All 5 CVE vulnerabilities found in DIRAC, with AI-generated Chinese analysis, references, and POCs.
Vendor: DIRACGrid
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-61668 | DIRAC: Pilot code downloaded over unverified HTTPS connection CWE-295 | 8.1 | High | 2026-09-15 |
| CVE-2026-61667 | DIRAC: RCE in FileCatalog DatasetManager via SQL injection + eval CWE-89 | 9.9 | Critical | 2026-09-15 |
| CVE-2026-45579 | DIRAC: RCE in RequestManager due to eval on untrusted input CWE-95 | 9.9 | Critical | 2026-09-15 |
| CVE-2024-29905 | DIRAC: Unauthorized users can read proxy contents during generation CWE-668 | 8.1 | High | 2024-04-09 |
| CVE-2024-24825 | TokenManager not checking permissions on cached tokens in DIRAC CWE-200 | 9.1 | Critical | 2024-02-08 |
All 5 known CVE vulnerabilities affecting DIRAC with full Chinese analysis, references, and POCs where available.