CVE tracker
393 subscribers
5.78K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-51904 - SuperAGI Improper Access Control Vulnerability

CVE ID :CVE-2026-51904
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :SuperAGI up to v0.0.14 contains an improper access control vulnerability in the agent execution controller. In affected source snapshots, create_agent_execution and create_agent_run in superagi/controllers/agent_execution.py accept a caller-supplied agent_id and fail to verify that the referenced agent belongs to the authenticated user's organization. A remote authenticated attacker from one organization can create or start execution records for agents owned by another organization through /agentexecutions/add or /agentexecutions/add_run.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51906 - TaskingAI Path Traversal Vulnerability

CVE ID :CVE-2026-51906
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :In TaskingAI v0.3.0 in the DALL-E 3 image generation tool save_url_image function, a path traversal vulnerability allows attackers to write downloaded images to arbitrary locations on the server filesystem by manipulating the project_id parameter.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51907 - TaskingAI QR Code Generator Plugin Path Traversal Vulnerability

CVE ID :CVE-2026-51907
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write image files to arbitrary locations on the server filesystem by manipulating the project_id parameter.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51911 - Vanna Code Injection Vulnerability

CVE ID :CVE-2026-51911
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :vanna v2.0.2 contains a code injection vulnerability in VannaBase.get_plotly_figure (src/vanna/legacy/base/base.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51914 - SuperAGI Agent Template Controller Incorrect Access Control

CVE ID :CVE-2026-51914
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the agent template controller. In affected source snapshots, save_agent_as_template and publish_template in superagi/controllers/agent_template.py accept caller-supplied agent_id or agent_execution_id values and do not verify that the referenced agent or execution belongs to the authenticated user's organization.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51915 - SuperAGI Incorrect Access Control Vulnerability

CVE ID :CVE-2026-51915
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the tool controller. In affected source snapshots, get_tool and update_tool in superagi/controllers/tool.py accept a caller-supplied tool_id and fail to verify organization ownership through the associated toolkit. A remote authenticated attacker from one organization can read or modify another organization's tool metadata through /tools/get/{tool_id} and /tools/update/{tool_id}.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51916 - SuperAGI Incorrect Access Control Vulnerability

CVE ID :CVE-2026-51916
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_user_knowledge in superagi/controllers/knowledges.py. In affected source snapshots, POST /knowledges/delete/{knowledge_id} deletes the selected knowledge object without requiring authentication in the route and without verifying organization ownership of the supplied knowledge_id.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51917 - FinRobot CodingUtils Code Injection

CVE ID :CVE-2026-51917
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :FinRobot v1.0.0 is vulnerable to Code Injection in CodingUtils.modify_code.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51918 - FinRobot Code Injection Vulnerability

CVE ID :CVE-2026-51918
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :FinRobot 1.0.0 contains code injection in CodingUtils.create_file_with_code ().
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51922 - AgentScope Code Injection Vulnerability

CVE ID :CVE-2026-51922
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :agentscope v1.0.20 contains code injection in execute_shell_command (src/agentscope/tool/_coding/_shell.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67989 - Ruby_llm Regular Expression Denial of Service

CVE ID :CVE-2026-67989
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-94483 - Next.js: Server-Side Request Forgery in Image Optimization

CVE ID :CVE-2026-94483
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, Image Optimization can follow attacker-controlled DNS resolution for a remote URL that matches images.remotePatterns, allowing the optimized image fetch to reach private IP addresses after the URL passes the allow-list check. Applications without images.remotePatterns are not affected. Administrators unable to upgrade should audit allow-listed hosts and avoid entries whose DNS records are not trusted. This issue is fixed in version 16.3.8.
Severity: 8.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-94484 - Next.js: Cache poisoning in Next.js SSG/ISR rendering leads to cross-user content substitution and persistent denial of service

CVE ID :CVE-2026-94484
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, applications with a root-level catch-all page and statically generated or Incremental Static Regeneration routes can use a shared response cache key that is insufficiently scoped to the source route. A single unauthenticated crafted request can poison that cache, causing cross-user content substitution or persistent denial of service until the poisoned entry is revalidated or replaced. This issue is fixed in versions 15.5.27 and 16.3.8.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-94485 - Next.js: Information disclosure in Next.js App Router metadata image routes via dynamicParams bypass

CVE ID :CVE-2026-94485
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the `next dev` development server exposes a Model Context Protocol endpoint without reliably restricting cross-site requests. A malicious website visited by a developer can reach the endpoint and read the project's disk location, source code snippets from error reports, route inventory, and development logs. Production deployments do not serve this endpoint. This issue is fixed in version 16.3.8.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-94486 - Next.js: Information disclosure in the Next.js development server's Model Context Protocol endpoint

CVE ID :CVE-2026-94486
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the next dev development server exposes a Model Context Protocol endpoint without reliably restricting cross-site requests. A malicious website visited by a developer can reach the endpoint and read the project's disk location, source code snippets from error reports, route inventory, and development logs. Production deployments do not serve this endpoint. This issue is fixed in version 16.3.8.
Severity: 2.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-94543 - Next.js: Cache poisoning of SSG and ISR pages in self-hosted Next.js applications

CVE ID :CVE-2026-94543
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated or Incremental Static Regeneration pages can key a response cache entry without sufficiently binding it to the source route. A request can replace one page's cache entry with content from a different route, causing the affected page to serve incorrect content to every visitor until revalidation. Applications deployed on Vercel are not affected. This issue is fixed in versions 15.5.27 and 16.3.8.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-94544 - Next.js: Pending `use cache` fill can leak Draft Mode content into regular responses and persisted pages

CVE ID :CVE-2026-94544
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :Next.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for the same key are shared without separating Draft Mode requests from regular requests. An overlapping regular request can receive unauthenticated unpublished content from an editor's Draft Mode fill, while an overlapping Draft Mode request can receive published content from a regular fill. When the regular request prerenders a page, the draft-dependent content can persist in the generated page and be served to later visitors until revalidation. Sites are affected when Cache Components or experimental.useCache is enabled and cached functions return draft-dependent content. This issue is fixed in version 16.3.8.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-96613 - Missing Authorization in Meari IoT Cloud Platform OpenAPI Service

CVE ID :CVE-2026-96613
Published : Oct. 2, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to access the complete device shadow of any device by specifying its device ID. This vulnerability exposes sensitive information, such as device credentials, owner details, network data, and telemetry, without verifying any relationship between the requester and the target device.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102626 - LimeSurvey Community Edition 7.4.0 - Stored XSS through the Date/Time date_min question attribute

CVE ID :CVE-2026-102626
Published : Oct. 2, 2026, 5:16 p.m. | 29 minutes ago
Description :An authenticated LimeSurvey Community Edition 7.4.0 user with the global Surveys: create permission can store a JavaScript-breaking value in the date_min attribute of a Date/Time question. When another user renders the affected question, LimeSurvey inserts the stored value into a single-quoted inline JavaScript literal without JavaScript-context encoding.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104848 - Tinypool: Prototype Pollution gadget in worker options leads to Remote Code Execution

CVE ID :CVE-2026-104848
Published : Oct. 2, 2026, 5:17 p.m. | 29 minutes ago
Description :Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.1, Tinypool constructs ThreadPool.options from a normal options object and reads the execArgv and env worker options in dist/index.js, allowing values inherited from a polluted Object.prototype to be copied into own properties and passed to worker_threads.Worker. An attacker who can first pollute either property can cause each newly spawned worker to load attacker-selected JavaScript through command-line preload arguments or NODE_OPTIONS, resulting in code execution with the host process's privileges and possible access to CI secrets, signing material, or build artifacts. This issue is fixed in version 2.1.1.
Severity: 9.5 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104849 - Tinypool: Prototype Pollution Gadget to RCE in run() options

CVE ID :CVE-2026-104849
Published : Oct. 2, 2026, 5:17 p.m. | 29 minutes ago
Description :Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from a caller-supplied options object in pool.run(task, options) without requiring an own property, so a polluted Object.prototype.filename can replace the intended worker module. Applications are affected only when they pass their own second-argument options object to pool.run(); calls without that argument use the trusted default options object. An attacker who can first pollute the prototype can cause the worker pool to load attacker-selected JavaScript and can read or modify task data with the host process's privileges. This issue is fixed in version 2.1.2.
Severity: 9.5 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...