<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 17:05:05 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-48797 — Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-48797</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; mcp-tool-shop-org backpropagate, mcp-tool-shop-org @mcptoolshop/backpropagate&lt;/p&gt;
&lt;p&gt;Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, the optional Reflex web UI exposes a training control plane without authentication: dataset upload, model load, training start/stop, multi-run orchestration, GGUF export, and HuggingFace Hub push. The CLI accepts two operator-facing flags intended as security controls: --auth user:pass — documented as &amp;#34;require HTTP Basic authentication on every request to the UI.&amp;#34; and--share — documented as &amp;#34;expose the UI on a public address; requires --auth.&amp;#34; When --auth user:pass is passed, the CLI prints Auth: enabled (user: &amp;lt;username&amp;gt;) to confirm to the operator that authentication is active, then exports BACKPROPAGATE_UI_AUTH=user:pass to the subprocess that launches the Reflex backend. The Reflex backend (backpropagate/ui_app/**) never reads BACKPROPAGATE_UI_AUTH. No authentication middleware is registered. No request-level guard runs. No WebSocket upgrade guard runs. Any client that reaches the bound port — local or remote, depending on whether --share is used — has full UI access. An inline comment at backpropagate/cli.py:1217-1218 in the v1.1.0 source documents the gap: &amp;#34;For Phase 1 the variable is exported but Reflex doesn&amp;#39;t read it yet.&amp;#34; This comment was internal-facing; the user-facing documentation (README, CHANGELOG, SHIP_GATE) advertised the contract as enforced. An attacker who reaches the bound port can read uploaded datasets, trigger arbitrary training runs…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; mcp-tool-shop-org backpropagate, mcp-tool-shop-org @mcptoolshop/backpropagate&lt;/p&gt;
&lt;p&gt;Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, the optional Reflex web UI exposes a training control plane without authentication: dataset upload, model load, training start/stop, multi-run orchestration, GGUF export, and HuggingFace Hub push. The CLI accepts two operator-facing flags intended as security controls: --auth user:pass — documented as &amp;#34;require HTTP Basic authentication on every request to the UI.&amp;#34; and--share — documented as &amp;#34;expose the UI on a public address; requires --auth.&amp;#34; When --auth user:pass is passed, the CLI prints Auth: enabled (user: &amp;lt;username&amp;gt;) to confirm to the operator that authentication is active, then exports BACKPROPAGATE_UI_AUTH=user:pass to the subprocess that launches the Reflex backend. The Reflex backend (backpropagate/ui_app/**) never reads BACKPROPAGATE_UI_AUTH. No authentication middleware is registered. No request-level guard runs. No WebSocket upgrade guard runs. Any client that reaches the bound port — local or remote, depending on whether --share is used — has full UI access. An inline comment at backpropagate/cli.py:1217-1218 in the v1.1.0 source documents the gap: &amp;#34;For Phase 1 the variable is exported but Reflex doesn&amp;#39;t read it yet.&amp;#34; This comment was internal-facing; the user-facing documentation (README, CHANGELOG, SHIP_GATE) advertised the contract as enforced. An attacker who reaches the bound port can read uploaded datasets, trigger arbitrary training runs…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-48797</guid>
    </item>
    <item>
      <title>GHSA-f65r-h4g3-3h9h — Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f65r-h4g3-3h9h</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: backpropagate, npm: @mcptoolshop/backpropagate&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;In `backpropagate &amp;gt;= 1.1.0`, the optional Reflex web UI (`pip install backpropagate[ui]`, launched via `backprop ui`) exposes a training control plane: dataset upload, model load, training start/stop, multi-run orchestration, GGUF export, and HuggingFace Hub push.&lt;/p&gt;
&lt;p&gt;The CLI accepts two operator-facing flags intended as security controls:&lt;/p&gt;
&lt;p&gt;- `--auth user:pass` — documented as &amp;#34;require HTTP Basic authentication on every request to the UI.&amp;#34;
- `--share` — documented as &amp;#34;expose the UI on a public address; requires `--auth`.&amp;#34;&lt;/p&gt;
&lt;p&gt;When `--auth user:pass` is passed, the CLI prints `Auth: enabled (user: &amp;lt;username&amp;gt;)` to confirm to the operator that authentication is active, then exports `BACKPROPAGATE_UI_AUTH=user:pass` to the subprocess that launches the Reflex backend.&lt;/p&gt;
&lt;p&gt;**The Reflex backend (`backpropagate/ui_app/**`) never reads `BACKPROPAGATE_UI_AUTH`.** No authentication middleware is registered. No request-level guard runs. No WebSocket upgrade guard runs. Any client that reaches the bound port — local or remote, depending on whether `--share` is used — has full UI access.&lt;/p&gt;
&lt;p&gt;An inline comment at `backpropagate/cli.py:1217-1218` in the v1.1.0 source documents the gap: *&amp;#34;For Phase 1 the variable is exported but Reflex doesn&amp;#39;t read it yet.&amp;#34;* This comment was internal-facing; the user-facing documentation (README, CHANGELOG, SHIP_GATE) advertised the contract as enforced.&lt;/p&gt;
&lt;p&gt;This advisory is filed primarily because the runtime contradicted an operator-facing security claim. Cod…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: backpropagate, npm: @mcptoolshop/backpropagate&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;In `backpropagate &amp;gt;= 1.1.0`, the optional Reflex web UI (`pip install backpropagate[ui]`, launched via `backprop ui`) exposes a training control plane: dataset upload, model load, training start/stop, multi-run orchestration, GGUF export, and HuggingFace Hub push.&lt;/p&gt;
&lt;p&gt;The CLI accepts two operator-facing flags intended as security controls:&lt;/p&gt;
&lt;p&gt;- `--auth user:pass` — documented as &amp;#34;require HTTP Basic authentication on every request to the UI.&amp;#34;
- `--share` — documented as &amp;#34;expose the UI on a public address; requires `--auth`.&amp;#34;&lt;/p&gt;
&lt;p&gt;When `--auth user:pass` is passed, the CLI prints `Auth: enabled (user: &amp;lt;username&amp;gt;)` to confirm to the operator that authentication is active, then exports `BACKPROPAGATE_UI_AUTH=user:pass` to the subprocess that launches the Reflex backend.&lt;/p&gt;
&lt;p&gt;**The Reflex backend (`backpropagate/ui_app/**`) never reads `BACKPROPAGATE_UI_AUTH`.** No authentication middleware is registered. No request-level guard runs. No WebSocket upgrade guard runs. Any client that reaches the bound port — local or remote, depending on whether `--share` is used — has full UI access.&lt;/p&gt;
&lt;p&gt;An inline comment at `backpropagate/cli.py:1217-1218` in the v1.1.0 source documents the gap: *&amp;#34;For Phase 1 the variable is exported but Reflex doesn&amp;#39;t read it yet.&amp;#34;* This comment was internal-facing; the user-facing documentation (README, CHANGELOG, SHIP_GATE) advertised the contract as enforced.&lt;/p&gt;
&lt;p&gt;This advisory is filed primarily because the runtime contradicted an operator-facing security claim. Cod…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f65r-h4g3-3h9h</guid>
    </item>
  </channel>
</rss>
