{"success":true,"data":{"threats":[{"id":"82e95429-084c-4acd-99ac-9fdc8c1aafed","slug":"cve-2026-107724","externalId":"CVE-2026-107724","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107724 — fast-jwt provides fast JSON Web Token (JWT) implementation.","description":"fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.2.4, fast-jwt can classify raw serialized public JWK or JWKS JSON as an HMAC secret because src/crypto.js performDetectPublicKeyAlgorithms treats non-PEM strings as symmetric key material. If HS256 is explicitly allowed or inferred, an attacker who knows the exact serialized public-key bytes can use those bytes as an HMAC key and create a token containing arbitrary claims that createVerifier accepts. Serialization ordering or whitespace differences can prevent exploitation, and applications using supported PEM keys with an asymmetric-only algorithm allowlist are not affected. This issue is fixed in version 6.3.0.","cveId":"CVE-2026-107724","cvssScore":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-347"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/nearform/fast-jwt/commit/10f9591349199ed2ab9fa1748ce92cdca697f6cf","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/nearform/fast-jwt/pull/636","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/nearform/fast-jwt/releases/tag/v6.3.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/nearform/fast-jwt/security/advisories/GHSA-g3jj-5cmm-3hxx","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T22:17:28.800Z","addedAt":"2026-10-08T23:06:40.181Z","updatedAt":"2026-10-08T23:06:40.181Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107724","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107724","note":"authoritative record"}]},{"id":"c1dd5c5e-3da4-4ee1-b44b-e711d974ab41","slug":"cve-2026-107723","externalId":"CVE-2026-107723","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107723 — fast-jwt provides fast JSON Web Token (JWT) implementation.","description":"fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.0, fast-jwt createVerifier accepts a validly signed JWT whose payload is a JSON array because src/decoder.js checks that the payload is an object but does not reject arrays. The claim validator loop then finds no named exp, nbf, iss, aud, sub, jti, or nonce properties and silently skips those configured checks, returning the array as a successfully verified payload. An attacker who can produce or influence a validly signed token may bypass expiry, issuer, audience, subject, revocation, and replay protections. The opt-in requiredClaims option can block missing claims, and signature verification itself is not bypassed. This issue is fixed in version 6.3.0.","cveId":"CVE-2026-107723","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-1287"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/nearform/fast-jwt/commit/86e83efd8b5244f50859532d99244f0a9a9a4368","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/nearform/fast-jwt/pull/639","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/nearform/fast-jwt/releases/tag/v6.3.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/nearform/fast-jwt/security/advisories/GHSA-5hjw-83fp-phq9","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T22:17:28.623Z","addedAt":"2026-10-08T23:06:40.168Z","updatedAt":"2026-10-08T23:06:40.168Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107723","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107723","note":"authoritative record"}]},{"id":"479e42c1-b22e-4a47-a4c4-f45ab30bce74","slug":"cve-2026-107722","externalId":"CVE-2026-107722","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107722 — fast-jwt provides fast JSON Web Token (JWT) implementation.","description":"fast-jwt provides fast JSON Web Token (JWT) implementation. From 6.2.0 until 6.3.0, fast-jwt can misclassify RSA public-key text as an HMAC secret when the key has non-whitespace content before its PEM header. In src/crypto.js, performDetectPublicKeyAlgorithms trims whitespace but publicKeyPemMatcher remains start-anchored, so comments, control characters, zero-width characters, or wrapper text can prevent PEM detection and reach the HMAC fallback. An attacker who knows the public key bytes can sign arbitrary HS256 claims with that public material when HS256 is inferred or allowed, resulting in authentication or authorization bypass. An asymmetric-only algorithm allowlist prevents the attack. This issue is fixed in version 6.3.0.","cveId":"CVE-2026-107722","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-347"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/nearform/fast-jwt/commit/d96bbc6c5336055a6dbfa318fdbab01197264cfa","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/nearform/fast-jwt/pull/632","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/nearform/fast-jwt/releases/tag/v6.3.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/nearform/fast-jwt/security/advisories/GHSA-ww5h-9m49-7xx4","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T22:17:28.447Z","addedAt":"2026-10-08T23:06:40.155Z","updatedAt":"2026-10-08T23:06:40.155Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107722","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107722","note":"authoritative record"}]},{"id":"05e7e095-182a-4216-bf84-dba1b3fccaa4","slug":"cve-2026-107721","externalId":"CVE-2026-107721","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107721 — fast-jwt provides fast JSON Web Token (JWT) implementation.","description":"fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.0, fast-jwt createVerifier accepts Infinity for clockTolerance because its option validation checks type and negativity but not finiteness. In validateClaimDateValue, infinite positive and negative modifiers make exp and nbf comparisons always pass, allowing expired or not-yet-active tokens to be accepted. The verifier cache also derives infinite bounds, so entries created under this configuration can remain valid until eviction. Exploitation requires an application administrator or equivalent configuration path to set clockTolerance to Infinity. This issue is fixed in version 6.3.0.","cveId":"CVE-2026-107721","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-613","CWE-682"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/nearform/fast-jwt/commit/c0fb5b88b4c88ff2bdd194ca2c713599ad9e38b6","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/nearform/fast-jwt/releases/tag/v6.3.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/nearform/fast-jwt/security/advisories/GHSA-687g-22h4-j4w4","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T22:17:28.263Z","addedAt":"2026-10-08T23:06:40.141Z","updatedAt":"2026-10-08T23:06:40.141Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107721","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107721","note":"authoritative record"}]},{"id":"8c4a5df4-9cf8-4918-89f8-e08af8fcb9e6","slug":"cve-2026-107720","externalId":"CVE-2026-107720","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107720 — fast-jwt provides fast JSON Web Token (JWT) implementation.","description":"fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.1, fast-jwt createVerifier accepts an unsigned JWT when key is an empty string or null and algorithms is a non-empty allowlist. Falsy synchronous keys bypass prepareKeyOrSecret, allowedAlgorithms remains active, hasKey is false, and the empty signature avoids the verifySignature gate. An attacker can therefore submit a token containing arbitrary claims without possessing a signing key, resulting in authentication or authorization bypass. Claim validators still run, and non-empty keys, an empty key without algorithms, and the async key resolver path do not have this behavior. This issue is fixed in version 6.3.1.","cveId":"CVE-2026-107720","cvssScore":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-20","CWE-347"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/nearform/fast-jwt/commit/e22a151e83bf6d5e54e281216982d204d5665534","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/nearform/fast-jwt/pull/649","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/nearform/fast-jwt/releases/tag/v6.3.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/nearform/fast-jwt/security/advisories/GHSA-8wpc-h4q6-8fxv","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T22:17:28.090Z","addedAt":"2026-10-08T23:06:40.127Z","updatedAt":"2026-10-08T23:06:40.127Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107720","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107720","note":"authoritative record"}]},{"id":"fd82a7b5-decb-41fa-af52-517f3a9036e6","slug":"cve-2026-107719","externalId":"CVE-2026-107719","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107719 — fast-jwt provides fast JSON Web Token (JWT) implementation.","description":"fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.4, the fast-jwt createVerifier cache can continue accepting a previously valid, signed JWT after its exp time when caching is enabled and the token has exp but no iat. In src/verifier.js, cacheSet derives the exp cache deadline only when iat is present, so the cache falls back to cacheTTL, and a later cache hit returns the saved payload before verifyToken rechecks expiration. An attacker who can replay the same cached bearer token can extend access until the cache entry expires, but cannot forge a token through this issue. This issue is fixed in version 6.3.4.","cveId":"CVE-2026-107719","cvssScore":4.2,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-613"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/nearform/fast-jwt/commit/fc1ddbbe5ce38066ba2cea0b0ce0233932757167","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/nearform/fast-jwt/releases/tag/v6.3.4","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/nearform/fast-jwt/security/advisories/GHSA-x937-hj6v-793p","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T22:17:27.913Z","addedAt":"2026-10-08T23:06:40.112Z","updatedAt":"2026-10-08T23:06:40.112Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107719","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107719","note":"authoritative record"}]},{"id":"4f90df58-77c3-482e-ae97-dd5de2356237","slug":"cve-2026-107717","externalId":"CVE-2026-107717","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107717 — Banks generates meaningful LLM prompts using a simple template language.","description":"Banks generates meaningful LLM prompts using a simple template language. Prior to 2.5.0, Banks Prompt.chat_messages() attempts to parse every line of rendered template output as ChatMessage JSON. When an application renders untrusted data and passes the returned ChatMessage objects to an LLM provider, attacker-controlled JSON can cross the prompt boundary and become a system, assistant, or tool message because ChatMessage.role accepts arbitrary strings. This can override application instructions, alter the intended prompt structure, or confuse downstream tool and message handling. This issue is fixed in version 2.5.0.","cveId":"CVE-2026-107717","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-20"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/masci/banks/commit/02172b816fb84f6a824cc09a8aca7416f53c12cb","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/masci/banks/pull/78","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/masci/banks/releases/tag/v2.5.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/masci/banks/security/advisories/GHSA-hmq2-7hp6-7crh","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T22:17:27.560Z","addedAt":"2026-10-08T23:06:40.085Z","updatedAt":"2026-10-08T23:06:40.085Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107717","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107717","note":"authoritative record"}]},{"id":"6006bd8e-0662-4ea9-966b-5f5c38592519","slug":"cve-2026-107716","externalId":"CVE-2026-107716","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107716 — Banks generates meaningful LLM prompts using a simple template language.","description":"Banks generates meaningful LLM prompts using a simple template language. Prior to 2.5.1, Banks DirectoryPromptRegistry does not reject symbolic links for index.json or discovered and existing .jinja prompt files. In an application where untrusted users can influence a prompt directory, DirectoryPromptRegistry._scan() and DirectoryPromptRegistry.get() can follow a link outside the registry root and disclose a file, while DirectoryPromptRegistry.set(), DirectoryPromptRegistry._save(), and DirectoryPromptRegistry._load() can read or overwrite an external link target. The issue requires attacker influence over the registry directory or its extracted contents. This issue is fixed in version 2.5.1.","cveId":"CVE-2026-107716","cvssScore":7.3,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-22","CWE-59"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/masci/banks/commit/23ed13e50b4e217693fa5f9c30943fac8a41582f","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/masci/banks/pull/79","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/masci/banks/releases/tag/v2.5.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/masci/banks/security/advisories/GHSA-556j-vv39-8rqv","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T22:17:27.323Z","addedAt":"2026-10-08T23:06:40.072Z","updatedAt":"2026-10-08T23:06:40.072Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107716","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107716","note":"authoritative record"}]},{"id":"b8d5c1e4-4346-447b-b158-0afac875028d","slug":"cve-2026-11318","externalId":"CVE-2026-11318","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-11318 — Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.deskin.service.installer XPC service that allows local unprivileged…","description":"Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.deskin.service.installer XPC service that allows local unprivileged attackers to execute arbitrary installer packages as root by connecting to the root-owned service without authentication. Attackers can invoke the privileged installer method to run an attacker-supplied installer, achieving full root compromise of the macOS host.","cveId":"CVE-2026-11318","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-306"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://deskin.io/","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/Cr0wld3r/CVE-2026-11318","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/deskin-xpc-service-privilege-escalation-via-unauthenticated-installer","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T21:17:53.377Z","addedAt":"2026-10-08T23:06:39.539Z","updatedAt":"2026-10-08T23:06:39.539Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-11318","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-11318","note":"authoritative record"}]},{"id":"2546aa8f-7947-4936-99cf-0dd19a42c12e","slug":"cve-2026-107781","externalId":"CVE-2026-107781","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107781 — Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a server-side request forgery and missing authorization vulnerabili…","description":"Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a server-side request forgery and missing authorization vulnerability in the OnlyOffice save callback editUploadOfficeFileById. Unauthenticated attackers can supply arbitrary url and key parameters to make the server fetch internal URLs and overwrite any user's stored file, then read results via queryFileToShowById.","cveId":"CVE-2026-107781","cvssScore":9.1,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-918"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/dromara/skyeye","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/dromara/skyeye/blob/003549ae5615bd114ba5bb8ddf6a8e8ead97c321/skyeye-adm/adm-pro/src/main/java/com/skyeye/eve/diskcloud/service/impl/FileConsoleServiceImpl.java#L533-L556","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/dromara/skyeye/issues/29","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/dromara-skyeye-unauthenticated-ssrf-and-file-overwrite-via-edituploadofficefilebyid","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T21:17:53.080Z","addedAt":"2026-10-08T23:06:39.512Z","updatedAt":"2026-10-08T23:06:39.512Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107781","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107781","note":"authoritative record"}]},{"id":"b71befbb-3f88-438d-96b9-bf0a4915fbac","slug":"cve-2026-107780","externalId":"CVE-2026-107780","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107780 — Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains an OS command injection vulnerability in the unauthenticated /post/…","description":"Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains an OS command injection vulnerability in the unauthenticated /post/TtsController/textToSpeech endpoint via the format parameter. Attackers can inject a single quote into format to break out of the PowerShell string and execute commands as the Skyeye service account on Windows.","cveId":"CVE-2026-107780","cvssScore":9.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-78"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/dromara/skyeye","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/dromara/skyeye/blob/003549ae5615bd114ba5bb8ddf6a8e8ead97c321/skyeye-promote/skyeye-common/src/main/java/com/skyeye/common/service/impl/TtsServiceImpl.java#L105-L166","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/dromara/skyeye/issues/29","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/dromara-skyeye-unauthenticated-os-command-injection-via-texttospeech-format-parameter","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T21:17:52.940Z","addedAt":"2026-10-08T23:06:39.499Z","updatedAt":"2026-10-08T23:06:39.499Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107780","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107780","note":"authoritative record"}]},{"id":"22a0d28e-26ed-47b1-b8b9-5860a937c3ca","slug":"cve-2026-107779","externalId":"CVE-2026-107779","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107779 — Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a missing authentication vulnerability in bundled xxl-job-admin Job…","description":"Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a missing authentication vulnerability in bundled xxl-job-admin JobInfoController endpoints annotated with @PermissionLimit(limit = false). Unauthenticated attackers can POST GLUE_SHELL, GLUE_PYTHON, or GLUE_POWERSHELL jobs with attacker-supplied glueSource to /jobinfo/addAndStart, executing commands on the executor host or stopping and deleting jobs.","cveId":"CVE-2026-107779","cvssScore":9.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-306"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/dromara/skyeye","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/dromara/skyeye/blob/003549ae5615bd114ba5bb8ddf6a8e8ead97c321/xxl-job-2.3.0/xxl-job-admin/src/main/java/com/xxl/job/admin/controller/JobInfoController.java#L183-L231","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/dromara/skyeye/issues/29","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/dromara-skyeye-xxl-job-admin-missing-authentication-on-job-endpoints-allows-rce","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T21:17:52.790Z","addedAt":"2026-10-08T23:06:39.484Z","updatedAt":"2026-10-08T23:06:39.484Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107779","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107779","note":"authoritative record"}]},{"id":"dbf0c28e-cf50-41ea-8051-4fe20b6d3370","slug":"cve-2026-107397","externalId":"CVE-2026-107397","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107397 — Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask.","description":"Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, users who can create content, including speakers who can create minutes, can store crafted HTML in event minutes. When concurrent edits are made to the same minutes, the minute editor conflict UI can execute attacker-controlled script in the viewer's browser in the Indico origin. This issue is fixed in version 3.3.13.","cveId":"CVE-2026-107397","cvssScore":4.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-79"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/indico/indico/commit/d4c8c7127176efa4cb53c64119ca8ee2b551be18","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/indico/indico/pull/7619","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/indico/indico/releases/tag/v3.3.13","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/indico/indico/security/advisories/GHSA-cw24-x4mj-fw3q","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T21:17:51.937Z","addedAt":"2026-10-08T23:06:39.439Z","updatedAt":"2026-10-08T23:06:39.439Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107397","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107397","note":"authoritative record"}]},{"id":"209432fa-9645-4dbf-8802-31296c0c49b6","slug":"cve-2026-107318","externalId":"CVE-2026-107318","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107318 — @fastify/reply-from is a Fastify plugin that forwards requests to an upstream HTTP or HTTPS server.","description":"@fastify/reply-from is a Fastify plugin that forwards requests to an upstream HTTP or HTTPS server. In versions prior to 12.7.0, all of the built-in HTTPS transports override the secure default and set rejectUnauthorized to false, so the proxy does not verify the TLS certificate of the upstream even when the application points it at an https upstream in the default configuration. An on-path network attacker can therefore impersonate the configured HTTPS upstream, read the credentials and request bodies the proxy forwards, and return forged responses that the application trusts. The issue is fixed in @fastify/reply-from 12.7.0, and users should upgrade to 12.7.0 or later. As a workaround, pass an explicit rejectUnauthorized true on the transport, supply an already configured undici instance, or use the undici global agent.","cveId":"CVE-2026-107318","cvssScore":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-295"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://cna.openjsf.org/security-advisories.html","type":"advisory","title":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"url":"https://github.com/fastify/fastify-reply-from/security/advisories/GHSA-j425-jw94-m29r","type":"advisory","title":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T21:17:51.807Z","addedAt":"2026-10-08T23:06:39.424Z","updatedAt":"2026-10-08T23:06:39.424Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107318","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107318","note":"authoritative record"}]},{"id":"2acb15a9-507a-41be-afd8-66af429100ea","slug":"cve-2026-102368","externalId":"CVE-2026-102368","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102368 — Affected Tapo device firmware stores device-specific cryptographic material in plaintext within nonvolatile storage.","description":"Affected Tapo device firmware stores device-specific cryptographic material in plaintext within nonvolatile storage. An attacker with physical access to an affected device can recover this sensitive material from the firmware. \n\nSuccessful exploitation of this vulnerability may result in the disclosure of device-specific cryptographic material and could, under certain conditions, increase the risk of unauthorized access to related protected information or communications.","cveId":"CVE-2026-102368","cvssScore":5.4,"cvssVector":"CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-312"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.tp-link.com/us/support/download/tapo-s505/#Firmware-Release-Notes","type":"advisory","title":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/faq/5332/","type":"advisory","title":"f23511db-6c3e-4e32-a477-6aa17d310630"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T21:17:51.397Z","addedAt":"2026-10-08T23:06:39.391Z","updatedAt":"2026-10-08T23:06:39.391Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102368","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102368","note":"authoritative record"}]},{"id":"b4beefc5-fe47-4c59-bd73-0c9decd67cc5","slug":"cve-2026-107707","externalId":"CVE-2026-107707","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107707 — Intego Antivirus for Windows through 3.0.0.1 contains a link following vulnerability in its optimization module that allows local unprivileged user…","description":"Intego Antivirus for Windows through 3.0.0.1 contains a link following vulnerability in its optimization module that allows local unprivileged users to delete arbitrary folders as SYSTEM. Attackers can replace a scanned duplicate file's directory with a junction to C:\\Config.msi and abuse Windows Installer rollback to execute code as SYSTEM.","cveId":"CVE-2026-107707","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-59"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.quarkslab.com/milking-the-last-drop-of-intego-time-for-windows-to-get-its-lpe.html","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.intego.com/","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/intego-antivirus-through-3.0.0.1-local-privilege-escalation-via-optimization-module-junction","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:35.690Z","addedAt":"2026-10-08T21:05:53.368Z","updatedAt":"2026-10-08T23:06:39.362Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107707","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107707","note":"authoritative record"}]},{"id":"a01a5b11-d109-4914-9845-206120efeaaf","slug":"cve-2026-107706","externalId":"CVE-2026-107706","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107706 — Dolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core/ajax/updateextrafield.php that checks only read per…","description":"Dolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core/ajax/updateextrafield.php that checks only read permission before writing extrafield values. Authenticated users with read-only access can POST objectType, objectId, field and value parameters to persistently modify extrafields on viewable third parties, products, members, projects or contacts.","cveId":"CVE-2026-107706","cvssScore":5.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-863"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Dolibarr/dolibarr","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/Dolibarr/dolibarr/blob/24.0.1/htdocs/core/ajax/updateextrafield.php#L80","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/Dolibarr/dolibarr/commit/3420d17b199059ac22fca8b59f23cb8962fc8ef8","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/dolibarr-before-24.0.2-incorrect-authorization-via-updateextrafield-php","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:35.503Z","addedAt":"2026-10-08T21:05:53.311Z","updatedAt":"2026-10-08T23:06:39.341Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107706","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107706","note":"authoritative record"}]},{"id":"d0ce1ab4-e33c-471d-a940-5d0cff40dda8","slug":"cve-2026-107705","externalId":"CVE-2026-107705","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107705 — Poppler 0.42.0 through 26.10.0 contains a stack-based buffer overflow in Decrypt::revision6Hash() that allows attackers controlling the password to…","description":"Poppler 0.42.0 through 26.10.0 contains a stack-based buffer overflow in Decrypt::revision6Hash() that allows attackers controlling the password to overwrite stack memory when opening AESV3/R6 encrypted PDFs. Attackers can supply a password longer than 127 bytes through applications using the libpoppler, libpoppler-glib or C++ API to overflow the K1 and E buffers, crashing the process or corrupting memory.","cveId":"CVE-2026-107705","cvssScore":8.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-121"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://gitlab.freedesktop.org/poppler/poppler","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://gitlab.freedesktop.org/poppler/poppler/-/blob/poppler-26.10.0/poppler/Decrypt.cc#L1767","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2398","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1814","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/poppler-0.42.0-through-26.10.0-stack-buffer-overflow-via-decrypt-revision6hash","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:35.300Z","addedAt":"2026-10-08T21:05:53.273Z","updatedAt":"2026-10-08T23:06:39.327Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107705","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107705","note":"authoritative record"}]},{"id":"169c981d-6fa7-431c-aeb0-4680532b6441","slug":"cve-2026-107396","externalId":"CVE-2026-107396","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107396 — Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask.","description":"Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, users who can manage events or create content, including speakers who can upload material, can store crafted javascript URLs in fields that accept custom URLs. A user who follows one of these URLs can execute attacker-controlled script in the user's browser in the Indico origin. This issue is fixed in version 3.3.13.","cveId":"CVE-2026-107396","cvssScore":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-692"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/indico/indico/commit/d4c8c7127176efa4cb53c64119ca8ee2b551be18","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/indico/indico/pull/7619","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/indico/indico/releases/tag/v3.3.13","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/indico/indico/security/advisories/GHSA-c4wc-ggrj-jg9v","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:34.417Z","addedAt":"2026-10-08T21:05:53.210Z","updatedAt":"2026-10-08T21:05:53.210Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107396","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107396","note":"authoritative record"}]},{"id":"e7710434-db62-4435-9d72-5db3a0047c7d","slug":"cve-2026-107395","externalId":"CVE-2026-107395","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107395 — Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask.","description":"Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, an authenticated user can misuse the legacy session export API to retrieve details for a restricted session without access to that session, as long as the containing event is accessible. The missing access check can disclose session metadata such as the title, description, and conveners. This issue is fixed in version 3.3.13.","cveId":"CVE-2026-107395","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-862"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/indico/indico/commit/524e8e93eadcd8484905b1147020a35f5dce6038","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/indico/indico/releases/tag/v3.3.13","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/indico/indico/security/advisories/GHSA-6p4f-j8j6-463q","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:34.250Z","addedAt":"2026-10-08T21:05:53.094Z","updatedAt":"2026-10-08T21:05:53.094Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107395","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107395","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":20246,"totalPages":1013,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:15:16.750Z","durationMs":159,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":["status:deferred"],"cwe":[],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}