VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5683 CVEsRSS

CVE-2026-56837High· 8.6
3mo ago

PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing

PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing

▾ Twilightpraisonai · praisonaivia OSV
CVE-2026-57113High· 8.1
3mo ago

PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion

PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion

▾ Twilightpraisonai · praisonaivia OSV
CVE-2026-57116Critical· 9.8
3mo ago

PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation

PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation

▾ Midnightpraisonai · praisonaivia OSV
CVE-2026-56832High· 8.8
3mo ago

PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals

PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals

▾ Twilightpraisonai · praisonaivia OSV
CVE-2026-57142High· 7.8
3mo ago

PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml

PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml

▾ Twilightpraisonai · praisonaivia OSV
CVE-2026-57144High· 8.8
3mo ago

PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable

PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable

▾ Twilightpraisonai · praisonaivia OSV
CVE-2026-56840High· 8.8
3mo ago

PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools

PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools

▾ Twilightpraisonai · praisonaivia OSV
CVE-2026-56836High· 8.2
3mo ago

PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard

PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard

▾ Twilightpraisonai · praisonaivia OSV
CVE-2026-57143High· 8.8
3mo ago

PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter

PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter

▾ Twilightpraisonaiagents · praisonaiagentsvia OSV
CVE-2026-56833High· 7.5
3mo ago

PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal

PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal

▾ Twilightpraisonai · praisonaivia OSV
CVE-2026-56664Medium· 4.2
3mo ago

ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider

ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider

▾ Sunlitzitadel · github.com/zitadel/zitadelEPSS 0.32%via OSV
CVE-2026-57573High· 8.6
3mo ago

Crawl4AI: Unauthenticated SSRF on the Docker server streaming crawl path (/crawl/stream)

Crawl4AI: Unauthenticated SSRF on the Docker server streaming crawl path (/crawl/stream)

▾ Twilightcrawl4ai · crawl4aiEPSS 0.45%via OSV
CVE-2026-57572Critical· 10.0
3mo ago

Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args

Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args

▾ Midnightcrawl4ai · crawl4aiEPSS 0.94%via OSV
CVE-2026-57204Medium
3mo ago

pypdf: Missing stream length values ignore defined limits

pypdf: Missing stream length values ignore defined limits

▾ Sunlitpypdf · pypdfEPSS 0.37%via OSV
CVE-2026-57571Critical· 9.6
3mo ago

Crawl4AI: Arbitrary file write (path traversal) in crawler downloads can lead to RCE

Crawl4AI: Arbitrary file write (path traversal) in crawler downloads can lead to RCE

▾ Midnightcrawl4ai · crawl4aiEPSS 0.81%via OSV
CVE-2026-58653Medium· 4.3
3mo ago

praisonai-platform: Authorization Bypass Through User-Controlled Key

praisonai-platform: Authorization Bypass Through User-Controlled Key

▾ Sunlitpraisonai-platform · praisonai-platformEPSS 0.26%via OSV
CVE-2026-44727Medium· 5.4
3mo ago

Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP

Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP

▾ Sunlitjupyter-server · jupyter-serverEPSS 0.44%via OSV
MAL-2026-6051None
3mo ago

Malicious code in telegram-lite-grabber (PyPI)

Malicious code in telegram-lite-grabber (PyPI)

▾ Sunlittelegram-lite-grabber · telegram-lite-grabbervia OSV
MAL-2026-6080None
3mo ago

Malicious code in boardflow (PyPI)

Malicious code in boardflow (PyPI)

▾ Sunlitboardflow · boardflowvia OSV
CVE-2026-54761High· 7.1PoC
3mo ago

Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services

Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services

▾ Midnighttraefik · github.com/traefik/traefik/v3EPSS 0.37%via OSV
CVE-2026-54235Medium· 6.5
3mo ago

vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels

vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels

▾ Sunlitvllm · vllmEPSS 0.45%via OSV
CVE-2026-12491Medium· 4.8
3mo ago

vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations

vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations

▾ Sunlitvllm · vllmEPSS 0.24%via OSV
CVE-2026-53923High· 7.5
3mo ago

vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving

vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving

▾ Twilightvllm · vllmEPSS 0.48%via OSV
CVE-2026-54236Medium· 5.3PoC
3mo ago

vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router

vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router

▾ Twilightvllm · vllmEPSS 0.93%via OSV
CVE-2026-54233Medium· 6.5
3mo ago

vLLM: OOM Denial of Service via Audio Decompression Bomb

vLLM: OOM Denial of Service via Audio Decompression Bomb

▾ Sunlitvllm · vllmEPSS 0.42%via OSV
CVE-2026-50203Critical· 9.1
3mo ago

Apache Airflow SFTP provider: Path traversal in SFTPHook.retrieve_directory

Apache Airflow SFTP provider: Path traversal in SFTPHook.retrieve_directory

▾ Midnightapache-airflow-providers-sftp · apache-airflow-providers-sftpEPSS 0.88%via OSV
CVE-2026-55748Medium· 6.0
3mo ago

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types…

▾ Sunlitopenstack · horizonEPSS 0.46%via NVD
CVE-2026-56258High· 8.1
3mo ago

Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server

Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server

▾ Twilightcrawl4ai · crawl4aiEPSS 0.91%via OSV
CVE-2026-56261Critical· 9.8
3mo ago

Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution

Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution

▾ Midnightcrawl4ai · crawl4aiEPSS 0.51%via OSV
MAL-2026-5878None
3mo ago

Malicious code in cache-compat-utils (PyPI)

Malicious code in cache-compat-utils (PyPI)

▾ Sunlitcache-compat-utils · cache-compat-utilsvia OSV
CVEs tagged “osv” — page 49 · VulnSea