PSIRT.COM

// psirt.com

Product Security Incident Response Team

Vulnerability intelligence and regulatory resources for security teams navigating NIS2, the Cyber Resilience Act, and coordinated disclosure.

View vulnerabilities  →

A server-side request forgery (SSRF) vulnerability was found in galaxy_ng, the Ansible Galaxy server plugin for Pulp. An authenticated user with namespace mana…

2026-08-25

A user who can read an existing remote VCS repository can replace its configured origin or supply an absolute VCS data URL.

2026-08-25

An authenticated user may initiate repository migration operations without required repository permissions, potentially causing information disclosure, unautho…

2026-08-25

MintyItanium Lost-Auction is an auction plugin for Minecraft. Prior to commit 88c920b05042929db334ba06d57f052b42d6b3f8, players can take items like barrier blo…

2026-08-25

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, is_path_within_directory() uses os.path.abspath() rather than os.path.realpath() for the wo…

2026-08-25

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, praisonai serve agents and praisonai serve unified parse --api-key but _create_agents_app()…

2026-08-25

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, JobSubmitRequest.validate_webhook_url() accepts webhook_url when resolution raises socket.g…

2026-08-25

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the Jobs API validate_webhook_url() path fails open on socket.gaierror and does not bind th…

2026-08-25

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream mcp_post handler creates a new _sessions entry for every initialize req…

2026-08-25

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, praisonai serve agents parses config["api_key"] but _create_agents_app() does not authentic…

2026-08-25

PraisonAI is a multi-agent teams system. From praisonai 4.6.34 until 4.6.58, praisonai serve agents accepts --api-key but _create_agents_app() does not authent…

2026-08-25

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the FileMemory constructor joins unsanitized user_id into self.user_path. A caller su…

2026-08-25

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, AgentServer exposes ServerConfig.auth_token but AgentServer._create_app does not chec…

2026-08-25

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream _validate_origin method accepts request_origin.startswith(allowed), so…

2026-08-25

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, ast_grep_rewrite lacks the @require_approval decorator used by sibling mutation tools…

2026-08-25

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, spider_tools._host_is_blocked() does not resolve ordinary hostnames before scrape_pag…

2026-08-25

When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possi…

2026-08-25

GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line…

2026-08-25

Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Sof…

2026-08-25

A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local attacker to perform arbitrary file creation or overwrite. By…

2026-08-25

NLTK before 3.10.0 Remote Code Execution via Unsafe Pickle Deserialization

2026-08-25GHSA-rhp5-r9x4-f5g2

NLTK before 3.10.3 SSRF Protection Bypass via Proxy

2026-08-25GHSA-6ww7-3frv-cqxh

NLTK before 3.10.3 Entity Expansion DoS via ElementTree

2026-08-25GHSA-97qj-x29f-37w7

NLTK before 3.10.3 Arbitrary Code Execution via Graphviz dot Binary

2026-08-25GHSA-6hwm-xvph-95vm

GitPython before 3.1.59 Arbitrary File Read via TagReference.create

2026-08-25GHSA-3wxw-xv34-2frg

GitPython before 3.1.59 Arbitrary File Read via Repo.blame()

2026-08-25GHSA-5xxx-qhh7-9287

GitPython before 3.1.59 Path Traversal via separate-git-dir

2026-08-25GHSA-8mcc-hrx5-hvxc

GitPython before 3.1.59 Remote Code Execution via Config Injection

2026-08-25GHSA-284h-m62q-gf8w

GitPython before 3.1.59 Local File Content Disclosure via .gitmodules

2026-08-25GHSA-7833-fr7j-v32q

Grav before 2.0.16 Information Disclosure via Twig Sandbox

2026-08-25GHSA-xjw5-q542-3vmr

Grav before 2.0.16 Information Disclosure via offsetGet

2026-08-25GHSA-3jhr-mxmx-38cx

Rocket.Chat Missing DDP Rate Limit on the sendForgotPasswordEmail Meteor Method

2026-08-25GHSA-7c6v-m68v-v73r

Grav CMS before 2.0.16 Origin Validation Bypass via Referer

2026-08-25GHSA-9ccq-2jfg-qw33

Grav CMS before 2.0.16 Timing Attack via verifyNonce

2026-08-25GHSA-38p6-h87p-r4cg

Grav CMS before 2.0.16 Information Disclosure via Twig Sandbox Bypass

2026-08-25GHSA-p597-crqc-m349

Grav CMS before 2.0.16 Path Traversal via media_directory

2026-08-25GHSA-47ch-6w46-6xm7

Grav CMS before 2.0.16 Symlink Following via createLockFile

2026-08-25GHSA-q8w8-6cq5-j4h2

Grav before 2.0.16 Path Traversal via MediaUploadTrait deleteFile

2026-08-25GHSA-jq29-c7v8-rg55

Grav Flex Objects 1.4.0 through 1.4.7 Authorization Bypass via Shortcode

2026-08-25GHSA-x929-528m-vx2m

Adminer before 5.4.3 CSRF Token Secret Recovery via XOR Masking

2026-08-25GHSA-33j4-hc95-pggg

KEV — Known Exploited Vulnerabilities CISA

Oracle — Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (comp…

Added 2026-08-24Due 2026-08-27

Synacor — A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp…

Added 2026-08-21Due 2026-08-24

TrueConf — A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.…

Added 2026-08-20Due 2026-08-23

TrueConf — A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.…

Added 2026-08-20Due 2026-09-03

MLflow — MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior…

Added 2026-08-19Due 2026-09-02

Microsoft — Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a…

Added 2026-08-18Due 2026-08-21

Broadcom — VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access…

Added 2026-08-18Due 2026-08-21

Apple — An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macO…

Added 2026-08-18Due 2026-08-21

Microsoft — Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

Added 2026-08-18Due 2026-08-21

Ray-Project — Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploite…

Added 2026-08-17Due 2026-08-20

Cisco — A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Softwa…

Added 2026-08-11Due 2026-08-14

Microsoft — Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loc…

Added 2026-08-11Due 2026-08-25

Metabase — Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint…

Added 2026-08-11Due 2026-08-14

Progress — OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated att…

Added 2026-08-07Due 2026-08-10

JetBrains — In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polli…

Added 2026-08-05Due 2026-08-08

The original full-disclosure vulnerability mailing list. Bugtraq has been the primary channel for publishing detailed vulnerability information and exploit techniques for over three decades.

Home of the Bugtraq ID (BID) vulnerability database - over 75,000 entries cross-referenced with CVEs, providing historical vulnerability intelligence dating back to 1999.

Coverage75,921 BIDs mapped

CommunityOpen Security

Join the security research community. Discuss vulnerabilities, share advisories, and collaborate on coordinated disclosure through the Bugtraq mailing lists.

Read the original on securityfocus.com ↗