Daily digest
Sunday 12 April 2026
A quiet day: only 5 new CVEs against a recent average of about 59. Of those, 2 high. One arrived with exploitation evidence or public exploit code already attached. metagpt was the most-affected vendor with 3.
New this day, ranked by depth score
The 5 that matter most of the 5 published.
CVE-2026-6111Medium· 6.3PoCMetaGPT affected by server-side request forgery in metagpt/utils/common.py
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
CVE-2026-40393High· 8.1In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.
In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.
CVE-2026-6110High· 7.3MetaGPT has an eval injection in metagpt/strategy/tot.py
MetaGPT has an eval injection in metagpt/strategy/tot.py
CVE-2026-1116Medium· 6.1A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms pr…
A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms prior to version 2.2.0. The vulnerability arises from the lack of sanitization or HTML encoding of the…
CVE-2026-6109Medium· 4.3MetaGPT has an eval injection via a cross-site request forgery attack
MetaGPT has an eval injection via a cross-site request forgery attack
Most-affected vendors
By CVEs published in the period.