CWE-200
CVEs classified under CWE-200, newest first.
824 CVEsRSS
CVE-2026-49988Mediumrepomix: attach_packed_output can bypass file-read secret scanning for supported local files
repomix: attach_packed_output can bypass file-read secret scanning for supported local files
GHSA-7m8x-qg2j-4m3vHigh· 8.1Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec
Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec
CVE-2026-49355Medium· 4.3OpenProject is open-source, web-based project management software
OpenProject is open-source, web-based project management software. Prior to 17.4.0, `GET /api/v3/meetings/:meeting_id/agenda_items/:agenda_item_id` discloses private work package data from a linked work package that belongs to a private/…
GHSA-q683-8468-r6h6MediumWebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs
WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs
CVE-2026-49288Medium· 4.3Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources
Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources
CVE-2026-49336Medium@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter
@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter
CVE-2026-50017Mediumpnpm binds unscoped user-level npm auth credentials to a repository-selected registry
pnpm binds unscoped user-level npm auth credentials to a repository-selected registry
CVE-2026-55180Medium· 6.5pnpm: Repository config can expand victim environment secrets into registry requests before scripts run
pnpm: Repository config can expand victim environment secrets into registry requests before scripts run
GHSA-ww5p-j6cj-6mqqMediumNezha Dashboard: DDNS and Notification credential exposure via unredacted list API
Nezha Dashboard: DDNS and Notification credential exposure via unredacted list API
CVE-2026-44025High· 7.5Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
CVE-2026-46406Medium@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write
@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write
CVE-2026-49219Medium· 5.5ImageMagick: Policy Bypass can read disallowed files via symlink
ImageMagick: Policy Bypass can read disallowed files via symlink
CVE-2026-12537High· 7.8⚖ disputedImproper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker …
Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker …
CVE-2026-52815MediumPoCGogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API
CVE-2026-54276Medium· 6.1AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This likely requires an open redirect vuln…
CVE-2026-55882HighTilt: Unauthenticated pprof debug endpoints on the Tilt HUD server
Tilt: Unauthenticated pprof debug endpoints on the Tilt HUD server
CVE-2026-49211Mediumsymfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
CVE-2026-53725Mediumparse-server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is denied
parse-server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is denied
CVE-2026-54317High· 7.6Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN
Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN
CVE-2026-11769MediumGrafana Operator: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName
Grafana Operator: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName
GHSA-pr33-38xx-6r26Mediumhttp4k: BasicCookieStorage` (renamed `InsecureCookieStorage`) did not enforce RFC 6265 cookie scoping; new `DefaultCookieStorage` is now the default
http4k: BasicCookieStorage` (renamed `InsecureCookieStorage`) did not enforce RFC 6265 cookie scoping; new `DefaultCookieStorage` is now the default
CVE-2026-55447Critical· 9.6Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
GHSA-97pr-9hgg-3p8rLowparse-server: LiveQuery discloses object data to a subscriber across an ACL read-access change
parse-server: LiveQuery discloses object data to a subscriber across an ACL read-access change
GHSA-h4h3-3rfj-x6fqMedium· 4.3SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
CVE-2026-47633High· 7.5Microsoft Cost Management Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network.
GHSA-22cj-m4wf-fv2cHigh· 7.5PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal
PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal
GHSA-j7qx-p75m-wp7gHigh· 7.5PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage
PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage
GHSA-892r-p3jq-jp24Critical· 9.8PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation
PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation
GHSA-gcq3-mfvh-3x25High· 7.3PraisonAI Code agent tools fail open without a workspace boundary
PraisonAI Code agent tools fail open without a workspace boundary
GHSA-jxcw-qp4h-6jfqHigh· 7.5PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default
PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default