coral-server是CoralOS开源的一个基于Docker的服务器运行与配置管理工具。 coral-server 1.1.0之前版本存在安全漏洞,该漏洞源于/api/v1/sessions端点允许在没有强身份验证的情况下创建代理会话,可能导致未经授权的会话创建或系统资源消耗。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Coral-Protocol | coral-server | < 1.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-30968 | Coral Server has insufficient validation of agent identity for SSE connections | |
| CVE-2026-30969 | Coral Server has insufficient agent authentication in session communication channels |
No comments yet