coral-server是CoralOS开源的一个基于Docker的服务器运行与配置管理工具。 coral-server 1.1.0之前版本存在安全漏洞,该漏洞源于未在活动会话中强制进行强身份验证,可能导致攻击者通过获取或预测会话标识符来冒充代理或加入现有会话。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Coral-Protocol | coral-server | < 1.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-30968 | Coral Server has insufficient validation of agent identity for SSE connections | |
| CVE-2026-30970 | Session authentication bypass in Coral Server session creation endpoint |
No comments yet