grackle-ai has 2 CVEs on record. 2 were published in the last 90 days.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- —
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Products
- @grackle-ai/mcp 1
- @grackle-ai/runtime-sdk 1
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
GHSA-vv65-f55v-xm6gHighGrackle has command/argument injection in the git worktree executor that enables RCE on provisioned hosts via an unsanitized task branch name (shell:true)41GHSA-f9ff-5x35-7gfwHighGrackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR)41
grackle-ai vulnerabilities
CVEs affecting grackle-ai, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
GHSA-vv65-f55v-xm6gHighGrackle has command/argument injection in the git worktree executor that enables RCE on provisioned hosts via an unsanitized task branch name (shell:true)
Grackle has command/argument injection in the git worktree executor that enables RCE on provisioned hosts via an unsanitized task branch name (shell:true)
▾ Twilightgrackle-ai · @grackle-ai/runtime-sdkvia GHSA
GHSA-f9ff-5x35-7gfwHighGrackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR)
Grackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR)
▾ Twilightgrackle-ai · @grackle-ai/mcpvia GHSA