CVE tracker
393 subscribers
5.75K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-103437 - ReadingLists imported metadata permits JavaScript URL XSS

CVE ID :CVE-2026-103437
Published : Sept. 30, 2026, 5:17 p.m. | 13 minutes ago
Description :Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki ReadingLists extension allows Reflected XSS. This issue affects MediaWiki ReadingLists extension: 1.46 and 1.45.
Severity: 1.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102996 - pypdf: Possible large memory usage when parsing font data

CVE ID :CVE-2026-102996
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can provide a TrueType or Type1 simple font with an unusually large /Widths array, causing pypdf/_font.py Font._collect_tt_t1_character_widths to process entries beyond the 256 character codes meaningful for a simple font and consume excessive memory during operations such as text extraction. This issue is fixed in version 6.18.1.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102997 - pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up)

CVE ID :CVE-2026-102997
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF containing a partially malformed /FlateDecode stream with padded data can force pypdf/filters.py to use inefficient byte-by-byte decompression while the earlier recovery counter fails to advance for bytes that successfully decode, causing long runtimes and application unavailability. This is a residual issue after the malformed FlateDecode recovery fix. This issue is fixed in version 6.18.1.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102998 - pypdf: Possible long runtimes when generating appearance streams

CVE ID :CVE-2026-102998
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF with form field values can cause pypdf/generic/_appearance_stream.py appearance-stream generation to repeat invariant selection-data work inside a loop when an application updates fields with flattening enabled, resulting in excessive runtimes and application unavailability. This issue is fixed in version 6.19.0.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102999 - pypdf: Possible long runtimes with large amount of embedded files

CVE ID :CVE-2026-102999
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF containing many embedded files can cause the dictionary-based attachments API in pypdf/_doc_common.py to reparse the full attachment list for each content lookup, producing repeated work and long runtimes when an application accesses the embedded-file mapping. This issue is fixed in version 6.19.0.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103000 - pypdf: Possible large memory usage when retrieving alphabetical page labels

CVE ID :CVE-2026-103000
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF can provide unusually large alphabetical page-label values that cause pypdf/_page_labels.py to generate strings beyond a reasonable page-label length when an application retrieves document page labels, consuming excessive memory and potentially making the application unavailable. This issue is fixed in version 6.19.0.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51568 - ModelScope AgentScope Path Traversal Vulnerability

CVE ID :CVE-2026-51568
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51570 - ModelScope AgentScope Path Traversal Vulnerability

CVE ID :CVE-2026-51570
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert_text_file.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51852 - Agent-Zero Directory Traversal

CVE ID :CVE-2026-51852
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.save_file_b64. The save_file_b64 method accepts user-controlled file paths without normalization or validation, allowing path traversal attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51853 - Agent-Zero Directory Traversal Vulnerability

CVE ID :CVE-2026-51853
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.__init__. The FileBrowser class initializes with the host root directory as the workspace, allowing the agent to access any file on the system without restriction.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51856 - AgentScope RealtimeAgent Arbitrary Code Execution Vulnerability

CVE ID :CVE-2026-51856
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python code in the service environment. In the validated path, RealtimeAgent._acting forwards the model-produced tool call to Toolkit.call_tool_function, which invokes execute_python_code without an additional approval or isolation boundary on that path.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51857 - Camel-AI CodeExecutionToolkit Arbitrary Code Execution Vulnerability

CVE ID :CVE-2026-51857
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, CodeExecutionToolkit can run model-produced Python code through SubprocessInterpreter without an approval boundary.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51858 - CAMEL TerminalToolkit Shell Command Injection Vulnerability

CVE ID :CVE-2026-51858
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, TerminalToolkit.shell_exec allows prompt-driven shell command execution without an approval boundary.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51859 - Bisheng Directory Traversal Vulnerability

CVE ID :CVE-2026-51859
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to directory traversal in save_download_file (src/backend/bisheng/core/cache/utils.py:290).
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51860 - Bisheng Directory Traversal Vulnerability

CVE ID :CVE-2026-51860
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Directory Traversal in src/backend/bisheng/linsight/domain/task_exec.py.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51861 - Bisheng Code Injection Vulnerability

CVE ID :CVE-2026-51861
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Code Injection in src/backend/bisheng/api/v1/validate.py.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51862 - DB-GPT Directory Traversal Vulnerability

CVE ID :CVE-2026-51862
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :DB-GPT 0.8.0 contains directory traversal in skill_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:40). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51864 - DB-GPT Directory Traversal Vulnerability

CVE ID :CVE-2026-51864
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :DB-GPT v0.7.5 and v0.8.0 contains directory traversal in python_file_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/python_upload_api.py:42). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51866 - DB-GPT Arbitrary Code Execution

CVE ID :CVE-2026-51866
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :In DB-GPT 0.7.5 and 0.8.0, a skill uploaded through the real /api/v1/skills/upload route can later be executed through the real /api/v1/chat/react-agent flow.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51867 - AgentGPT Incorrect Access Control Vulnerability

CVE ID :CVE-2026-51867
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :agentgpt v.1.0.0 is vulnerable to Incorrect Access Control in next/src/server/api/routers/agentRouter.ts. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51869 - DB-GPT Sandbox API Arbitrary Code Execution

CVE ID :CVE-2026-51869
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :DB-GPT v0.8.0 sandbox API silently falls back to LocalRuntime and executes code on host.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...