CVE tracker
383 subscribers
5.36K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-79622 - dekdee adobe-xd-mcp file-access-from-request Endpoint xd-parser.ts path traversal

CVE ID :CVE-2026-79622
Published : Aug. 25, 2026, 2:16 p.m. | 36 minutes ago
Description :A weakness has been identified in dekdee adobe-xd-mcp 1.0.0. Impacted is an unknown function of the file src/parsers/xd-parser.ts of the component file-access-from-request Endpoint. Executing a manipulation of the argument outputFile/outputDir can lead to path traversal. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-79623 - FishCodeTech Muteki Default Local Worker Backend settings.json os command injection

CVE ID :CVE-2026-79623
Published : Aug. 25, 2026, 2:16 p.m. | 36 minutes ago
Description :A security vulnerability has been detected in FishCodeTech Muteki up to 0.2.5. The affected element is an unknown function of the file .claude/settings.json of the component Default Local Worker Backend. The manipulation leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The issue was closed with the comment (translated from Chinese): "The project will be refactored and shut down."
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-79655 - Sos: sos: path traversal in sos clean tar extraction via unvalidated symlink/hardlink targets leads to arbitrary file write

CVE ID :CVE-2026-79655
Published : Aug. 25, 2026, 2:16 p.m. | 36 minutes ago
Description :A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local attacker to perform arbitrary file creation or overwrite. By crafting a malicious tar archive, an attacker can exploit a path traversal issue during tar extraction, where symlink and hardlink targets are not properly validated. This enables the attacker to write files to arbitrary locations on the system with the privileges of the sos clean process, which often runs as root.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16599 - Denial of Service in GNU wget

CVE ID :CVE-2026-16599
Published : Aug. 25, 2026, 2:17 p.m. | 36 minutes ago
Description :GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a crafted OPIE challenge with a sequence number near INT_MAX, causing wget to perform up to approximately 2.1 billion MD5 computations and suspend for some time. The --timeout option does not mitigate this because it applies only to network I/O, not CPU computation. This issue was fixed in commit e9697d98e7249b0f68a6be040a4f3dcc5bc101fa
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16286 - File Upload in TRTEK Software's Software Repository Management

CVE ID :CVE-2026-16286
Published : Aug. 25, 2026, 2:26 p.m. | 26 minutes ago
Description :Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Software Repository Management allows Upload a Web Shell to a Web Server. This issue affects Software Repository Management: before 2fb4acee.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-55529 - PraisonAI: Origin validation bypass in MCP HTTP Stream transport allows browser-mediated unauthenticated tool execution on local MCP server

CVE ID :CVE-2026-55529
Published : Aug. 25, 2026, 2:26 p.m. | 26 minutes ago
Description :PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream _validate_origin method accepts request_origin.startswith(allowed), so the attacker-controlled localhost.evil.example HTTP origin matches the localhost allowlist. Without an API key, a malicious webpage can submit tools/call requests to the local MCP server and execute exposed tools. This issue is fixed in version 4.6.58.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-75749 - Substance3D - Painter | Out-of-bounds Write (CWE-787)

CVE ID :CVE-2026-75749
Published : Aug. 25, 2026, 6:18 p.m. | 35 minutes ago
Description :Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-75750 - Substance3D - Painter | Heap-based Buffer Overflow (CWE-122)

CVE ID :CVE-2026-75750
Published : Aug. 25, 2026, 6:18 p.m. | 35 minutes ago
Description :Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-75752 - Substance3D - Painter | Out-of-bounds Read (CWE-125)

CVE ID :CVE-2026-75752
Published : Aug. 25, 2026, 6:18 p.m. | 35 minutes ago
Description :Substance3D - Painter is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-75766 - Substance3D - Painter | Heap-based Buffer Overflow (CWE-122)

CVE ID :CVE-2026-75766
Published : Aug. 25, 2026, 6:18 p.m. | 35 minutes ago
Description :Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-75767 - Substance3D - Painter | Heap-based Buffer Overflow (CWE-122)

CVE ID :CVE-2026-75767
Published : Aug. 25, 2026, 6:18 p.m. | 35 minutes ago
Description :Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-75768 - Substance3D - Painter | Untrusted Search Path (CWE-426)

CVE ID :CVE-2026-75768
Published : Aug. 25, 2026, 6:18 p.m. | 35 minutes ago
Description :Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-75769 - Substance3D - Painter | Heap-based Buffer Overflow (CWE-122)

CVE ID :CVE-2026-75769
Published : Aug. 25, 2026, 6:18 p.m. | 35 minutes ago
Description :Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-75770 - Substance3D - Painter | Out-of-bounds Write (CWE-787)

CVE ID :CVE-2026-75770
Published : Aug. 25, 2026, 6:18 p.m. | 35 minutes ago
Description :Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76189 - CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)

CVE ID :CVE-2026-76189
Published : Aug. 25, 2026, 6:18 p.m. | 35 minutes ago
Description :CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Severity: 6.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76193 - Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)

CVE ID :CVE-2026-76193
Published : Aug. 25, 2026, 6:18 p.m. | 35 minutes ago
Description :Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76195 - Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)

CVE ID :CVE-2026-76195
Published : Aug. 25, 2026, 6:18 p.m. | 35 minutes ago
Description :Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76197 - Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)

CVE ID :CVE-2026-76197
Published : Aug. 25, 2026, 6:18 p.m. | 35 minutes ago
Description :Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76198 - CAI Content Credentials | Improper Input Validation (CWE-20)

CVE ID :CVE-2026-76198
Published : Aug. 25, 2026, 6:18 p.m. | 35 minutes ago
Description :CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-79992 - Emacs: local shell command injection through the user field in emacs tramp

CVE ID :CVE-2026-79992
Published : Aug. 25, 2026, 6:18 p.m. | 35 minutes ago
Description :A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation could lead to arbitrary code execution.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-80051 - graphql-go/graphql Improper Input Validation and Denial of Service Vulnerability

CVE ID :CVE-2026-80051
Published : Aug. 25, 2026, 6:18 p.m. | 35 minutes ago
Description :github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not validate that a scalar variable value matches its declared type. The built-in coerceString and coerceBool functions (scalars.go) accept input whose type does not match the declared String, ID, or Boolean scalar instead of raising the request error that the GraphQL specification mandates. In some cases (but not any typical case of JSON sent to a website), a deeply nested value leads to an unrecoverable "fatal error: stack overflow" condition.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...