| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-55527 🧪 | PraisonAI: Arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location | MervinPraison | PraisonAI | High | 7.1 | 2026-08-25 15:09:08 | Deep Dive |
| CVE-2026-15310 | zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits | Python Software Foundation | CPython | Low | 2.1 | 2026-08-25 15:07:58 | Deep Dive |
| CVE-2026-70551 | Server-Side Request Forgery Via VCS remote download in JFrog Artifactory | jfrog | artifactory | High | 8.5 | 2026-08-25 15:06:48 | Deep Dive |
| CVE-2026-55541 🧪 | PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced | MervinPraison | PraisonAI | High | 8.8 | 2026-08-25 15:05:25 | Deep Dive |
| CVE-2026-55535 | PraisonAI: Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation | MervinPraison | PraisonAI | Medium | 6.8 | 2026-08-25 15:01:48 | Deep Dive |
| CVE-2026-55537 🧪 | PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114 | MervinPraison | PraisonAI | High | 7.1 | 2026-08-25 14:58:50 | Deep Dive |
| CVE-2026-55538 🧪 | PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated | MervinPraison | PraisonAI | High | 7.3 | 2026-08-25 14:56:34 | Deep Dive |
| CVE-2026-55624 | MintyItanium Lost-Auction takes items like barrier blocks out from search GUI | MintyItanium | Lost-Auction | Medium | 5.3 | 2026-08-25 14:56:11 | Deep Dive |
| CVE-2026-55540 | PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks | MervinPraison | PraisonAI | High | 7.1 | 2026-08-25 14:54:32 | Deep Dive |
| CVE-2026-79717 | Galaxy_ng: galaxy_ng: blind ssrf via namespace avatar_url with no private-address restriction | Red Hat | Red Hat Ansible Automation Platform 2 | Medium | 6.4 | 2026-08-25 14:53:45 | Deep Dive |
| CVE-2026-55530 | PraisonAI: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool | MervinPraison | PraisonAI | Medium | 6.1 | 2026-08-25 14:45:08 | Deep Dive |
| CVE-2026-55534 🧪 | PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution | MervinPraison | PraisonAI | High | 8.6 | 2026-08-25 14:41:14 | Deep Dive |
| CVE-2026-55526 🧪 | PraisonAI: SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`) | MervinPraison | PraisonAI | High | 8.5 | 2026-08-25 14:36:10 | Deep Dive |
| CVE-2026-55531 | PraisonAI: Unauthenticated unbounded session accumulation in the PraisonAI MCP HTTP server (memory exhaustion; session TTL never enforced) | MervinPraison | PraisonAI | Medium | 6.5 | 2026-08-25 14:33:52 | Deep Dive |
| CVE-2026-55528 🧪 | praisonaiagents: AgentServer declares auth_token but never enforces it on any route (CWE-862) | MervinPraison | PraisonAI | High | 8.2 | 2026-08-25 14:32:06 | Deep Dive |
| CVE-2026-55529 | PraisonAI: Origin validation bypass in MCP HTTP Stream transport allows browser-mediated unauthenticated tool execution on local MCP server | MervinPraison | PraisonAI | Medium | 6.9 | 2026-08-25 14:26:31 | Deep Dive |
| CVE-2026-16286 | File Upload in TRTEK Software's Software Repository Management | TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company | Software Repository Management | Critical | 9.8 | 2026-08-25 14:26:20 | Deep Dive |
| CVE-2026-16599 | Denial of Service in GNU wget | GNU | wget | Medium | 5.1 | 2026-08-25 14:17:05 | Deep Dive |
| CVE-2026-55525 🧪 | PraisonAI: SSRF via redirect-following in praisonaiagents web_crawl | MervinPraison | PraisonAI | High | 7.5 | 2026-08-25 14:07:09 | Deep Dive |
| CVE-2026-79655 🧪 | Sos: sos: path traversal in sos clean tar extraction via unvalidated symlink/hardlink targets leads to arbitrary file write | Red Hat | Red Hat Enterprise Linux 10 | High | 7.8 | 2026-08-25 13:49:38 | Deep Dive |