3w ago
2026-08-25 20:16Z
CRIT

CVE-2026-45018 — Chainlit: From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45018

Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requiring authentication. For stdio transport, the endpoint accepts a user-controlled fullCommand string. The validate_mcp_command() function in backend/chainlit/mcp.py checks only the executable name against config.features.mcp.stdio.al CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDChainlitTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-25 20:16Z
HIGH

CVE-2026-43670 — Content: A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43670

A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may bypass Content Security Policy. CVSSv3.1 8.8 (HIGH)

CWECWE 693VNDContentTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-25 19:16Z
HIGH

CVE-2026-80049 — Airbyte: Platform resolves the workspace used for its authorization decision from a field the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80049

Airbyte Platform resolves the workspace used for its authorization decision from a field the caller supplies. AuthorizationServerHandler copies recognised identifiers out of the raw JSON request body into X-Airbyte-* headers, and AuthenticationHeaderResolver.resolveWorkspace consults X-Airbyte-Workspace-Id ahead of every resource-derived header, including those for connection, source and destination identifiers. Endpoints whose declared request bodies carry only a resource id CVSSv3.1 8.8 (HIGH)

CWECWE 639VNDAirbyteTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-25 19:16Z
CRIT

CVE-2026-79787 — REST: Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79787

Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. Attackers can extract usernames from unsigned Authorization headers and impersonate any user, including service accounts, to read, write, and delete arbitrary data. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDRestTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-25 19:16Z
HIGH

CVE-2026-78379 — Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78379

Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute arbitrary Python code on the agent's host by bypassing the human consent gate, via a crafted prompt that forwards non_interactive_mode as a keyword argument through the batch tool. To remediate this issue, users should upgrade to version 0.8.5 or later. CVSSv3.1 8.1 (HIGH)

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-25 18:18Z
CRIT

CVE-2026-76197 — Adobe: Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76197

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 10.0 (CRITICAL)

CWECWE 78VNDAdobeTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
3w ago
2026-08-25 18:18Z
CRIT

CVE-2026-76195 — Adobe: Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76195

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 10.0 (CRITICAL)

CWECWE 78VNDAdobeTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
728 × 90 / responsive · programmatic ad slot
3w ago
2026-08-25 18:18Z
CRIT

CVE-2026-76193 — Adobe: Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76193

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 10.0 (CRITICAL)

CWECWE 918VNDAdobeTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
3w ago
2026-08-25 17:17Z
HIGH

CVE-2026-55585 — QWED: The default-enabled POST /auth/signup endpoint allows anyone to create a standard tenant account, POST

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55585

QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, tool calls, code, schemas, and agent state before production execution. Prior to 5.1.2, the qwed package passes caller-controlled math expressions directly to SymPy parse_expr() without restricted global_dict and local_dict namespaces, allowing Python eval() to resolve builtins and execute arbitrary Python code in the API server process. In src/qwed_new/api/main.py, POST /verify/ CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDQwedTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-25 17:17Z
HIGH

CVE-2026-55571 — Phoenix: Because LiveViewConsumer.handle_event does not recheck authentication or authorization, the client can send `{"type":"event",...}` frames

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55571

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to 1.0.4, LiveViewConsumer.handle_mount sends a `{"type":"navigate","to":...}` frame when login_required, permission_required, or a redirecting on_mount hook denies a LiveView mount, but returns without closing the WebSocket or clearing self.view_instance. A browser follows the redirect, but a raw WebSocket client can ignore it and retain the mounted socket. Be CVSSv3.1 8.2 (HIGH)

CWECWE 306CWECWE 285VNDPhoenixTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
3w ago
2026-08-25 17:17Z
HIGH

CVE-2026-47626 — NVIDIA: DGX Spark contains a vulnerability in the system firmware, where a privileged attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47626

NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering. CVSSv3.1 8.2 (HIGH)

CWECWE 787VNDNvidiaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
3w ago
2026-08-25 17:17Z
HIGH

CVE-2026-24263 — NVIDIA: DGX Spark contains a vulnerability in the system firmware, where a privileged attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24263

NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause a NULL pointer dereference. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering. CVSSv3.1 8.2 (HIGH)

CWECWE 476VNDNvidiaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
3w ago
2026-08-25 17:17Z
HIGH

CVE-2026-24262 — NVIDIA: DGX Spark contains a vulnerability in the system firmware, where a privileged attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24262

NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering. CVSSv3.1 8.2 (HIGH)

CWECWE 787VNDNvidiaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
3w ago
2026-08-25 17:17Z
HIGH

CVE-2026-24170 — NVIDIA: A successful exploit of this vulnerability might lead to code execution and escalation of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24170

NVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component, where an authenticated user could cause improper authentication by sending specially crafted HTTP requests. A successful exploit of this vulnerability might lead to code execution and escalation of privileges. CVSSv3.1 8.8 (HIGH)

CWECWE 287VNDNvidiaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-25 17:17Z
HIGH

CVE-2026-24169 — NVIDIA: A successful exploit of this vulnerability might lead to code execution, escalation of privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24169

NVIDIA UFM Enterprise contains a vulnerability in the plugin management API, where an authenticated user with low privileges could inject code by sending a specially crafted API request. A successful exploit of this vulnerability might lead to code execution, escalation of privileges and information disclosure. CVSSv3.1 8.0 (HIGH)

CWECWE 77VNDNvidiaTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
3w ago
2026-08-25 17:17Z
CRIT

CVE-2026-19912 — Kaltura: The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19912

The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vulnerability caused by unsafe data deserialization and unsanitized filesystem path construction. mwEmbedLoader.php accepts a user‑controlled ServiceUrl, whose response is passed to unserialize(), and the resulting object’s fields are written to a cache path derived from attacker‑supplied uiconf_id without proper path validation. An attacker can write arbitrary files into web‑acces CVSSv3.1 9.8 (CRITICAL) · EPSS 13th percentile

CWECWE 22CWECWE 20VNDKalturaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-25 16:17Z
HIGH

CVE-2026-79784 — Vocos: instantiates a class named by a configuration file without restricting which class may

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79784

Vocos instantiates a class named by a configuration file without restricting which class may be named. instantiate_class in vocos/pretrained.py takes the class_path value from the configuration, splits it into a module and an attribute, imports the module with __import__, resolves the attribute with getattr, and calls the result as args_class(*args, **kwargs) where kwargs is the config's own init_args mapping. No allowlist constrains the dotted path, so a configuration may na CVSSv3.1 8.8 (HIGH)

CWECWE 470VNDVocosTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-25 16:17Z
HIGH

CVE-2026-79774 — Winter: CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79774

Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\\Twig\\SecurityPolicy that allows authenticated backend users with template-editing permissions to bypass sandbox restrictions. Attackers can exploit method forwarding through Eloquent models and query builders using methods like saveQuietly(), deleteQuietly(), increment(), decrement(), and newQuery() to read and modify arbitrary database records, execute arbitrary SQ CVSSv3.1 8.4 (HIGH)

CWECWE 693VNDWinterTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
3w ago
2026-08-25 16:17Z
CRIT

CVE-2026-79675 — NLTK: Attackers can supply malicious options like -agentpath, -javaagent, or @argfile to Stanford wrapper classes

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79675

NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or @argfile to Stanford wrapper classes to achieve arbitrary code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 88VNDNltkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-25 16:17Z
HIGH

CVE-2026-79674 — NLTK: versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructors that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79674

NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructors that allows attackers to read files outside the intended data root. Attackers can supply arbitrary corpus root paths to LinThesaurusCorpusReader and PanLexLiteCorpusReader constructors to access filesystem content and SQLite databases outside the pathsec sandbox boundary. CVSSv3.1 8.2 (HIGH)

CWECWE 73VNDNltkTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
3w ago
2026-08-25 16:16Z
CRIT

CVE-2026-55640 — Nextcloud: MCP Server is a production-ready MCP server that connects AI assistants to a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55640

Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud instance. Prior to 0.117.2, the POST /webhooks/nextcloud endpoint in nextcloud_mcp_server/vector/webhook_receiver.py has no authentication by default because WEBHOOK_SECRET defaults to None and startup validation does not require it. When WEBHOOK_SECRET is unset, handle_nextcloud_webhook() accepts unauthenticated requests. The payload["user"]["uid"] field parsed in nextcloud_mcp_s CVSSv3.1 9.1 (CRITICAL)

CWECWE 306VNDNextcloudTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-25 16:16Z
HIGH

CVE-2026-55582 — MCP: Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while security.go omits !

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55582

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while security.go omits ! from containsShellMetacharacters and containsDangerousShellConstructs and applies no per-executable argument policy. A caller of the shell_exec MCP tool can provide the command argument /usr/bin/git -c alias.pwn=!<arbitrary-command>, causing Git to create a shell alias and execute arbitrary OS comman CVSSv3.1 8.4 (HIGH)

CWECWE 78VNDMcpTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
3w ago
2026-08-25 16:16Z
HIGH

CVE-2026-55581 — MCP: A caller of the shell_exec MCP tool can provide the command argument `/bin/bash -c

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55581

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default Docker security.yaml includes /bin/bash in allowed_executables, while security.go validates only the first token and checkBlockedPatternsAndCommands does not reject the shell command-mode flag -c. A caller of the shell_exec MCP tool can provide the command argument `/bin/bash -c <arbitrary-command>`, which passes validation and reaches executor.go, where parse CVSSv3.1 8.4 (HIGH)

CWECWE 78CWECWE 1188CWECWE 183VNDMcpTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
3w ago
2026-08-25 16:16Z
CRIT

CVE-2026-55546 — QWED: Prior to 0.2.1, verify_math_expression() in src/qwed_mcp/engines/math_engine.py passes attacker-controlled expression and claimed_result strings directly to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55546

QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2.1, verify_math_expression() in src/qwed_mcp/engines/math_engine.py passes attacker-controlled expression and claimed_result strings directly to SymPy's parse_expr() after only normalizing caret syntax to Python exponent syntax, without restricting global_dict, removing Python built-ins, or validating the expression AST. Because parse_expr() calls Python's eval() with built-ins available, an attacker who ca CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDQwedTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-25 16:16Z
HIGH

CVE-2026-55539 — PraisonAI: Prior to praisonai 4.6.51, the Jobs API create_app function mounts /api/v1/runs without authentication.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55539

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, the Jobs API create_app function mounts /api/v1/runs without authentication. Any reachable caller can submit jobs, read results, cancel runs, or delete jobs using operator credentials. The fix adds PRAISONAI_JOBS_API_KEY middleware for Authorization or X-API-Key. This issue is fixed in version 4.6.58. CVSSv3.1 8.6 (HIGH)

CWECWE 306VNDPraisonaiTYPVulnerability
8.6
CVSS v3.1
93
Edit Score