CVE tracker
392 subscribers
5.78K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-94656 - Apache Thrift: rb `TJsonProtocol`/`TJSONProtocol` has no string size bound

CVE ID :CVE-2026-94656
Published : Oct. 2, 2026, 1:18 p.m. | 27 minutes ago
Description :Allocation of resources without limits or throttling vulnerability in Apache Thrift ruby bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-94657 - Apache Thrift: javame `TJsonProtocol`/`TJSONProtocol` has no string size bound

CVE ID :CVE-2026-94657
Published : Oct. 2, 2026, 1:18 p.m. | 27 minutes ago
Description :Allocation of resources without limits or throttling vulnerability in Apache Thrift JavaME bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-94658 - Apache Thrift: Lua `TFramedTransport`/`THttpTransport` re-slice the buffer on every read (quadratic)

CVE ID :CVE-2026-94658
Published : Oct. 2, 2026, 1:18 p.m. | 27 minutes ago
Description :Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-96277 - Apache Thrift: Ruby `SimpleServer` ends `serve()` on any non-Transport/Protocol exception

CVE ID :CVE-2026-96277
Published : Oct. 2, 2026, 1:18 p.m. | 27 minutes ago
Description :Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-96286 - Apache Thrift: Perl servers end `serve()` when serving one connection fails

CVE ID :CVE-2026-96286
Published : Oct. 2, 2026, 1:18 p.m. | 27 minutes ago
Description :Uncaught exception vulnerability in Apache Thrift Perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-96287 - Apache Thrift: Perl `FramedTransport` reads and TLS socket writes re-slice the remaining buffer on every call (quadratic)

CVE ID :CVE-2026-96287
Published : Oct. 2, 2026, 1:18 p.m. | 27 minutes ago
Description :Inefficient Algorithmic Complexity vulnerability in Apache Thrift Perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-96289 - Apache Thrift: php `--gen php:inlined` struct readers (and `TProtocol::skipBinary`) have no recursion-depth guard

CVE ID :CVE-2026-96289
Published : Oct. 2, 2026, 1:18 p.m. | 27 minutes ago
Description :Uncontrolled Recursion vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104721 - Logback: Incomplete protection against CVE-2026-19880

CVE ID :CVE-2026-104721
Published : Oct. 2, 2026, 1:21 p.m. | 23 minutes ago
Description :Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender path, letting an attacker who influences that MDC value (e.g. via an HTTP header) create and append log files outside the intended directory. This issue affects Logback-classic: from 0.9.14 through 1.6.4.  This vulnerability is similar to CVE-2026-19880 but involves other attack techniques.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93875 - JetAppointment <= 2.5.2.1 - Unauthenticated Stored Cross-Site Scripting via 'friendlyTime' Parameter

CVE ID :CVE-2026-93875
Published : Oct. 2, 2026, 1:29 p.m. | 16 minutes ago
Description :The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friendlyTime' parameter in all versions up to, and including, 2.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload is stored in the wp_jet_appointments_meta table via the unauthenticated jet_engine_form_booking_submit endpoint and executes in the administrator's browser when the appointment details popup is opened in the WordPress admin panel.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19652 - Divi Membership <= 2.2.0 - Unauthenticated Privilege Escalation via 'form_id' Parameter

CVE ID :CVE-2026-19652
Published : Oct. 2, 2026, 1:29 p.m. | 16 minutes ago
Description :The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash supplied in the `form_id` POST parameter, with no validation or whitelist of allowed roles. This makes it possible for unauthenticated attackers to register a new account with the administrator role by submitting a locally computed bcrypt hash of `administrator` as `form_id`, and when `auto_login=on` is submitted, be immediately authenticated as that administrator in the same request, resulting in full site takeover. Exploitation requires a WordPress nonce, but that nonce is publicly emitted on any page rendering the Divi Membership registration form and is therefore obtainable by any unauthenticated visitor.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51904 - SuperAGI Improper Access Control Vulnerability

CVE ID :CVE-2026-51904
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :SuperAGI up to v0.0.14 contains an improper access control vulnerability in the agent execution controller. In affected source snapshots, create_agent_execution and create_agent_run in superagi/controllers/agent_execution.py accept a caller-supplied agent_id and fail to verify that the referenced agent belongs to the authenticated user's organization. A remote authenticated attacker from one organization can create or start execution records for agents owned by another organization through /agentexecutions/add or /agentexecutions/add_run.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51906 - TaskingAI Path Traversal Vulnerability

CVE ID :CVE-2026-51906
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :In TaskingAI v0.3.0 in the DALL-E 3 image generation tool save_url_image function, a path traversal vulnerability allows attackers to write downloaded images to arbitrary locations on the server filesystem by manipulating the project_id parameter.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51907 - TaskingAI QR Code Generator Plugin Path Traversal Vulnerability

CVE ID :CVE-2026-51907
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write image files to arbitrary locations on the server filesystem by manipulating the project_id parameter.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51911 - Vanna Code Injection Vulnerability

CVE ID :CVE-2026-51911
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :vanna v2.0.2 contains a code injection vulnerability in VannaBase.get_plotly_figure (src/vanna/legacy/base/base.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51914 - SuperAGI Agent Template Controller Incorrect Access Control

CVE ID :CVE-2026-51914
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the agent template controller. In affected source snapshots, save_agent_as_template and publish_template in superagi/controllers/agent_template.py accept caller-supplied agent_id or agent_execution_id values and do not verify that the referenced agent or execution belongs to the authenticated user's organization.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51915 - SuperAGI Incorrect Access Control Vulnerability

CVE ID :CVE-2026-51915
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the tool controller. In affected source snapshots, get_tool and update_tool in superagi/controllers/tool.py accept a caller-supplied tool_id and fail to verify organization ownership through the associated toolkit. A remote authenticated attacker from one organization can read or modify another organization's tool metadata through /tools/get/{tool_id} and /tools/update/{tool_id}.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51916 - SuperAGI Incorrect Access Control Vulnerability

CVE ID :CVE-2026-51916
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_user_knowledge in superagi/controllers/knowledges.py. In affected source snapshots, POST /knowledges/delete/{knowledge_id} deletes the selected knowledge object without requiring authentication in the route and without verifying organization ownership of the supplied knowledge_id.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51917 - FinRobot CodingUtils Code Injection

CVE ID :CVE-2026-51917
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :FinRobot v1.0.0 is vulnerable to Code Injection in CodingUtils.modify_code.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51918 - FinRobot Code Injection Vulnerability

CVE ID :CVE-2026-51918
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :FinRobot 1.0.0 contains code injection in CodingUtils.create_file_with_code ().
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51922 - AgentScope Code Injection Vulnerability

CVE ID :CVE-2026-51922
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :agentscope v1.0.20 contains code injection in execute_shell_command (src/agentscope/tool/_coding/_shell.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67989 - Ruby_llm Regular Expression Denial of Service

CVE ID :CVE-2026-67989
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...