CWE-863
CVEs classified under CWE-863, newest first.
876 CVEsRSS
GHSA-gcq3-mfvh-3x25High· 7.3PraisonAI Code agent tools fail open without a workspace boundary
PraisonAI Code agent tools fail open without a workspace boundary
GHSA-4qq2-2j2x-x62cHigh· 8.2npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation
npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation
GHSA-vjv9-7m7j-h833High· 8.8npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining
npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining
GHSA-h2w2-v7j6-xqm4High· 8.8npm PraisonAI AgentLoop onToolCall approval runs after tool execution
npm PraisonAI AgentLoop onToolCall approval runs after tool execution
GHSA-5jv7-2mjm-h6qjHigh· 8.8npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining
npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining
GHSA-7qw2-w5rc-37x2High· 7.8PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml
PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml
CVE-2026-53855High· 8.1OpenClaw: Shell positional parameters could weaken strict inline-eval checks
OpenClaw: Shell positional parameters could weaken strict inline-eval checks
CVE-2026-53860Low· 4.2OpenClaw: BlueBubbles sender policy could match mutable conversation identifiers
OpenClaw: BlueBubbles sender policy could match mutable conversation identifiers
CVE-2026-53853High· 7.1OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns
OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns
CVE-2026-53854MediumOpenClaw: Internal/webchat command auth could inherit ownerAllowFrom wildcard state
OpenClaw: Internal/webchat command auth could inherit ownerAllowFrom wildcard state
GHSA-664h-gpgq-h6xxMedium· 5.4n8n: Wrong OAuth Scope on Evaluation Test Runs Endpoints
n8n: Wrong OAuth Scope on Evaluation Test Runs Endpoints
CVE-2026-54761High· 7.1PoCTraefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services
Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services
CVE-2026-54021Medium· 6.3Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter
Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter
CVE-2026-54022Medium· 5.3Open WebUI: Any authenticated user can read other users' private notes via Socket.IO
Open WebUI: Any authenticated user can read other users' private notes via Socket.IO
CVE-2026-54324Medium· 6.5Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join
Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join
CVE-2026-22555High· 8.1Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration
Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration
CVE-2026-24791High· 8.1Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
CVE-2026-32966Critical· 9.8Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure
Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure
CVE-2026-32967Critical· 9.1Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks
Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks
CVE-2026-41280Medium· 4.9Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
CVE-2026-42357Medium· 6.5Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.
Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.
CVE-2026-55518Critical· 9.6Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation
Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation
CVE-2026-53721HighNuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher
Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher
CVE-2026-54321High· 7.0Daytona: Public sandbox previews remain accessible for up to one hour after being made private
Daytona: Public sandbox previews remain accessible for up to one hour after being made private
GHSA-r2fx-hp6p-pgrmMedium· 6.5Duplicate Advisory: Internal/webchat command auth could inherit ownerAllowFrom wildcard state
Duplicate Advisory: Internal/webchat command auth could inherit ownerAllowFrom wildcard state
GHSA-h3jj-5f3v-3685Medium· 6.4n8n: Public API Execution Retry Authorization Bypass
n8n: Public API Execution Retry Authorization Bypass
CVE-2026-54307High· 9.6n8n: Credential Exfiltration via Permission Bypass
n8n: Credential Exfiltration via Permission Bypass
CVE-2026-28744High· 8.1Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens
Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens
CVE-2026-28699High· 8.1PoCGitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication
Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication
CVE-2026-26231High· 8.5Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo
Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo