2026-06-23
2026-06-23 19:18Z
CRIT

Nuclei Templates v10.4.5 - Release Notes

Nuclei Templates v10.4.5 release adds 86 new detection templates covering 64 CVEs, including critical RCE vulnerabilities in WordPress plugins, Joomla extensions, Oracle PeopleSoft, Splunk, Palo Alto PAN-OS, and multiple authentication bypass flaws. The release includes significant bug fixes addressing false positives/negatives in WAF detection, Docker enumeration, and Apache Struts2 exploitation patterns, plus 22 first-time community contributors.

SRFApplicationSRFNetworkSRFWebSWNucleiSWNuclei TemplatesVNDProjectdiscoveryTYPTool
78
Edit Score
2026-06-23
2026-06-23 19:17Z
HIGH

CVE-2026-54320 — Daytona: On identity providers that allow self-service signup and issue a session before the email

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54320

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.184.0, organization invitations could be accepted (and declined) by a user whose email matched the invitation but had not been verified. Daytona authenticates users via OIDC and matches an invitation's target email against the email in the caller's token, but the invitation accept and decline paths did not require that email to be verified, unlike organizatio CVSSv3.1 8.4 (HIGH)

CWECWE 287CWECWE 863VNDDaytonaTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-06-23
2026-06-23 19:17Z
HIGH

CVE-2026-53755 — Crawl4AI: Prior to 0.8.9, the Docker API server applied its SSRF destination check to the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53755

Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.9, the Docker API server applied its SSRF destination check to the crawl target URL only, not to the proxy address. An unauthenticated request could supply a proxy pointing at an internal IP and route the browser through it, reaching internal services and cloud-metadata endpoints, while using a perfectly valid crawl URL. The Docker API is unauthenticated by default. /crawl, /crawl/stream, and /crawl/j CVSSv3.1 8.6 (HIGH)

CWECWE 918VNDCrawl4aiTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-23
2026-06-23 19:17Z
CRIT

CVE-2026-53753 — Crawl4AI: Python generator and frame object attributes (gi_frame, f_back, f_builtins) do NOT start with underscore

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53753

Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature uses an AST validator that only blocks attributes starting with underscore. Python generator and frame object attributes (gi_frame, f_back, f_builtins) do NOT start with underscore, enabling a complete sandbox escape to achieve arbitrary code execution. The attack requires no authentication (JWT disabled by default) and is triggere CVSSv3.1 9.8 (CRITICAL)

CWECWE 94CWECWE 913VNDCrawl4aiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-23
2026-06-23 18:18Z
CRIT

CVE-2026-54316 — Anthropic Claude_code: From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54316

Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that domain—including attacker-controlled model repositories—was auto-approved without a permission prompt or being subject to --allowedTools restrictions. An attacker able to inject untrusted content into a Claude Code context could direct it to issue WebFetch requests against attacker-controlled reposit CVSSv3.1 9.1 (CRITICAL) · EPSS 33th percentile

CWECWE 200CWECWE 183CWECWE 515VNDAnthropicVNDClaudeTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-23
2026-06-23 18:18Z
CRIT

CVE-2026-54157 — LobeHub: An attacker can use this to make arbitrary outbound requests from LobeHub's infrastructure, leak

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54157

LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.57, the /webapi/proxy endpoint on app.lobehub.com accepts a URL in the POST body and fetches it server-side without any authentication. An attacker can use this to make arbitrary outbound requests from LobeHub's infrastructure, leak Vercel deployment details, and inject cookies on the lobehub.com domain through reflected Set-Cookie headers. This vulnerab CVSSv3.1 9.0 (CRITICAL)

CWECWE 918VNDLobehubTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-06-23
2026-06-23 18:18Z
HIGH

CVE-2026-54011 — Open: Prior to 0.9.6,Open WebUI renders Mermaid blocks from Markdown files in the file preview

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54011

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6,Open WebUI renders Mermaid blocks from Markdown files in the file preview panel and inserts the generated SVG into the DOM using innerHTML. Because Mermaid is configured with securityLevel: 'loose', attacker-controlled Mermaid content can be rendered unsafely in this flow. A working payload was validated through the Markdown preview path, resulting in JavaScript e CVSSv3.1 8.7 (HIGH)

CWECWE 79TYPVulnerability
8.7
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-23
2026-06-23 18:18Z
HIGH

CVE-2026-54010 — Open: Prior to 0.9.6, Open WebUI lets an authenticated user attach arbitrary file_id values to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54010

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets an authenticated user attach arbitrary file_id values to their own chat message without checking whether they own or can read those files. If the attacker then shares that chat and grants themselves read access, has_access_to_file() treats the victim file as accessible through the shared chat, and the file endpoints read or delete the victim file. CVSSv3.1 8.3 (HIGH)

CWECWE 862CWECWE 639CWECWE 284TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-23
2026-06-23 18:18Z
HIGH

CVE-2026-54008 — Open: Prior to 0.9.6, backend/open_webui/utils/oauth.py::_process_picture_url calls validate_url(picture_url) on the initial URL only, then invokes aiohttp.ClientSession.get(picture_u

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54008

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, backend/open_webui/utils/oauth.py::_process_picture_url calls validate_url(picture_url) on the initial URL only, then invokes aiohttp.ClientSession.get(picture_url, ...) without allow_redirects=False. aiohttp's default is allow_redirects=True, max_redirects=10; the function does not pass the project's AIOHTTP_CLIENT_ALLOW_REDIRECTS env constant either. An attacke CVSSv3.1 8.5 (HIGH)

CWECWE 918TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-23
2026-06-23 18:18Z
CRIT

CVE-2026-53662 — From commit 4ffa26c9 until 4eb1003, a reflected cross-site scripting (XSS) vulnerability on the /auth/login

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53662

immich is a high performance self-hosted photo and video management solution. From commit 4ffa26c9 until 4eb1003, a reflected cross-site scripting (XSS) vulnerability on the /auth/login page allows an attacker to fully compromise any authenticated user's account with a single link click. The continue query parameter is read from the URL and passed to SvelteKit's redirect() without any scheme or origin validation, allowing attacker-controlled JavaScript to execute inside Immic CVSSv3.1 9.6 (CRITICAL)

CWECWE 79CWECWE 601TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-23
2026-06-23 18:18Z
HIGH

CVE-2026-52845 — Caddy: Prior to 2.11.4, forward_auth copy_headers deletes the exact client-supplied identity header before copying the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52845

Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, forward_auth copy_headers deletes the exact client-supplied identity header before copying the trusted value from the auth gateway. But when the request later goes through php_fastcgi, Caddy normalizes HTTP headers into CGI variables by replacing - with _. This lets a client send an underscore alias that survives the forward_auth delete step but becomes the same PHP/FastCGI variable. Result: a r CVSSv3.1 8.1 (HIGH)

CWECWE 287CWECWE 290CWECWE 444VNDCaddyTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-23
2026-06-23 18:18Z
HIGH

CVE-2026-49402 — Deno: Prior to 2.7.10, Deno's node:child_process implementation provided an escapeShellArg() helper used when callers passed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49402

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.10, Deno's node:child_process implementation provided an escapeShellArg() helper used when callers passed shell: true to spawn / spawnSync / exec and friends. On Windows, the helper failed to quote arguments that contained cmd.exe metacharacters and did not neutralize % (which cmd.exe expands even inside double-quoted strings). An attacker who controlled any portion of an argument passed to such a call co CVSSv3.1 8.1 (HIGH)

CWECWE 78VNDDenoTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-23
2026-06-23 18:17Z
HIGH

CVE-2026-45135 — Caddy: In any deployment where the attacker can place content into a file served via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45135

Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitPos() in modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go misuses golang.org/x/text/search with search.IgnoreCase when the request path contains a non-ASCII byte. Two distinct flaws in that fallback let an attacker mislead Caddy's FastCGI splitting into treating a non-.php (or other configured split_path extension) file as a script. In any deployment where t CVSSv3.1 8.1 (HIGH)

CWECWE 20CWECWE 178CWECWE 176VNDCaddyTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-23
2026-06-23 17:17Z
HIGH

CVE-2026-56115 — Bootimus: through 0.1.70 contains a broken access control vulnerability that allows authenticated low-privileged users

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56115

Bootimus through 0.1.70 contains a broken access control vulnerability that allows authenticated low-privileged users to perform administrative actions by exploiting missing role enforcement in the JWTMiddleware function in internal/auth/auth.go, which validates JWT tokens and account status but fails to inspect the is_admin flag. Attackers can send requests to any endpoint under the /api/users path to create new administrator accounts or reset administrator passwords, thereb CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDBootimusTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-23
2026-06-23 17:17Z
CRIT

CVE-2026-55450 — Langflow: This can lead to space exhaustion on the server.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55450

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to the server without any limitations. No need for any prior knowledge, only network access to Langflow. This can lead to space exhaustion on the server. In addition, in the response, the absolute path of the uploaded file is reported to the attacker, which is an information leak that can assist in chaining other primitives. This v CVSSv3.1 9.3 (CRITICAL)

CWECWE 306CWECWE 200CWECWE 400VNDLangflowTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-23
2026-06-23 17:17Z
CRIT

CVE-2026-55447 — Langflow: All components based on BaseFileComponent are vulnerable to the vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55447

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files that are digested into the RAG, an attacker can direct the node to read any file on the file-system by absolute path. All components based on BaseFileComponent are vulnerable to the vulnerability. This includes Docling (DoclingInlineComponent), Docling Serve, DoclingRemoteComponent), Read File (FileComponent), NVIDIA Retriever Extraction (NvidiaIngestComponent CVSSv3.1 9.6 (CRITICAL)

CWECWE 200CWECWE 61VNDLangflowTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-23
2026-06-23 17:17Z
CRIT

CVE-2026-55255 — Langflow: Prior to 1.9.2, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55255

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability is fixed in 1.9.2. CVSSv3.1 9.9 (CRITICAL)

CWECWE 639VNDLangflowTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-23
2026-06-23 17:17Z
CRIT

CVE-2026-54307 — N8n N8n: is an open source workflow automation platform.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54307

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, a member-level user with editor access to a shared workflow could reference credentials they do not own via specific public API endpoints. Credential ownership checks were only enforced partially leading to cross-user credential access. This issue affects instances where workflow sharing is enabled and at least one workflow has been shared with a member-level user as an Editor. This vul CVSSv3.1 9.6 (CRITICAL)

CWECWE 863VNDN8nTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-23
2026-06-23 17:17Z
CRIT

CVE-2026-54305 — N8n N8n: is an open source workflow automation platform.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54305

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, three EE endpoints used by the Dynamic Credentials feature accepted any authenticated n8n session without performing per-resource ownership or scope checks on the target workflow or credential. An authenticated user with no project membership or credential sharing relationship could enumerate credential identifiers, names, and types referenced by any private workflow in the instance, in CVSSv3.1 9.9 (CRITICAL)

CWECWE 284CWECWE 200VNDN8nTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-23
2026-06-23 17:17Z
HIGH

CVE-2026-50574 — Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50574

yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windows platforms, this can lead to immediate arbitrary code execution. On non-Windows platforms, this can lead to arbitrary code execution upon the next invocation of yt-dlp. This vuln CVSSv3.1 8.3 (HIGH)

CWECWE 74TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-23
2026-06-23 17:17Z
HIGH

CVE-2026-50023 — Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a remote attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50023

yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a remote attacker to write arbitrary OS-shortcut files (such as .desktop, .url, .webloc) to the user's filesystem, bypassing the remediation for CVE-2024-38519. The allowlist explicitly included the unsafe extensions .desktop, .url, and .webloc so that the functionality of the --write-link option (and its variants) could be preserved. These allowlist inclusions c CVSSv3.1 8.3 (HIGH)

CWECWE 641TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-23
2026-06-23 17:17Z
HIGH

CVE-2026-49444 — N8n N8n: Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with permission to create or

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49444

n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with permission to create or modify workflows containing a Python Code Node could escape the sandbox and achieve arbitrary code execution on the task runner container. This vulnerability is fixed in 1.123.48, 2.21.8, and 2.22.4. CVSSv3.1 8.5 (HIGH)

CWECWE 20VNDN8nTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-23
2026-06-23 17:17Z
CRIT

CVE-2026-48519 — Langflow: Prior to 1.9.2, the "Shareable Playground" (or "Public Flows" in code) contains a critical

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48519

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the "Shareable Playground" (or "Public Flows" in code) contains a critical RCE vulnerability. Shareable Playground feature works by enabling the execution of workflows by unauthenticated users, by accessing a link. Specifically, it enables the route /api/v1/build_public_tmp to execute any public flow, given a public flow ID. When the route executes the flow, it allows for providing CVSSv3.1 9.6 (CRITICAL)

CWECWE 94VNDLangflowTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-23
2026-06-23 17:17Z
HIGH

CVE-2026-45732 — N8n N8n: is an open source workflow automation platform.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45732

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, the OAuth1 and OAuth2 credential reconnect endpoints authorized access using credential:read rather than credential:update. An authenticated user with read-only access to a shared credential could initiate an OAuth reconnect flow and overwrite the stored token material for that credential with tokens bound to an external account they control. Workflows relying on the affected credential CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDN8nTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-23
2026-06-23 17:17Z
HIGH

CVE-2026-44959 — A missing validation of user input exists when saving delivery limitations in Revive Adserver

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44959

A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑privileged user could add an unexpected component parameter and inject malicious PHP code into the compiledlimitations field, which would then be executed during banner delivery. Input sanitisation has been improved to ensure that unexpected parameters are filtered out. CVSSv3.1 8.8 (HIGH)

CWECWE 94TYPVulnerability
8.8
CVSS v3.1
94
Edit Score