebind.lab` to an internal Docker IP during the fetch phase. The internal canary receives `GET /secret` from a headless Chrome user agent.\n\n<img width=\"1659\" height=\"946\" alt=\"02-Crawl4AI-DNS-Log-And-Internal-Hit\" src=\"https://github.com/user-attachments/assets/d93db090-3e39-43d0-af3b-5d1d8f614db8\" />\n\n**Crawl4AI redirect read-back**\n\nThe attacker-controlled redirector URL is accepted by the Crawl4AI-backed endpoint. PraisonAI follows the redirect and returns the internal canary response body.\n\n<img width=\"1544\" height=\"771\" alt=\"03-Crawl4AI-Redirect-Readback\" src=\"https://github.com/user-attachments/assets/7d05c8aa-5bda-45bc-b94c-bef0bdcf055c\" />\n\n**Crawl4AI redirect runtime evidence**\n\nThe controlled redirector returns `302 -> http://internal-canary:8081/secret`, and the internal canary receives `GET /secret` from the Crawl4AI/Chromium backend.\n\n<img width=\"1590\" height=\"920\" alt=\"04-Crawl4AI-Redirect-Internal-Hit-Log\" src=\"https://github.com/user-attachments/assets/dd9c0fec-3583-43ab-b83c-4470fa6aa409\" />\n\n\n## Impact\nSame class as PRAI-05: read-back SSRF to internal/metadata services, now on the crawl4ai backend. Broadens the affected surface (the flaw is in the shared validate-without-pinning design, not one backend).\n\n## Suggested remediation\nResolve-once + IP-pin + per-connect validation must also cover the crawl4ai backend (constrain the headless browser to the validated IP, or allowlist crawl destinations).","cveId":"CVE-2026-61429","cvssScore":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","severity":"high","vendor":"PyPI","product":"praisonaiagents","affectedVersions":["pkg:pypi/praisonaiagents < 1.6.78"],"cwes":["CWE-200","CWE-367","CWE-918"],"tags":["osv","osv:ghsa-6g59-gm2v-qhvq","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-6g59-gm2v-qhvq","type":"advisory","title":"OSV GHSA-6g59-gm2v-qhvq"},{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-6g59-gm2v-qhvq","type":"other","title":"OSV web"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61429","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/MervinPraison/PraisonAI","type":"vendor","title":"OSV package"},{"url":"https://www.vulncheck.com/advisories/praisonai-before-ssrf-via-crawl4ai-chromium-backend","type":"other","title":"OSV web"}],"epssScore":0.00348,"epssPercentile":0.26274,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T20:22:17.000Z","addedAt":"2026-10-08T00:42:50.063Z","updatedAt":"2026-10-08T00:42:50.063Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61429","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-61429","note":"authoritative record"},{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-6g59-gm2v-qhvq"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-6g59-gm2v-qhvq"}]},{"id":"5fab371e-65fb-43fe-9018-bfb7c66545a2","slug":"cve-2026-20362","externalId":"CVE-2026-20362","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-20362 — A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side reque…","description":"A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.\r\n\r\nThis vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain limited sensitive information for services that are associated with the affected device.","cveId":"CVE-2026-20362","cvssScore":7.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-918"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-finesse-ssrf-mmSuyugS","type":"advisory","title":"psirt@cisco.com"}],"epssScore":0.0047,"epssPercentile":0.38719,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T17:16:55.303Z","addedAt":"2026-10-07T18:39:31.322Z","updatedAt":"2026-10-08T21:05:42.499Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-20362","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-20362","note":"authoritative record"}]},{"id":"00c410f6-73a4-4339-b780-36e723e479ba","slug":"cve-2026-106557","externalId":"CVE-2026-106557","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106557 — Backstage is an open framework for building developer portals.","description":"Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package did not sufficiently validate TechDocs Markdown extension configuration. An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary, potentially exposing backend-host data or internal network resources. This issue is fixed in versions 1.14.6 and 1.15.4 when pymdown-extensions 10.21.3 or later is also used, normally through mkdocs-techdocs-core 1.7.0 or later.","cveId":"CVE-2026-106557","cvssScore":7.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","severity":"high","vendor":"npm","product":"@backstage/plugin-techdocs-node","affectedVersions":["pkg:npm/%40backstage/plugin-techdocs-node < 1.15.4"],"cwes":["CWE-22","CWE-918"],"tags":["nvd","status:received","osv","osv:ghsa-f7v3-xhm6-w245","ecosystem:npm","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/backstage/backstage/commit/017ace52d9b327ededc6704cf17799c875ae0f29","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/backstage/backstage/commit/2d9de4ca117a529de4b6ed7dfb7aa507ca7b3f91","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.50.5","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.54.6","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/backstage/backstage/security/advisories/GHSA-f7v3-xhm6-w245","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-f7v3-xhm6-w245","type":"advisory","title":"OSV GHSA-f7v3-xhm6-w245"},{"url":"https://github.com/backstage/backstage","type":"vendor","title":"OSV package"}],"epssScore":0.00297,"epssPercentile":0.2056,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T17:16:50.900Z","addedAt":"2026-10-07T18:39:31.275Z","updatedAt":"2026-10-08T23:06:36.693Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106557","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106557","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-F7V3-XHM6-W245"}]},{"id":"0dc54bee-b902-411f-a401-f2333e7aaa26","slug":"cve-2026-107273","externalId":"CVE-2026-107273","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107273 — Gophish 0.11.0 through 0.12.1 contains a server-side request forgery vulnerability that allows authenticated low-privileged users to reach loopback…","description":"Gophish 0.11.0 through 0.12.1 contains a server-side request forgery vulnerability that allows authenticated low-privileged users to reach loopback and private hosts via POST /api/import/site. Attackers can submit internal URLs, which the default dialer deny list does not block, to read service responses and enumerate internal hosts and ports through error messages.","cveId":"CVE-2026-107273","cvssScore":5.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-918"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.ostorlab.co/gophish-0121-manual-review-agentic-deep-scan.html","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/gophish/gophish","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/gophish/gophish/blob/b1648f0759c6d57ac989157c55d8b47c40254fe6/controllers/api/import.go#L102-L125","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/gophish/gophish/blob/b1648f0759c6d57ac989157c55d8b47c40254fe6/dialer/dialer.go#L82-L86","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/gophish-0.11.0-through-0.12.1-ssrf-via-post-api-import-site","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00199,"epssPercentile":0.0895,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T16:17:47.033Z","addedAt":"2026-10-07T16:39:32.758Z","updatedAt":"2026-10-07T22:39:36.393Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107273","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107273","note":"authoritative record"}]},{"id":"c6672cbb-c264-48c9-8f46-e49f3ad98d94","slug":"cve-2026-59707","externalId":"CVE-2026-59707","source":"OSV","sourceType":"osv","type":"vulnerability","title":"LocalAI POST /models/apply permits unauthenticated server-side request forgery through gallery URLs in github.com/mudler/LocalAI","description":"LocalAI POST /models/apply permits unauthenticated server-side request forgery through gallery URLs in github.com/mudler/LocalAI","cveId":"CVE-2026-59707","cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":"Go","product":"github.com/mudler/LocalAI","affectedVersions":["pkg:golang/github.com/mudler/LocalAI < 1.40.1-0.20260703213242-2cbb3c96b34d"],"cwes":["CWE-918"],"tags":["osv","osv:ghsa-8c5q-hx4g-qq23","ecosystem:go","osv:go-2026-6645"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/mudler/LocalAI/commit/f9b968e19d7cbc556d59dceb2e0e450b828a3fda"],"references":[{"url":"https://osv.dev/vulnerability/GHSA-8c5q-hx4g-qq23","type":"advisory","title":"OSV GHSA-8c5q-hx4g-qq23"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59707","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/mudler/LocalAI/issues/10665","type":"report","title":"OSV report"},{"url":"https://github.com/mudler/LocalAI/commit/f9b968e19d7cbc556d59dceb2e0e450b828a3fda","type":"patch","title":"OSV fix"},{"url":"https://github.com/mudler/LocalAI","type":"vendor","title":"OSV package"},{"url":"https://www.vulncheck.com/advisories/localai-server-side-request-forgery-via-post-models-apply","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GO-2026-6645","type":"advisory","title":"OSV GO-2026-6645"},{"url":"https://github.com/advisories/GHSA-8c5q-hx4g-qq23","type":"advisory","title":"OSV advisory"}],"epssScore":0.00482,"epssPercentile":0.3957,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T14:10:14.000Z","addedAt":"2026-10-02T19:54:22.567Z","updatedAt":"2026-10-07T18:42:43.772Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59707","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-59707","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-8C5Q-HX4G-QQ23"}]},{"id":"f0f0b65b-6d94-42e5-b680-b45a60a7c3e8","slug":"cve-2026-102255","externalId":"CVE-2026-102255","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102255 — A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.","description":"A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.","cveId":"CVE-2026-102255","cvssScore":10,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-441","CWE-918"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017","type":"advisory","title":"PSIRT@sonicwall.com"}],"epssScore":0.00477,"epssPercentile":0.39223,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T13:17:16.387Z","addedAt":"2026-10-07T14:39:35.059Z","updatedAt":"2026-10-07T16:39:32.100Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102255","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102255","note":"authoritative record"}]},{"id":"71a5520c-70ee-4783-ba5c-dd13e83c3602","slug":"cve-2026-97354","externalId":"CVE-2026-97354","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-97354 — The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.11 does not validate the destination of redirects when fetching a user-su…","description":"The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.11 does not validate the destination of redirects when fetching a user-supplied media URL, allowing users with the contributor role and above to perform Server-Side Request Forgery attacks against internal services.","cveId":"CVE-2026-97354","cvssScore":4.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-918"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://wpscan.com/vulnerability/473239c2-0b66-466b-98ac-391dad2853b9/","type":"advisory","title":"contact@wpscan.com"}],"epssScore":0.00179,"epssPercentile":0.06826,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T07:17:02.870Z","addedAt":"2026-10-07T08:39:33.470Z","updatedAt":"2026-10-07T16:39:31.918Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97354","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-97354","note":"authoritative record"}]},{"id":"b33bd945-2f89-4804-813f-10ac628850a4","slug":"cve-2026-106498","externalId":"CVE-2026-106498","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106498 — Backstage is an open framework for building developer portals.","description":"Backstage is an open framework for building developer portals. Prior to 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1, the @backstage/plugin-catalog-backend package is affected by improper url validation in catalog entity placeholder resolution. An authenticated Backstage user could craft a catalog entity with placeholder directives that reference resources outside the entity's source repository. Under certain configurations, this could allow access to data not intended to be available to the user. This issue is fixed in versions 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1.","cveId":"CVE-2026-106498","cvssScore":7.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","severity":"high","vendor":"npm","product":"@backstage/plugin-catalog-backend","affectedVersions":["pkg:npm/%40backstage/plugin-catalog-backend < 3.9.1"],"cwes":["CWE-863","CWE-918"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-qgvj-qcf8-xq73","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/backstage/backstage/commit/0b0f6fc89b4eb4872c76a498abbe1dc65998bb6e","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/commit/286bfc1f9cc3608a073b41016be302785be385d1","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/commit/61a10f19926aeda7f4a32de48d733e6710584634","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/commit/99729e925fd2bd40ba210022351a0ee6318e6197","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/commit/e786ac309ed2d775daf2309393c015c43902d6f6","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.49.6","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.50.5","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.51.3","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.53.2","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.54.6","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/security/advisories/GHSA-qgvj-qcf8-xq73","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-qgvj-qcf8-xq73","type":"advisory","title":"OSV GHSA-qgvj-qcf8-xq73"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106498","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/backstage/backstage","type":"vendor","title":"OSV package"}],"epssScore":0.00314,"epssPercentile":0.22357,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T22:17:04.713Z","addedAt":"2026-10-06T22:39:33.182Z","updatedAt":"2026-10-07T18:42:42.694Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106498","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106498","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-QGVJ-QCF8-XQ73"}]},{"id":"1bdc9e00-97eb-406e-8415-91e3978d98b1","slug":"cve-2026-106459","externalId":"CVE-2026-106459","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106459 — Backstage is an open framework for building developer portals.","description":"Backstage is an open framework for building developer portals. From 0.3.0 until 0.3.8, the @backstage/plugin-scaffolder-backend-module-sentry package is affected by improper input validation in sentry scaffolder actions. An authenticated internal user who can execute the affected actions may cause the backend to contact unintended destinations and disclose Sentry integration credentials. Subsequent impact depends on network reachability and the privileges granted to the configured token. This issue is fixed in version 0.3.8.","cveId":"CVE-2026-106459","cvssScore":8.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","severity":"high","vendor":"npm","product":"@backstage/plugin-scaffolder-backend-module-sentry","affectedVersions":["pkg:npm/%40backstage/plugin-scaffolder-backend-module-sentry >= 0.3.0, < 0.3.8"],"cwes":["CWE-200","CWE-918"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-g734-fhp4-7mfp","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/backstage/backstage/commit/b0170fad7962fb8c3d71366b5265cf283c7bbcf7","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.54.8","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.55.0","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/security/advisories/GHSA-g734-fhp4-7mfp","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-g734-fhp4-7mfp","type":"advisory","title":"OSV GHSA-g734-fhp4-7mfp"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106459","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/backstage/backstage","type":"vendor","title":"OSV package"}],"epssScore":0.00212,"epssPercentile":0.10534,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T21:17:16.450Z","addedAt":"2026-10-06T22:39:32.949Z","updatedAt":"2026-10-08T00:42:49.957Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106459","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106459","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-G734-FHP4-7MFP"}]}],"pagination":{"page":1,"limit":20,"total":1302,"totalPages":66,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:55:36.802Z","durationMs":35,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-918"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}