eidetic-labs stigmem是eidetic-labs组织的一款威胁情报网络产品。 eidetic-labs stigmem 0.9.0a11之前版本存在服务端请求伪造漏洞,该漏洞源于未验证delivery_address参数,可能导致认证用户指定内部回环和私有网络目标,攻击者通过触发事实变更事件使服务器向内部服务发起HTTP POST请求,从而对localhost和私有网络端点进行盲SSRF攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| eidetic-labs | stigmem-node | < 0.9.0a11 |
affected |
0.9.0a11 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| eidetic-labs | stigmem-node | 0 ~ 0.9.0a11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-76243 | 9.2 CRITICAL | stigmem before 0.9.0a2 Authentication Bypass via Disabled Auth |
| CVE-2026-76242 | 9.1 CRITICAL | stigmem Federation Peer Registration Authentication Bypass |
| CVE-2026-76244 | 9.1 CRITICAL | stigmem-node Insecure Federation Transport Configuration |
| CVE-2026-76237 | 8.6 HIGH | stigmem before 0.9.0a12 Cross-Tenant BOLA via quarantine |
| CVE-2026-76240 | 7.5 HIGH | stigmem Postgres SQL Injection via Schema Identifier |
| CVE-2026-76241 | 7.3 HIGH | stigmem Plugin Signature Enforcement Bypass via Configuration |
| CVE-2026-76238 | 7.2 HIGH | stigmem before 0.9.0a12 Cross-Tenant BOLA via decay sweep |
| CVE-2026-76236 | 7.2 HIGH | stigmem before 0.9.0a12 Cross-Tenant BOLA via Tombstones |
| CVE-2026-76245 | 7.1 HIGH | stigmem Federation Peer Token Timestamp Validation Bypass |
No comments yet