Michael White Frogman是Michael White个人开发者的一款通过 MCP 和 HTTP API 实现无头 PBX 控制的软件。 Michael White Frogman 1.6.2之前版本存在信任管理问题漏洞,该漏洞源于Frogman将API令牌以原始字符串形式存储,并通过比较存储原始值来验证X-Frogman-Token标头,可能允许数据库读取访问恢复可重用的活动令牌,达到其分配的权限级别,包括管理员权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-46512 | 9.9 CRITICAL | Frogman: Dialplan template parameters interpolated into extensions_custom.conf without esc |
| CVE-2026-46514 | 6.5 MEDIUM | Frogman: Plaintext passwords and secrets persisted to audit log |
| CVE-2026-46515 | Frogman: Multiple read-tier tools expose admin-grade data and arbitrary GraphQL execution |
No comments yet