VulnSea

CWE-184

CVEs classified under CWE-184, newest first.

73 CVEsRSS

CVE-2026-93598High· 7.1
3d ago

ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny-list in the polyglot script sandbox: com.arcadedb.query.polyglot.HostClassLookupFilter.DENIED lists java.util.ResourceBundle as a bare clas…

ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny-list in the polyglot script sandbox: com.arcadedb.query.polyglot.HostClassLookupFilter.DENIED lists java.util.ResourceBundle as a bare clas…

TwilightArcadeData · arcadedbEPSS 0.48%via NVD
CVE-2026-92952Medium· 6.8PoC
4d ago

vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary

vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary. The extraction filters in lib/setup-sandbox.js and the cross-realm symbol checks and write traps in lib/bridge.js use…

Twilightpatriksimek · vm2EPSS 0.42%via NVD
CVE-2026-61453Medium
5d ago

Grav: XSS Blueprint Validation Bypass via Twig String Concatenation

Grav: XSS Blueprint Validation Bypass via Twig String Concatenation

Sunlitgetgrav · getgrav/gravEPSS 0.16%via GHSA
CVE-2026-63671High· 8.1PoC
5d ago

MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component

MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to 0.22.1, @nuxtjs/mdc uses parseMarkdown with allowDangerousHtml enabled by default and relies on validateProps, validateProp, and…

Midnightnuxt-content · mdcEPSS 0.38%via NVD
CVE-2026-92125High· 8.8
5d ago

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotation, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to run an arbitra…

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotation, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to run an arbitra…

Twilightjenkins · script_securityEPSS 0.51%via NVD
CVE-2026-11918Medium· 5.4
6d ago

IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge could allow an authenticated user to bypass protection mechanisms due to incomplete recursive inspection of nested payload content.

IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge could allow an authenticated user to bypass protection mechanisms due to incomplete recursive inspection of nested payload content.

SunlitIBM · ContextForge MCP GatewayEPSS 0.27%via NVD
CVE-2026-57138Critical· 9.9
6d ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builtins/code-mode.ts executes untrusted JavaScript with new Function() inside with(sandbox) and relies on a small source-code blockl…

MidnightMervinPraison · PraisonAIEPSS 0.39%via NVD
CVE-2026-90808Medium· 6.3PoC
1w ago

A vulnerability was determined in HKUDS nanobot up to 0.2.1

A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. This manipulation causes incomplete blackli…

TwilightHKUDS · nanobotEPSS 0.29%via NVD
CVE-2026-87985Critical· 10.0
1w ago

An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using ANSI-C quoted arguments

An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using ANSI-C quoted arguments. These arguments are not properly inspected, enabling a crafted allowlisted command to execute…

Midnightmistralai · mistral-vibeEPSS 0.44%via NVD
CVE-2026-85788Medium· 5.5
1w ago

Incomplete list of disallowed inputs in the mutable SQL detector component in Amazon awslabs mysql-mcp-server might allow context-dependent actors to bypass the read-only enforcement gate and reach file-read and file-write SQL sinks via …

Incomplete list of disallowed inputs in the mutable SQL detector component in Amazon awslabs mysql-mcp-server might allow context-dependent actors to bypass the read-only enforcement gate and reach file-read and file-write SQL sinks via …

SunlitAWS · AWS Labs MySQL MCP ServerEPSS 0.13%via NVD
CVE-2026-87911Critical· 9.6
1w ago

An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a s…

An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a s…

MidnightAWS · AWS Labs postgres MCP ServerEPSS 0.99%via NVD
CVE-2026-79696Critical· 10.0
1w ago

A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote att…

A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote att…

MidnightGoogle Cloud · Agent Development Kit (ADK) for PythonEPSS 0.44%via NVD
CVE-2026-86199High· 7.5PoC
1w ago

PocketMine-MP versions before 5.43.1 fail to properly validate the Certificate field during offline login authentication

PocketMine-MP versions before 5.43.1 fail to properly validate the Certificate field during offline login authentication. Unauthenticated players can trigger an uninitialized property access error that crashes the server.

Midnightpmmp · PocketMine-MPEPSS 0.32%via NVD
CVE-2026-82536High· 8.8
1w ago

Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability in the shell command parsing logic that allows attackers to execute denied shell commands by exploiting the omission of the bash pipe operator from the command parser'…

Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability in the shell command parsing logic that allows attackers to execute denied shell commands by exploiting the omission of the bash pipe operator from the command parser'…

TwilightRooCodeInc · Roo-CodeEPSS 0.31%via NVD
CVE-2026-70334High· 7.8
1w ago

Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Twilightmicrosoft · visual_studio_codeEPSS 0.43%via NVD
CVE-2026-69624Medium· 6.5
1w ago

Incomplete list of disallowed inputs in Active Directory Certificate Services (AD CS) allows an authorized attacker to perform tampering over a network.

Incomplete list of disallowed inputs in Active Directory Certificate Services (AD CS) allows an authorized attacker to perform tampering over a network.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.71%via NVD
CVE-2026-33197High· 8.7
1w ago

AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the “Incomplete List of Disallowed Inputs” by local access

AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the “Incomplete List of Disallowed Inputs” by local access. Successful exploitation of this vulnerability may lead to arbitrary code execution and impact syste…

TwilightAMI · AptioVEPSS 0.12%via NVD
CVE-2026-85787Medium· 6.5
2w ago

An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify data beyond the read-only scope by placing crafted SQL int…

An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify data beyond the read-only scope by placing crafted SQL int…

SunlitAmazon · postgres-mcp-serverEPSS 0.20%via NVD
CVE-2026-77124None
2w ago

In affected versions of Nexus Repository 3, the script execution endpoint (POST /service/rest/v1/script/{name}/run) did not verify whether script execution had been administratively disabled

In affected versions of Nexus Repository 3, the script execution endpoint (POST /service/rest/v1/script/{name}/run) did not verify whether script execution had been administratively disabled. An account holding script-execution permissio…

SunlitEPSS 0.31%via NVD
CVE-2026-84370High· 8.2
2w ago

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin, named removeScriptElement in versions …

Twilightsvgo · svgoEPSS 0.34%via NVD
CVE-2026-55830High· 8.3
3w ago

RestrictedPython guard hooks can be shadowed via positional-only arguments

RestrictedPython guard hooks can be shadowed via positional-only arguments

Twilightrestrictedpython · restrictedpythonEPSS 0.23%via OSV
CVE-2026-52776High
3w ago

Compliance-trestle (Trestle) is a tooling platform for managing compliance as code

Compliance-trestle (Trestle) is a tooling platform for managing compliance as code. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the URLSecurityValidator that guards trestle's remote-fetch paths against server-side request…

Twilightcompliance-trestle · compliance-trestleEPSS 0.42%via NVD
CVE-2026-62676High· 7.1
1mo ago

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, the shared shell-command parser in omnigent/policies/builtins/_shell.py fails to recognize combined interpreter flags, the ti…

Twilightomnigent · omnigentEPSS 0.29%via NVD
CVE-2026-72860High· 8.5
1mo ago

The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/ssrfGuard.js

The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/ssrfGuard.js. That guard compares host…

TwilightEPSS 0.27%via NVD
CVE-2026-68921Medium· 4.7
1mo ago

DiceBear is an avatar library for designers and developers

DiceBear is an avatar library for designers and developers. Prior to 9.4.3, @dicebear/core interpolates the rotate option into an SVG transform attribute without XML escaping in addRotate in packages/@dicebear/core/src/utils/svg.ts, whil…

Sunlitdicebear · @dicebear/coreEPSS 0.22%via NVD
CVE-2026-49825High· 8.2
1mo ago

lxml is a library for processing XML and HTML in the Python language

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. cont…

TwilightRed Hat · Red Hat OpenStack Platform 16.2EPSS 0.24%via NVD
CVE-2026-45741High· 7.5PoC
1mo ago

Gotenberg is a Docker-powered stateless API for PDF files

Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, the IsPublicIP function in pkg/gotenberg/outbound.go does not reject the 2002::/16 6to4 prefix, the 64:ff9b::/96 and 64:ff9b:1::/48 NAT64 prefixes, the fec…

Midnightgotenberg · gotenbergEPSS 0.76%via NVD
CVE-2026-73650High· 8.2
1mo ago

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named removeScriptElement in versions 1 throu…

TwilightEPSS 0.24%via NVD
CVE-2026-73491Low· 2.3
1mo ago

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: URIs whose scheme is split …

Sunlitflavorjones · loofahEPSS 0.24%via NVD
CVE-2026-73492None
1mo ago

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: or vbscript: URIs whose sch…

SunlitEPSS 0.24%via NVD
CWE-184 vulnerabilities (CVEs) · VulnSea