<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T03:09:40.536199+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-328614</id>
    <title>EUVD-2026-328614</title>
    <updated>2026-10-06T03:09:40.581514+00:00</updated>
    <content>EUVD-2026-328614</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-328614"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48814</id>
    <title>fkie_cve-2026-48814</title>
    <updated>2026-10-06T03:09:40.581550+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows unauthenticated cross-origin MCP tool invocation due to an empty default secret. This issue was partially addressed by CVE-2026-46701 in version 5.4.5 by closing the CORS flaw (with Access-Control-Allow-Origin now set only for localhost origins), but the empty-default-secret flaw described in the title remained: the SSE MCP server still defaulted to an empty secret, _isAuthorized() still returned true when the secret was empty, and a non-loopback bind only produced a warning. As a result, the server still ran fully unauthenticated by default. Any non-browser caller (for example, curl, SSRF, or a 0.0.0.0 bind) could invoke all 22 MCP tools (config_set, agent_spawn, blackboard_write, token_*) with no credentials. This issue was fixed in version 5.7.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-48814"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r78r-rwrf-rjwp</id>
    <title>GHSA-r78r-rwrf-rjwp — Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests</title>
    <updated>2026-10-06T03:09:40.581587+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: network-ai</p>
<p>## Advisory / Disclosure</p>
<p># Network-AI — CVE-2026-46701 fix is incomplete: the "Empty Default Secret" unauth path survives</p>
<p>**Target:** Jovancoding/Network-AI (npm `network-ai`), **latest v5.7.1**
**Status:** the advisory ("Unauthenticated Cross-Origin MCP Tool Invocation via Empty
Default Secret") named three flaws. The fix (5.4.5) closed the **CORS** flaw
(`Access-Control-Allow-Origin` is now set only for localhost origins), but left the
**empty-default-secret** flaw the title is about: the SSE MCP server still defaults to an
empty secret, `_isAuthorized()` still returns `true` when the secret is empty, and a
non-loopback bind only **warns**. So the server still runs **fully unauthenticated by
default** — any non-browser caller (curl, SSRF, or a `0.0.0.0` bind) can invoke all 22 MCP
tools (`config_set`, `agent_spawn`, `blackboard_write`, `token_*`) with no credentials.
**Class:** CWE-306/CWE-862 Missing Authentication — incomplete fix.
**Methodology:** M1 incomplete-fix audit (anchor = the 5.4.5 fix; sibling-walk on latest v5.7.1, executed).
**Severity:** High (matches parent; the browser amplifier is removed, so exploitation now
needs non-browser reach — SSRF or a non-loopback bind, which the fix only warns about).</p>
<p>## What the fix did and didn't do (verified on latest v5.7.1)
| advisory flaw | latest v5.7.1 |
|---|---|
| wildcard CORS (`ACAO: *`) | **FIXED** — `lib/mcp-transport-sse.ts` sets `ACAO` only when `origin` matches `^https?://(localhost\|127\.0\.0\.1)(:\d+)?$`…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r78r-rwrf-rjwp"/>
  </entry>
</feed>
