Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, api_get_recording_stream in warpgate-admin/src/api/recordings_detail.rs protects /@warpgate/admin/api/recordings/{uuid}/stream only with session authentication and omits r
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58491 | 9.3 CRITICAL | Warpgate: Reflected XSS in SSO return endpoint via attacker-controlled next parameter |
| CVE-2026-91167 | 6.0 MEDIUM | Warpgate: Missing authorization check on `PUT /users/:id/roles/:role_id` allows any admin |
| CVE-2026-91166 | 5.7 MEDIUM | Warpgate: Web SSH stores a jump host's key against the target's address, so it validates a |
| CVE-2026-63329 | 4.9 MEDIUM | Warpgate: x-warpgate-username Header Not Stripped from Client Requests Enables Identity Sp |
| CVE-2026-91164 | 4.3 MEDIUM | Warpgate: API tokens bypass the user's allowed_ip_ranges restriction |
| CVE-2026-91165 | 2.4 LOW | Warpgate: Markup injection in SSO form_post return page via unencoded redirect/error value |
No comments yet