Tagged “osv”
CVEs tagged osv, newest first.
5683 CVEsRSS
CVE-2026-47393Critical· 9.8PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
CVE-2026-47213Medium· 6.5BoxLite has a Timeout Bypass Vulnerability
BoxLite has a Timeout Bypass Vulnerability
CVE-2026-47409High· 8.1praisonai-platform: Missing authorization on member removal enables full workspace takeover by any user regardless of role
praisonai-platform: Missing authorization on member removal enables full workspace takeover by any user regardless of role
CVE-2026-47184Medium· 6.5zeroconf has unbounded DNS record cache that allows LAN-local memory exhaustion via multicast flood
zeroconf has unbounded DNS record cache that allows LAN-local memory exhaustion via multicast flood
CVE-2026-47183Medium· 6.5zeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustion
zeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustion
CVE-2026-47397HighPraisonAI has an Arbitrary File Write in Python API
PraisonAI has an Arbitrary File Write in Python API
CVE-2026-47405High· 8.8PraisonAI Platform: Missing role checks let any workspace member become owner and control workspace membership
PraisonAI Platform: Missing role checks let any workspace member become owner and control workspace membership
CVE-2026-47180Medium· 6.5zeroconf has unbounded recursion in DNS compression-pointer decoder that allows LAN-local denial of service
zeroconf has unbounded recursion in DNS compression-pointer decoder that allows LAN-local denial of service
CVE-2026-47394HighPraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate
PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate
CVE-2026-47398High· 8.1PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334
PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334
CVE-2026-47399High· 8.8PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object ID
PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object ID
CVE-2026-47414High· 7.6praisonai-platform: Label endpoints' unchecked label_id/issue_id enable cross-workspace label IDOR (edit, delete, link)
praisonai-platform: Label endpoints' unchecked label_id/issue_id enable cross-workspace label IDOR (edit, delete, link)
CVE-2026-47395Medium· 5.5PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context
PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context
CVE-2026-47390Medium· 5.5PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings
PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings
CVE-2026-47406High· 8.1praisonai-platform: IDOR in dependency endpoints allows cross-workspace issue linking, reading, and deletion due to missing ownership checks
praisonai-platform: IDOR in dependency endpoints allows cross-workspace issue linking, reading, and deletion due to missing ownership checks
CVE-2026-47408Medium· 6.5praisonai-platform: list_issue_activity returns activity log for any issue regardless of workspace ownership
praisonai-platform: list_issue_activity returns activity log for any issue regardless of workspace ownership
CVE-2026-49299MediumOpenStack Neutron has an Incorrect Authorization issue
OpenStack Neutron has an Incorrect Authorization issue
CVE-2026-10105High· 8.3agno contains a SQL injection vulnerability
agno contains a SQL injection vulnerability
CVE-2026-10108High· 7.5xiaomusic contains an unauthenticated path traversal vulnerability
xiaomusic contains an unauthenticated path traversal vulnerability
CVE-2026-6720HighCalico Inserts Sensitive Information into Log File
Calico Inserts Sensitive Information into Log File
GHSA-qp9x-wp8f-qgjjMedium· 4.0tuf has platform-dependent delegation path matching
tuf has platform-dependent delegation path matching
CVE-2026-44973High· 8.1github.com/go-git/go-billy: Go-billy: Arbitrary file access due to path traversal vulnerability (CVE-2026-44973)
A flaw was found in go-billy, an interface filesystem abstraction for Go. Multiple path traversal vulnerabilities exist due to insufficient path sanitization and boundary enforcement. A remote attacker could exploit this by crafting malici…
CVE-2026-47179High· 7.7Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives
Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives
CVE-2026-45287Lowopentelemetry-go's Schema ParseFile leaks file descriptors on each parse
opentelemetry-go's Schema ParseFile leaks file descriptors on each parse
CVE-2026-47144Medium· 5.5Shamefile has an arbitrary file read via shamefile.yaml in shame next
Shamefile has an arbitrary file read via shamefile.yaml in shame next
CVE-2026-46526Medium· 5.0local-deep-research has an SSRF bypass in `safe_get`
local-deep-research has an SSRF bypass in `safe_get`
CVE-2026-9094Critical· 9.8Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check
Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check
CVE-2026-9804High· 7.7A flaw was found in KubeVirt's virt-exportserver component
A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an ex…
CVE-2026-44394Medium· 6.0OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
CVE-2026-43000Medium· 6.0OpenStack Keystone has an Incorrect Authorization issue
OpenStack Keystone has an Incorrect Authorization issue