Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

HKUDS — Vulnerabilities & Security Advisories 34

Browse all 34 CVE security advisories affecting HKUDS. AI-powered Chinese analysis, POCs, and references for each vulnerability.

HKUDS is a software platform primarily used for enterprise content management and document processing workflows. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, accounting for its 14 recorded CVEs. The platform's complex architecture and extensive integration capabilities have contributed to persistent security challenges, with several critical vulnerabilities allowing unauthorized system access and data exfiltration. While no major public security incidents have been widely documented, the consistent pattern of vulnerabilities in its web interface and API components remains a significant concern for organizations relying on this system for sensitive document handling.

CVE ID Title CVSS Severity Published
CVE-2026-19246 HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url server-side request forgery — nanobot CWE-918 6.3 Medium 2026-08-07
CVE-2026-19245 HKUDS nanobot Login-shell Environment shell.py ExecTool._prepare_command information disclosure — nanobot CWE-200 3.3 Low 2026-08-07
CVE-2026-19244 HKUDS nanobot MCP enabledTools Scope mcp.py connect_mcp_servers access control — nanobot CWE-284 4.7 Medium 2026-08-07
CVE-2026-61808 LightRAG: Missing Authentication for Critical API Functions in Default Configuration — LightRAG CWE-306 9.8 Critical 2026-08-07
CVE-2026-19243 HKUDS nanobot Shell Allowlist shell.py ExecTool._spawn os command injection — nanobot CWE-78 6.3 Medium 2026-08-07
CVE-2026-61740 LightRAG: Authentication bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection — LightRAG CWE-287 - - 2026-07-15
CVE-2026-61736 LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests — LightRAG CWE-942 9.3 Critical 2026-07-15
CVE-2026-58173 Vibe-Trading < 0.1.10 - Path Traversal via Persistent Memory Type — Vibe-Trading CWE-22 6.5 Medium 2026-06-30
CVE-2026-58171 Vibe-Trading < 0.1.10 - Path Traversal via Swarm Run Identifier — Vibe-Trading CWE-22 4.2 Medium 2026-06-30
CVE-2026-58170 Vibe-Trading < 0.1.10 - Path Traversal in Proposal Identifier Allows Forging Live Trading Mandates — Vibe-Trading CWE-22 8.3 High 2026-06-30
CVE-2026-58169 Vibe-Trading < 0.1.10 - Loopback Trust and Missing Host Validation Enable DNS-Rebinding Authentication Bypass and Remote Code Execution — Vibe-Trading CWE-346 7.5 High 2026-06-30
CVE-2026-58168 DeepTutor < 1.4.10 - Insecure Default Grants Unrestricted MCP Tool Access to Non-Admin Users — DeepTutor CWE-862 8.8 High 2026-06-30
CVE-2026-56696 OpenHarness - Prompt Injection via /issue and /pr_comments Slash Commands — OpenHarness CWE-862 5.4 Medium 2026-06-23
CVE-2026-56695 OpenHarness - Cross-Session Disclosure via /resume and /summary Commands — OpenHarness CWE-862 6.5 Medium 2026-06-23
CVE-2026-48716 nanobot: Path traversal via unsanitized WhatsApp document fileName enables arbitrary file write — nanobot CWE-22 8.7 High 2026-06-18
CVE-2026-12203 HKUDS AI-Trader Research Export agents.csv information disclosure — AI-Trader CWE-200 5.3 Medium 2026-06-15
CVE-2026-49140 Nanobot < 0.2.1 Denial of Service via Matrix Media Download Handler — nanobot CWE-770 4.3 Medium 2026-06-01
CVE-2026-49139 Nanobot < 0.2.1 SSRF via Microsoft Teams Channel serviceUrl Poisoning — nanobot CWE-918 7.0 High 2026-06-01
CVE-2026-49138 Nanobot < 0.2.1 SSRF via web_fetch Tool Redirect Following — nanobot CWE-918 5.0 Medium 2026-06-01
CVE-2026-32847 DeepCode 1.2.0 Path Traversal via SPA Catch-All Route in main.py — DeepCode CWE-22 7.5 High 2026-05-28
CVE-2026-7551 HKUDS OpenHarness Remote Command Execution via /bridge Slash Command — OpenHarness CWE-78 8.8 High 2026-04-30
CVE-2026-6823 HKUDS OpenHarness Insecure Default Remote Channel Allowlist — OpenHarness CWE-276 8.2 High 2026-04-21
CVE-2026-6819 HKUDS OpenHarness Plugin Management Command Exposure — OpenHarness CWE-276 8.8 High 2026-04-21
CVE-2026-6729 HKUDS OpenHarness Session Key Collision Privilege Escalation — OpenHarness CWE-287 6.3 Medium 2026-04-20
CVE-2026-40516 OpenHarness SSRF via web_fetch and web_search — OpenHarness CWE-918 8.3 High 2026-04-17
CVE-2026-40515 OpenHarness Permission Bypass via grep and glob root argument — OpenHarness CWE-863 7.5 High 2026-04-17
CVE-2026-40502 OpenHarness Remote Administrative Command Injection via Gateway Handler — OpenHarness CWE-862 8.8 High 2026-04-16
CVE-2026-40503 OpenHarness Path Traversal Information Disclosure via /memory show — OpenHarness CWE-22 6.5 Medium 2026-04-16
CVE-2026-35589 nanobot: Cross-Site WebSocket Hijacking in WhatsApp Bridge (CVE-2026-2577 Fix Update) — nanobot CWE-1385 8.0 High 2026-04-14
CVE-2026-39413 LightRAG has a JWT Algorithm Confusion Vulnerability in LightRAG API — LightRAG CWE-347 4.2 Medium 2026-04-08

This page lists every published CVE security advisory associated with HKUDS. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.