| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-55582 🧪 | mcp-shell: Secure Mode Allowlist Bypass via Git Shell Alias | sonirico | mcp-shell | High | 8.4 | 2026-08-25 15:37:43 | Deep Dive |
| CVE-2026-55546 🧪 | QWED-MCP: Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input | QWED-AI | qwed-mcp | Critical | 9.8 | 2026-08-25 15:25:35 | Deep Dive |
| CVE-2026-70550 | Potential unauthorized access to private Composer repository metadata in JFrog Artifactory | jfrog | artifactory | Medium | 6.5 | 2026-08-25 15:22:53 | Deep Dive |
| CVE-2026-55536 🧪 | Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92) | MervinPraison | PraisonAI | Critical | 9.1 | 2026-08-25 15:21:53 | Deep Dive |
| CVE-2026-55532 🧪 | PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server | MervinPraison | PraisonAI | High | 7.6 | 2026-08-25 15:17:53 | Deep Dive |
| CVE-2026-70548 | SSRF In CocoaPods Via JFrog Artifactory External Dependency | jfrog | artifactory | Low | 3.5 | 2026-08-25 15:17:17 | Deep Dive |
| CVE-2026-79783 | rclone before 1.74.4 Privilege Escalation via setuid Metadata | rclone | rclone | Low | 3.6 | 2026-08-25 15:16:12 | Deep Dive |
| CVE-2026-79784 🧪 | Vocos through 0.1.0 Arbitrary Code Execution via Unrestricted class_path in Model Configuration | gemelo-ai | vocos | High | 8.8 | 2026-08-25 15:16:12 | Deep Dive |
| CVE-2026-79782 | rclone before 1.74.4 Security Token Disclosure via HTTPS to HTTP Redirect | rclone | rclone | Low | 3.1 | 2026-08-25 15:16:11 | Deep Dive |
| CVE-2026-79780 | rclone before v1.75.0 Credential Exposure via S3 Redirect | rclone | rclone | Medium | 5.3 | 2026-08-25 15:16:10 | Deep Dive |
| CVE-2026-79781 | rclone serve s3 Path Traversal via dot-dot object keys | rclone | rclone | Medium | 6.5 | 2026-08-25 15:16:10 | Deep Dive |
| CVE-2026-79779 | rclone before v1.75.0 WebDAV Credential Exposure via HTTPS-to-HTTP Redirect | rclone | rclone | Medium | 5.3 | 2026-08-25 15:16:09 | Deep Dive |
| CVE-2026-79777 | rclone before v1.75.0 Information Disclosure via RC API | rclone | rclone | Low | 2.7 | 2026-08-25 15:16:08 | Deep Dive |
| CVE-2026-79778 | rclone before v1.75.0 Denial of Service via TUS nil-response panic | rclone | rclone | Medium | 5.3 | 2026-08-25 15:16:08 | Deep Dive |
| CVE-2026-79776 | rclone before 1.75.0 Authentication Bypass via pprof | rclone | rclone | Medium | 5.3 | 2026-08-25 15:16:07 | Deep Dive |
| CVE-2026-79775 | rclone Archive Backend SquashFS Parser Denial of Service | rclone | rclone | Medium | 6.5 | 2026-08-25 15:16:06 | Deep Dive |
| CVE-2026-79774 🧪 | Winter CMS before 1.2.13 Twig Sandbox Escape via SecurityPolicy | wintercms | winter | High | 8.4 | 2026-08-25 15:16:06 | Deep Dive |
| CVE-2026-79773 | Winter CMS before 1.2.13 Local File Inclusion via JavaScript | wintercms | winter | Medium | 4.9 | 2026-08-25 15:16:05 | Deep Dive |
| CVE-2026-79771 | Nokogiri before 1.19.3 Memory Leak via XSLT Transform | sparklemotion | nokogiri | Medium | 5.3 | 2026-08-25 15:16:04 | Deep Dive |
| CVE-2026-79772 | Nokogiri before 1.19.1 Unchecked Return Value canonicalize | sparklemotion | nokogiri | Medium | 5.3 | 2026-08-25 15:16:04 | Deep Dive |