CWE-183
CVEs classified under CWE-183, newest first.
14 CVEsRSS
CVE-2026-90808Medium· 6.3PoCA vulnerability was determined in HKUDS nanobot up to 0.2.1
A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. This manipulation causes incomplete blackli…
CVE-2026-54694Critical· 9.6PoCSkillTree is a micro-learning gamification platform
SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a single exploitable attack chain, with three distinct exploitation paths of escalating impact. `StringHighlighter.js` b…
CVE-2026-55581High· 8.4mcp-shell is an MCP server for running shell commands securely, auditably, and on demand
mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default Docker security.yaml includes /bin/bash in allowed_executables, while security.go validates only the first token and ch…
CVE-2026-67315Noneaxios versions 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules
axios versions 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured pr…
CVE-2026-66005Medium· 6.3PoCJan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attackers to bypass trusted host restrictions by exploiting the server's replacement of user-…
Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attackers to bypass trusted host restrictions by exploiting the server's replacement of user-…
GHSA-f4gw-2p7v-4548MediumAxios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
CVE-2026-16129Medium· 5.3A vulnerability has been found in princezuda SafestClaw up to 4.2.4
A vulnerability has been found in princezuda SafestClaw up to 4.2.4. This vulnerability affects the function ShellAction._validate_command of the file src/safestclaw/actions/shell.py of the component Built-in Web Interface. Such manipula…
CVE-2026-8918High· 7.1A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or cause a system crash (BSOD) by bypassing the validation mechanism.Refer to the ' Security Update …
A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or cause a system crash (BSOD) by bypassing the validation mechanism.Refer to the ' Security Update …
CVE-2026-46608High· 7.4Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)
Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)
CVE-2026-11525Low· 3.7undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
CVE-2026-54316MediumPoCClaude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
GHSA-82fg-2r99-h7v6Critical· 10.0Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass
Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass
CVE-2026-42043High· 7.2PoCAxios is a promise based HTTP client for the browser and Node.js
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to complet…
CVE-2026-21915Medium· 6.7A Permissive List of Allowed Input vulnerability in the CLI of Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows a local, high privileged attacker to escalate their privileges to root. The CLI menu acce…
A Permissive List of Allowed Input vulnerability in the CLI of Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows a local, high privileged attacker to escalate their privileges to root. The CLI menu acce…