VulnSea

CWE-863

CVEs classified under CWE-863, newest first.

876 CVEsRSS

GHSA-gcq3-mfvh-3x25High· 7.3
3mo ago

PraisonAI Code agent tools fail open without a workspace boundary

PraisonAI Code agent tools fail open without a workspace boundary

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-4qq2-2j2x-x62cHigh· 8.2
3mo ago

npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation

npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-vjv9-7m7j-h833High· 8.8
3mo ago

npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining

npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-h2w2-v7j6-xqm4High· 8.8
3mo ago

npm PraisonAI AgentLoop onToolCall approval runs after tool execution

npm PraisonAI AgentLoop onToolCall approval runs after tool execution

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-5jv7-2mjm-h6qjHigh· 8.8
3mo ago

npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining

npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-7qw2-w5rc-37x2High· 7.8
3mo ago

PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml

PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml

▾ Twilightpraisonai · praisonaivia GHSA
CVE-2026-53855High· 8.1
3mo ago

OpenClaw: Shell positional parameters could weaken strict inline-eval checks

OpenClaw: Shell positional parameters could weaken strict inline-eval checks

▾ Twilightopenclaw · openclawEPSS 0.45%via GHSA
CVE-2026-53860Low· 4.2
3mo ago

OpenClaw: BlueBubbles sender policy could match mutable conversation identifiers

OpenClaw: BlueBubbles sender policy could match mutable conversation identifiers

▾ Sunlitopenclaw · openclawEPSS 0.23%via GHSA
CVE-2026-53853High· 7.1
3mo ago

OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns

OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns

▾ Twilightopenclaw · openclawEPSS 0.60%via GHSA
CVE-2026-53854Medium
3mo ago

OpenClaw: Internal/webchat command auth could inherit ownerAllowFrom wildcard state

OpenClaw: Internal/webchat command auth could inherit ownerAllowFrom wildcard state

▾ Sunlitopenclaw · openclawEPSS 0.41%via GHSA
GHSA-664h-gpgq-h6xxMedium· 5.4
3mo ago

n8n: Wrong OAuth Scope on Evaluation Test Runs Endpoints

n8n: Wrong OAuth Scope on Evaluation Test Runs Endpoints

▾ Sunlitn8n · n8nvia GHSA
CVE-2026-54761High· 7.1PoC
3mo ago

Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services

Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services

▾ Midnighttraefik · github.com/traefik/traefik/v3EPSS 0.37%via OSV
CVE-2026-54021Medium· 6.3
3mo ago

Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter

Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter

▾ Sunlitopen-webui · open-webuiEPSS 0.28%via GHSA
CVE-2026-54022Medium· 5.3
3mo ago

Open WebUI: Any authenticated user can read other users' private notes via Socket.IO

Open WebUI: Any authenticated user can read other users' private notes via Socket.IO

▾ Sunlitopen-webui · open-webuiEPSS 0.35%via GHSA
CVE-2026-54324Medium· 6.5
3mo ago

Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join

Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join

▾ Sunlitdaytonaio · github.com/daytonaio/daytonaEPSS 0.46%via GHSA
CVE-2026-22555High· 8.1
3mo ago

Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration

Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.43%via GHSA
CVE-2026-24791High· 8.1
3mo ago

Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.45%via GHSA
CVE-2026-32966Critical· 9.8
3mo ago

Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure

Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure

▾ Midnightapache · org.apache.dolphinscheduler:dolphinscheduler-apiEPSS 0.66%via GHSA
CVE-2026-32967Critical· 9.1
3mo ago

Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks

Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks

▾ Midnightapache · org.apache.dolphinscheduler:dolphinscheduler-apiEPSS 0.55%via GHSA
CVE-2026-41280Medium· 4.9
3mo ago

Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects

Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects

▾ Sunlitapache · org.apache.dolphinscheduler:dolphinscheduler-apiEPSS 0.54%via GHSA
CVE-2026-42357Medium· 6.5
3mo ago

Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.

Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.

▾ Sunlitapache · org.apache.dolphinscheduler:dolphinscheduler-apiEPSS 0.49%via GHSA
CVE-2026-55518Critical· 9.6
3mo ago

Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation

Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation

▾ Midnightavo · avoEPSS 0.45%via GHSA
CVE-2026-53721High
3mo ago

Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher

Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher

▾ Twilightnuxt · nuxtEPSS 0.51%via GHSA
CVE-2026-54321High· 7.0
3mo ago

Daytona: Public sandbox previews remain accessible for up to one hour after being made private

Daytona: Public sandbox previews remain accessible for up to one hour after being made private

▾ Twilightdaytonaio · github.com/daytonaio/daytonaEPSS 0.40%via GHSA
GHSA-r2fx-hp6p-pgrmMedium· 6.5
3mo ago

Duplicate Advisory: Internal/webchat command auth could inherit ownerAllowFrom wildcard state

Duplicate Advisory: Internal/webchat command auth could inherit ownerAllowFrom wildcard state

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-h3jj-5f3v-3685Medium· 6.4
3mo ago

n8n: Public API Execution Retry Authorization Bypass

n8n: Public API Execution Retry Authorization Bypass

▾ Sunlitn8n · n8nvia GHSA
CVE-2026-54307High· 9.6
3mo ago

n8n: Credential Exfiltration via Permission Bypass

n8n: Credential Exfiltration via Permission Bypass

▾ Twilightn8n · n8nEPSS 0.39%via GHSA
CVE-2026-28744High· 8.1
3mo ago

Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens

Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.45%via GHSA
CVE-2026-28699High· 8.1PoC
3mo ago

Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication

Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication

▾ Midnightgitea · code.gitea.io/giteaEPSS 0.55%via GHSA
CVE-2026-26231High· 8.5
3mo ago

Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo

Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.35%via GHSA
CWE-863 vulnerabilities (CVEs) — page 26 · VulnSea