CVE tracker
374 subscribers
5.22K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-71985 - MSI Radix AXE6600 v781521 Command Injection via accesscontrol Function

CVE ID :CVE-2026-71985
Published : Aug. 8, 2026, 11:21 p.m. | 55 minutes ago
Description :MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the accesscontrol function to execute malicious commands and obtain root privileges on the underlying system.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-71986 - MSI Radix AXE6600 v781521 Command Injection via dmz Function

CVE ID :CVE-2026-71986
Published : Aug. 8, 2026, 11:24 p.m. | 52 minutes ago
Description :MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the dmz function to execute malicious commands and obtain root privileges on the underlying system.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-71987 - MSI Radix AXE6600 v781521 Command Injection via alg function

CVE ID :CVE-2026-71987
Published : Aug. 8, 2026, 11:27 p.m. | 49 minutes ago
Description :MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-71988 - MSI Radix AXE6600 v781521 Command Injection via portFw function

CVE ID :CVE-2026-71988
Published : Aug. 8, 2026, 11:31 p.m. | 45 minutes ago
Description :MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-71989 - MSI Radix AXE6600 v781521 Command Injection via porTrigger function

CVE ID :CVE-2026-71989
Published : Aug. 8, 2026, 11:33 p.m. | 43 minutes ago
Description :MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-71990 - MSI Radix AXE6600 v781521 Command Injection via TelnetSSH Function

CVE ID :CVE-2026-71990
Published : Aug. 8, 2026, 11:37 p.m. | 39 minutes ago
Description :MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the SSH configuration interface to inject malicious commands and obtain root privileges on the underlying system.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-71991 - MSI Radix AXE6600 v781521 Command Injection via TelnetSSH Function

CVE ID :CVE-2026-71991
Published : Aug. 8, 2026, 11:49 p.m. | 27 minutes ago
Description :MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the Telnet configuration interface to inject malicious commands and obtain root privileges on the underlying system.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-71992 - MSI Radix AXE6600 v781521 Command Injection via macfilter

CVE ID :CVE-2026-71992
Published : Aug. 8, 2026, 11:52 p.m. | 23 minutes ago
Description :MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-71993 - MSI Radix AXE6600 v781521 Command Injection via openvpn function

CVE ID :CVE-2026-71993
Published : Aug. 9, 2026, midnight | 16 minutes ago
Description :MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19323 - azer react-analyzer-mcp analyze-projec index.ts generateProjectDocs path traversal

CVE ID :CVE-2026-19323
Published : Aug. 9, 2026, midnight | 16 minutes ago
Description :A security flaw has been discovered in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0. Affected by this vulnerability is the function generateProjectDocs of the file src/index.ts of the component analyze-projec. The manipulation of the argument projectName results in path traversal. The attack is only possible with local access. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-17510 - Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute

CVE ID :CVE-2026-17510
Published : Aug. 9, 2026, 2:16 a.m. | 2 hours, 1 minute ago
Description :Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute. print_attribute() sizes the destination buffer for a BMPSTRING attribute from its declared byte length with `Renew(*attribute, length, char)`. A zero length attribute makes that a zero size reallocation, which Perl implements as a free returning NULL, so the buffer pointer becomes NULL, the following `strncpy` copies nothing, and the caller dereferences NULL in the `strlen()` it passes to `newSVpvn()`. A zero length BMPSTRING is even length, so the ASN.1 decoder accepts it and the value reaches this code. The UTF8STRING, OCTET STRING and BIT STRING arms size on `length + 1` or `length * 4 + 1` and are unaffected. Any caller that passes an untrusted PKCS#12 file to info_as_hash() can crash the process. info() prints attribute values directly without sizing a buffer and is unaffected.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19324 - HelloGGX shadcn-vue-mcp callback-server.ts fs.promises.readFile path traversal

CVE ID :CVE-2026-19324
Published : Aug. 9, 2026, 3:16 a.m. | 1 hour, 1 minute ago
Description :A weakness has been identified in HelloGGX shadcn-vue-mcp up to e170e277b94235cde627803277fc8c41103a4d38. Affected by this issue is the function fs.promises.readFile of the file src/server/callback-server.ts. This manipulation of the argument filepath causes path traversal. The attack is restricted to local execution. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19325 - IncomeStreamSurfer roo-code-memory-bank-mcp-server read_memory_bank_file/append_memory_bank_entry index.ts appendMemoryBankEntry path traversal

CVE ID :CVE-2026-19325
Published : Aug. 9, 2026, 3:16 a.m. | 1 hour, 1 minute ago
Description :A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35ac1983885a6d4e5621a0081e. This affects the function readMemoryBankFile/appendMemoryBankEntry of the file src/index.ts of the component read_memory_bank_file/append_memory_bank_entry. Such manipulation of the argument file_name leads to path traversal. The attack must be carried out locally. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19326 - Jevon-Zhong Ai-doctor filemanagement.service.ts deleteImage path traversal

CVE ID :CVE-2026-19326
Published : Aug. 9, 2026, 3:16 a.m. | 1 hour, 1 minute ago
Description :A vulnerability was detected in Jevon-Zhong Ai-doctor 0.0.1. This vulnerability affects the function deleteImage of the file ai-doctor-server/src/filemanagement/filemanagement.service.ts. Performing a manipulation of the argument imagePath results in path traversal. The attack must be initiated from a local position. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 4.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19327 - abracadabra50 claude-sesh enricher.ts enrichSession path traversal

CVE ID :CVE-2026-19327
Published : Aug. 9, 2026, 3:16 a.m. | 1 hour, 1 minute ago
Description :A flaw has been found in abracadabra50 claude-sesh 1.0.0. This issue affects the function getEnrichedData/enrichSession of the file src/services/enricher.ts. Executing a manipulation of the argument sessionId can lead to path traversal. The attack needs to be launched locally. This patch is called 786c9d74800e6d0858b65778f31beb71b3983a50. Applying a patch is advised to resolve this issue.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19328 - aktsmm skill-ninja-mcp-server installer.ts uninstallSkill path traversal

CVE ID :CVE-2026-19328
Published : Aug. 9, 2026, 3:16 a.m. | 1 hour, 1 minute ago
Description :A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0. Impacted is the function getInstalledSkills/installSkill/updateAgentsMd/uninstallSkill of the file src/installer.ts. The manipulation of the argument workspacePath leads to path traversal. The attack needs to be performed locally. Upgrading to version 0.1.1 is recommended to address this issue. The identifier of the patch is 855b46739e0f6e8388f17f9d0066ac4298a3965d. Upgrading the affected component is recommended.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19329 - andreahaku codex_mcp ask MCP Tool codex-process-simple.ts command injection

CVE ID :CVE-2026-19329
Published : Aug. 9, 2026, 3:30 a.m. | 47 minutes ago
Description :A vulnerability was found in andreahaku codex_mcp up to 1ff521cc6cc57cfe56ddef946c644b8534771390. The affected element is an unknown function of the file src/codex-process-simple.ts of the component ask MCP Tool. The manipulation of the argument model results in command injection. The attack requires a local approach. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19330 - angrysky56 advanced-reasoning-mcp index.ts switch_memory_library path traversal

CVE ID :CVE-2026-19330
Published : Aug. 9, 2026, 3:45 a.m. | 32 minutes ago
Description :A vulnerability was determined in angrysky56 advanced-reasoning-mcp 1.0.0. The impacted element is the function create_system_json/create_library to get_system_json/switch_memory_library of the file src/index.ts. This manipulation causes path traversal. The attack requires local access. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-10595 - Path Traversal Vulnerability in parisneo/lollms

CVE ID :CVE-2026-10595
Published : Aug. 9, 2026, 3:52 a.m. | 25 minutes ago
Description :A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper handling of user-controlled path input, which is directly joined into a filesystem path without sanitization or containment checks. URL-encoded dot-dot sequences (`%2e%2e`) bypass Starlette's built-in path normalization and are resolved by Python's `pathlib`, allowing an unauthenticated attacker to read arbitrary files on the server. This issue has been resolved in version 3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16032 - LWS Optimize < 4.1.2 - Unauthenticated Stored XSS via Real User Monitoring

CVE ID :CVE-2026-16032
Published : Aug. 9, 2026, 6:17 a.m. | 2 hours, 1 minute ago
Description :The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated analytics endpoint before storing it and rendering it in an administrative dashboard, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the affected dashboard page.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16957 - Slim SEO < 4.9.11 - Contributor+ Arbitrary Post Meta Disclosure

CVE ID :CVE-2026-16957
Published : Aug. 9, 2026, 6:17 a.m. | 2 hours, 1 minute ago
Description :The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed to edit, verifying only read access, allowing users with the Contributor role to read arbitrary post meta, including protected and private keys, of published posts they do not own, including password-protected posts and posts of non-public post types.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...