| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-55537 🧪 | PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114 | MervinPraison | PraisonAI | High | 7.1 | 2026-08-25 14:58:50 | Deep Dive |
| CVE-2026-55538 🧪 | PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated | MervinPraison | PraisonAI | High | 7.3 | 2026-08-25 14:56:34 | Deep Dive |
| CVE-2026-55534 🧪 | PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution | MervinPraison | PraisonAI | High | 8.6 | 2026-08-25 14:41:14 | Deep Dive |
| CVE-2026-55526 🧪 | PraisonAI: SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`) | MervinPraison | PraisonAI | High | 8.5 | 2026-08-25 14:36:10 | Deep Dive |
| CVE-2026-55528 🧪 | praisonaiagents: AgentServer declares auth_token but never enforces it on any route (CWE-862) | MervinPraison | PraisonAI | High | 8.2 | 2026-08-25 14:32:06 | Deep Dive |
| CVE-2026-55525 🧪 | PraisonAI: SSRF via redirect-following in praisonaiagents web_crawl | MervinPraison | PraisonAI | High | 7.5 | 2026-08-25 14:07:09 | Deep Dive |
| CVE-2026-79655 🧪 | Sos: sos: path traversal in sos clean tar extraction via unvalidated symlink/hardlink targets leads to arbitrary file write | Red Hat | Red Hat Enterprise Linux 10 | High | 7.8 | 2026-08-25 13:49:38 | Deep Dive |
| CVE-2026-79622 🧪 | dekdee adobe-xd-mcp file-access-from-request Endpoint xd-parser.ts path traversal | dekdee | adobe-xd-mcp | High | 7.3 | 2026-08-25 13:15:09 | Deep Dive |
| CVE-2026-79667 🧪 | Ech0 before 4.4.3 Authentication Bypass via Scope Enforcement | lin-snow | Ech0 | High | 7.6 | 2026-08-25 11:33:29 | Deep Dive |
| CVE-2026-79665 🧪 | Ech0 before 4.5.1 Authorization Bypass via Session Tokens | lin-snow | Ech0 | High | 8.8 | 2026-08-25 11:33:28 | Deep Dive |
| CVE-2026-79664 🧪 | Ech0 before 4.7.3 Access Token Revocation Bypass | lin-snow | Ech0 | High | 7.4 | 2026-08-25 11:33:27 | Deep Dive |
| CVE-2026-79662 🧪 | Ech0 before 4.7.3 OAuth Redirect URI Validation Bypass | lin-snow | Ech0 | High | 8.0 | 2026-08-25 11:33:26 | Deep Dive |
| CVE-2026-79659 🧪 | Ech0 before 4.7.3 Server-Side Request Forgery via fetchPeerConnectInfo | lin-snow | Ech0 | High | 7.7 | 2026-08-25 11:33:24 | Deep Dive |
| CVE-2026-79658 🧪 | Ech0 before 5.0.1 Denial of Service via Accept-Language | lin-snow | Ech0 | High | 7.5 | 2026-08-25 11:33:23 | Deep Dive |
| CVE-2026-79657 🧪 | NLTK before 3.10.3 Remote Code Execution via Unsafe Pickle Deserialization | nltk | nltk | Critical | 9.8 | 2026-08-25 11:33:23 | Deep Dive |
| CVE-2026-19949 🧪 | All-in-One WP Migration and Backup <= 7.109 - Unauthenticated Second-Order SQL Injection via Archive Restore to Remote Code Execution | servmask | All-in-One WP Migration and Backup | High | 8.8 | 2026-08-25 11:27:11 | Deep Dive |
| CVE-2026-16231 🧪 | hbs vulnerable to XSS via registerAsyncHelper output-escaping bypass | hbs | hbs | High | 8.1 | 2026-08-25 10:00:10 | Deep Dive |
| CVE-2026-75037 🧪 | Polkit authentication bypass in LACT | ilya-zlobintsev | LACT | High | 7.0 | 2026-08-25 09:52:33 | Deep Dive |
| CVE-2026-65633 🧪 | Purpose-limited JWT accepted as full bearer authentication in AshAuthentication | team-alembic | ash_authentication | High | 7.6 | 2026-08-25 08:03:52 | Deep Dive |
| CVE-2026-78654 🧪 | cleverbrush framework/deep deepExtend.ts deepExtend prototype pollution | cleverbrush | framework | High | 7.3 | 2026-08-25 06:00:13 | Deep Dive |