VulnSea

CWE-693

CVEs classified under CWE-693, newest first.

276 CVEsRSS

CVE-2026-50545Critical· 9.9
2mo ago

Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover

Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover

▾ Midnightfission · github.com/fission/fissionEPSS 0.52%via GHSA
CVE-2026-50564Critical· 9.9
2mo ago

Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape

Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape

▾ Midnightfission · github.com/fission/fissionEPSS 0.51%via GHSA
CVE-2026-48805Low
2mo ago

Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`

Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`

▾ Sunlittwig · twig/twigEPSS 0.48%via GHSA
CVE-2026-48806Medium
2mo ago

Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys

Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys

▾ Sunlittwig · twig/twigEPSS 0.42%via GHSA
CVE-2026-48807Medium
2mo ago

Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters

Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters

▾ Sunlittwig · twig/twigEPSS 0.37%via GHSA
CVE-2026-48808Medium
2mo ago

Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`

Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`

▾ Sunlittwig · twig/twigEPSS 0.41%via GHSA
CVE-2026-13601High· 7.1
3mo ago

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted C…

▾ Twilightgnome · yelpEPSS 0.18%via NVD
CVE-2026-58052Low· 3.3
3mo ago

7-Zip for Windows through 26.01 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because its guard that suppresses an archive-supplied Zone.Identifier stream matches the exact name 'Zone.Identifier' while a R…

7-Zip for Windows through 26.01 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because its guard that suppresses an archive-supplied Zone.Identifier stream matches the exact name 'Zone.Identifier' while a R…

▾ Sunlit7-zip · 7-zipEPSS 0.17%via NVD
GHSA-72w7-mf9g-733pMedium· 6.4
3mo ago

nono-py has proxy-only network fallback bypass on older Linux kernels

nono-py has proxy-only network fallback bypass on older Linux kernels

▾ Sunlitnono-py · nono-pyvia GHSA
CVE-2026-55487High· 7.5
3mo ago

pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle

pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle

▾ Twilightpnpm · pnpmEPSS 0.18%via GHSA
CVE-2026-57280High· 8.8
3mo ago

Jenkins Script Security Plugin sandbox bypass vulnerability

Jenkins Script Security Plugin sandbox bypass vulnerability

▾ Twilightjenkins-ci · org.jenkins-ci.plugins:script-securityEPSS 0.51%via GHSA
CVE-2026-54762High· 8.6
3mo ago

Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails

Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails

▾ Twilighttraefik · github.com/traefik/traefik/v3EPSS 0.43%via OSV
GHSA-v847-hxxw-3pxgHigh· 7.8
3mo ago

PraisonAI recipe.run_stream skips dangerous-tool policy enforcement

PraisonAI recipe.run_stream skips dangerous-tool policy enforcement

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-pv2j-rghr-v5r9Medium· 6.5
3mo ago

PraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunder

PraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunder

▾ Sunlitpraisonaiagents · praisonaiagentsvia GHSA
GHSA-vmmj-pfw7-fjwpCritical· 9.9
3mo ago

npm PraisonAI codeMode sandbox escape via Function constructor

npm PraisonAI codeMode sandbox escape via Function constructor

▾ Midnightpraisonai · praisonaivia GHSA
GHSA-gqmf-56h7-rrpfHigh· 7.6
3mo ago

npm PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients

npm PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-vjv9-7m7j-h833High· 8.8
3mo ago

npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining

npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-h2w2-v7j6-xqm4High· 8.8
3mo ago

npm PraisonAI AgentLoop onToolCall approval runs after tool execution

npm PraisonAI AgentLoop onToolCall approval runs after tool execution

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-5jv7-2mjm-h6qjHigh· 8.8
3mo ago

npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining

npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-6jcq-6546-qrrwHigh· 8.8
3mo ago

PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable

PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable

▾ Twilightpraisonai · praisonaivia GHSA
CVE-2026-53845Low· 4.3
3mo ago

OpenClaw: Skill-command dispatch could skip before-tool-call hooks

OpenClaw: Skill-command dispatch could skip before-tool-call hooks

▾ Sunlitopenclaw · openclawEPSS 0.31%via GHSA
CVE-2026-53853High· 7.1
3mo ago

OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns

OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns

▾ Twilightopenclaw · openclawEPSS 0.60%via GHSA
CVE-2026-54013High· 7.6
3mo ago

Open WebUI: Stored XSS to Account Takeover via Model Profile Images

Open WebUI: Stored XSS to Account Takeover via Model Profile Images

▾ Twilightopen-webui · open-webuiEPSS 0.30%via GHSA
GHSA-5gp7-4733-2w2vHigh· 8.8
3mo ago

Duplicate Advisory: Picklescan Bypasses Unsafe Globals Check using pty.spawn

Duplicate Advisory: Picklescan Bypasses Unsafe Globals Check using pty.spawn

▾ Twilightpicklescan · picklescanvia GHSA
CVE-2026-12296Critical· 9.6
3mo ago

Sandbox escape in the Security: Process Sandboxing component

Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

▾ Midnightmozilla · firefoxEPSS 0.39%via NVD
CVE-2026-12295Critical· 9.6PoC
3mo ago

Sandbox escape in the DOM: Navigation component

Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

▾ Abyssalmozilla · firefoxEPSS 0.39%via NVD
CVE-2026-12294Critical· 9.6
3mo ago

Sandbox escape in the DOM: Workers component

Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

▾ Midnightmozilla · firefoxEPSS 0.36%via NVD
CVE-2026-49859Medium· 5.2
3mo ago

Deno: `fetch()` API sandbox bypass via missing DNS resolution check

Deno: `fetch()` API sandbox bypass via missing DNS resolution check

▾ Sunlitdeno · denoEPSS 0.14%via GHSA
GHSA-r7vv-6763-m739Low· 4.3
3mo ago

Duplicate Advisory: Skill-command dispatch could skip before-tool-call hooks

Duplicate Advisory: Skill-command dispatch could skip before-tool-call hooks

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-3v3j-737j-7g74High· 8.3
3mo ago

Duplicate Advisory: Linux and macOS exec allowlists skipped configured argument patterns

Duplicate Advisory: Linux and macOS exec allowlists skipped configured argument patterns

▾ Twilightopenclaw · openclawvia GHSA
CWE-693 vulnerabilities (CVEs) — page 7 · VulnSea