Tagged “osv”
CVEs tagged osv, newest first.
5681 CVEsRSS
CVE-2026-6110High· 7.3MetaGPT has an eval injection in metagpt/strategy/tot.py
MetaGPT has an eval injection in metagpt/strategy/tot.py
CVE-2026-6109Medium· 4.3MetaGPT has an eval injection via a cross-site request forgery attack
MetaGPT has an eval injection via a cross-site request forgery attack
CVE-2026-6111Medium· 6.3PoCMetaGPT affected by server-side request forgery in metagpt/utils/common.py
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
GHSA-x462-jjpc-q4q4High· 8.1PraisonAI: Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint
PraisonAI: Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint
GHSA-pjjw-68hj-v9mwLowuv vulnerable to arbitrary file deletion through RECORD entries
uv vulnerable to arbitrary file deletion through RECORD entries
CVE-2026-79671Medium· 5.5Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation
Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation
CVE-2026-79673Medium· 6.5Ech0 Scope Bypass: profile:read Access Token Can Change Admin Password and Escalate to Unrestricted Session
Ech0 Scope Bypass: profile:read Access Token Can Change Admin Password and Escalate to Unrestricted Session
CVE-2026-79672Medium· 5.5Ech0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass
Ech0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass
CVE-2026-79666Medium· 6.5Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs
Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs
CVE-2026-79670Medium· 4.8Ech0 has Stored XSS via SVG Upload and Content-Type Validation Bypass in File Upload
Ech0 has Stored XSS via SVG Upload and Content-Type Validation Bypass in File Upload
CVE-2026-79667High· 7.6Ech0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export
Ech0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export
CVE-2026-5388Mediumjusthtml includes multiple security fixes
justhtml includes multiple security fixes
CVE-2026-34178Critical· 9.1LXD: Importing a crafted backup leads to project restriction bypass
LXD: Importing a crafted backup leads to project restriction bypass
CVE-2026-34177Critical· 9.1LXD: VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf
LXD: VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf
CVE-2026-34179Critical· 9.1LXD: Update of type field in restricted TLS certificate allows privilege escalation to cluster admin
LXD: Update of type field in restricted TLS certificate allows privilege escalation to cluster admin
CVE-2026-35204High· 8.6PoCHelm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory
Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory
CVE-2026-35205High· 7.8Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install
Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install
CVE-2026-35206MediumHelm Chart extraction output directory collapse via `Chart.yaml` name dot-segment
Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment
CVE-2026-35596Medium· 4.3Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug
CVE-2026-35597Medium· 5.9Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout
Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout
CVE-2026-40242High· 7.2PoCArcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint
Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint
CVE-2026-35594Medium· 6.5Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade
CVE-2026-34727High· 7.4Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path
CVE-2026-39921Medium· 6.3GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery vulnerability that allows authenticated user…
GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery vulnerability that allows authenticated users with document upload permissions to trigger arbitrary outbound HTTP requests by providing a malici…
CVE-2026-40315MediumPraisonAI: SQLiteConversationStore didn't validate table_prefix when constructing SQL queries
PraisonAI: SQLiteConversationStore didn't validate table_prefix when constructing SQL queries
CVE-2026-40153High· 7.4PraisonAIAgents: Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool
PraisonAIAgents: Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool
CVE-2026-40160HighPraisonAIAgents: SSRF via unvalidated URL in `web_crawl` httpx fallback
PraisonAIAgents: SSRF via unvalidated URL in `web_crawl` httpx fallback
CVE-2026-40116High· 7.5PraisonAI: Unauthenticated WebSocket Endpoint Proxies to Paid OpenAI Realtime API Without Rate Limits
PraisonAI: Unauthenticated WebSocket Endpoint Proxies to Paid OpenAI Realtime API Without Rate Limits
CVE-2026-40151Medium· 5.3PoCPraisonAI: Unauthenticated Information Disclosure of Agent Instructions via /api/agents in AgentOS
PraisonAI: Unauthenticated Information Disclosure of Agent Instructions via /api/agents in AgentOS
CVE-2026-40159Medium· 5.5PraisonAI Vulnerable to Sensitive Environment Variable Exposure via Untrusted MCP Subprocess Execution
PraisonAI Vulnerable to Sensitive Environment Variable Exposure via Untrusted MCP Subprocess Execution