{"id":"CVE-2026-26057","aliases":["GHSA-ppfx-73j5-fhxc","PYSEC-2026-2415"],"title":"Skill-scanner Unsecured Network Binding Vulnerability","summary":"Skill-scanner Unsecured Network Binding Vulnerability","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","vendor":"cisco-ai-skill-scanner","product":"cisco-ai-skill-scanner","ecosystem":"pip","affected":["cisco-ai-skill-scanner < 1.0.2"],"patched":["cisco-ai-skill-scanner 1.0.2"],"published":"2026-02-17","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-ppfx-73j5-fhxc","references":[{"url":"https://github.com/cisco-ai-defense/skill-scanner/security/advisories/GHSA-ppfx-73j5-fhxc"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26057"},{"url":"https://github.com/cisco-ai-defense/skill-scanner/commit/1e35e57f3051ecc89ba845ae7206321c8eac20a1"},{"url":"https://github.com/cisco-ai-defense/skill-scanner"}],"tags":["osv","pip"],"epss":0.00341,"epssPercentile":0.27684,"ingestedAt":"2026-07-13T18:58:01.602Z","slug":"CVE-2026-26057","body":"## Overview\n\n**Description:**\nA vulnerability in the API Server of Skill Scanner could allow a unauthenticated, remote attacker to interact with the server API and either trigger a denial of service (DoS) condition or upload arbitrary files.\n\nThis vulnerability is due to an erroneous binding to multiple interfaces. An attacker could exploit this vulnerability by sending API requests to a device exposing the affected API Server. A successful exploit could allow the attacker to consume an excessive amount of resources (memory starvation) or to upload files to arbitrary folders on the affected device.\n\n**Conditions:**\nThis vulnerability affects Skill-scanner 1.0.1 and earlier releases when the API Server is enabled. The API Server is not enabled by default.\n\n**Fixed Software:**\nSkill-scanner software releases 1.0.2 and later contained the fix for this vulnerability.\n\n**For more information:**\nIf you have any questions or comments about this advisory:\n- [Open an issue in cisco-ai-defense/skill-scanner](https://github.com/cisco-ai-defense/skill-scanner/issues)\n- Email Cisco Open Source Security ([oss-security@cisco.com](mailto:oss-security@cisco.com)) and Cisco PSIRT ([psirt@cisco.com](mailto:psirt@cisco.com))\n\n**Credits:**\n\n- Research: Richard Tweed (@RichardoC)\n- Fix ideation and implementation: Richard Tweed (@RichardoC)\n- Release engineering: Vineeth Sai Narajala (@vineethsai7)\n\n## Affected packages\n\n- `cisco-ai-skill-scanner < 1.0.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `cisco-ai-skill-scanner 1.0.2`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}