CVE tracker
393 subscribers
5.75K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-103000 - pypdf: Possible large memory usage when retrieving alphabetical page labels

CVE ID :CVE-2026-103000
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF can provide unusually large alphabetical page-label values that cause pypdf/_page_labels.py to generate strings beyond a reasonable page-label length when an application retrieves document page labels, consuming excessive memory and potentially making the application unavailable. This issue is fixed in version 6.19.0.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51568 - ModelScope AgentScope Path Traversal Vulnerability

CVE ID :CVE-2026-51568
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51570 - ModelScope AgentScope Path Traversal Vulnerability

CVE ID :CVE-2026-51570
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert_text_file.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51852 - Agent-Zero Directory Traversal

CVE ID :CVE-2026-51852
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.save_file_b64. The save_file_b64 method accepts user-controlled file paths without normalization or validation, allowing path traversal attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51853 - Agent-Zero Directory Traversal Vulnerability

CVE ID :CVE-2026-51853
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.__init__. The FileBrowser class initializes with the host root directory as the workspace, allowing the agent to access any file on the system without restriction.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51856 - AgentScope RealtimeAgent Arbitrary Code Execution Vulnerability

CVE ID :CVE-2026-51856
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python code in the service environment. In the validated path, RealtimeAgent._acting forwards the model-produced tool call to Toolkit.call_tool_function, which invokes execute_python_code without an additional approval or isolation boundary on that path.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51857 - Camel-AI CodeExecutionToolkit Arbitrary Code Execution Vulnerability

CVE ID :CVE-2026-51857
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, CodeExecutionToolkit can run model-produced Python code through SubprocessInterpreter without an approval boundary.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51858 - CAMEL TerminalToolkit Shell Command Injection Vulnerability

CVE ID :CVE-2026-51858
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, TerminalToolkit.shell_exec allows prompt-driven shell command execution without an approval boundary.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51859 - Bisheng Directory Traversal Vulnerability

CVE ID :CVE-2026-51859
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to directory traversal in save_download_file (src/backend/bisheng/core/cache/utils.py:290).
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51860 - Bisheng Directory Traversal Vulnerability

CVE ID :CVE-2026-51860
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Directory Traversal in src/backend/bisheng/linsight/domain/task_exec.py.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51861 - Bisheng Code Injection Vulnerability

CVE ID :CVE-2026-51861
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Code Injection in src/backend/bisheng/api/v1/validate.py.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51862 - DB-GPT Directory Traversal Vulnerability

CVE ID :CVE-2026-51862
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :DB-GPT 0.8.0 contains directory traversal in skill_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:40). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51864 - DB-GPT Directory Traversal Vulnerability

CVE ID :CVE-2026-51864
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :DB-GPT v0.7.5 and v0.8.0 contains directory traversal in python_file_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/python_upload_api.py:42). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51866 - DB-GPT Arbitrary Code Execution

CVE ID :CVE-2026-51866
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :In DB-GPT 0.7.5 and 0.8.0, a skill uploaded through the real /api/v1/skills/upload route can later be executed through the real /api/v1/chat/react-agent flow.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51867 - AgentGPT Incorrect Access Control Vulnerability

CVE ID :CVE-2026-51867
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :agentgpt v.1.0.0 is vulnerable to Incorrect Access Control in next/src/server/api/routers/agentRouter.ts. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51869 - DB-GPT Sandbox API Arbitrary Code Execution

CVE ID :CVE-2026-51869
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :DB-GPT v0.8.0 sandbox API silently falls back to LocalRuntime and executes code on host.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51870 - DeepTutor Command Injection Vulnerability

CVE ID :CVE-2026-51870
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :DeepTutor v1.4.0 is vulnerable to command execution in /tutorbot/agent/tools/shell.py:ExecTool.execute.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51871 - Devika Code Injection Vulnerability

CVE ID :CVE-2026-51871
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :Devika v1.0 is vulnerable to Code Injection in the Runner.execute function in src/agents/runner/runner.py which allows an attacker to achieve arbitrary code execution by exploiting the direct execution of LLM-generated content.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51872 - Devika Code Injection Vulnerability

CVE ID :CVE-2026-51872
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :Devika v1.0 is vulnerable to Code Injection via the Runner.run_code function in src/agents/runner/runner.py.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92172 - Meta Horizon OS OVRMediaService Privilege Escalation Vulnerability

CVE ID :CVE-2026-92172
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :Prior to v66.0.0.733.524 of Meta Horizon OS, OVRMediaService could be induced to send a privileged PendingIntent including a com.oculus.horizon CallerIdentity to an arbitrary application registering for com.oculus.systemactivities.SCREENSHOT via a broadcast receiver. That would allow the application to impersonate the com.oculus.horizon package towards any endpoint within the OS that uses CallerIdentity authentication.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92173 - Meta Horizon OS Improper Privilege Management Vulnerability

CVE ID :CVE-2026-92173
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent including a com.oculus.vrshell CallerIdentity to an arbitrary application listening via NotificationListenerService. That would allow the application to impersonate the com.oculus.vrshell package, as well as packages signed with the same key, towards any endpoint within the OS that uses CallerIdentity authentication.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...