Vulnerabilities

Recent vulnerabilities

Recent vulnerabilities from
Select from 81 available sources using the dropdown above.

OSV Homebrew 🍺 is not individually searchable yet β€” the search will cover the sources available on the search page.

OSV Homebrew 🍺

Recent vulnerabilities Β· 14139 entries
ID Description Published Updated
brew-mlx-lm-cve-2026-104851 fsspec: Server-Side Template Injection in ReferenceFileSystem leads to Remote Code Execution 2026-10-05T23:18:28Z 2026-10-05T23:18:28Z
brew-pnpm-ghsa-vx52-2968-3vc6 pnpm 11.0.0 before 11.11.0 Environment Variable Exfiltration via Proxy Settings 2026-09-02T09:40:48Z 2026-10-05T22:35:38Z
brew-pillow-cve-2026-55798 Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path 2026-08-13T17:28:20Z 2026-10-05T20:29:37Z
brew-mcp-atlassian-cve-2026-77274 MCP Atlassian: SSRF Protection Bypass 2026-10-05T19:49:40Z 2026-10-05T19:49:40Z
brew-mcp-atlassian-cve-2026-77272 MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler 2026-10-05T19:49:40Z 2026-10-05T19:49:40Z
brew-mcp-atlassian-cve-2026-77271 MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (bypass of CVE-2026-27825) 2026-10-05T19:49:40Z 2026-10-05T19:49:40Z
brew-mcp-atlassian-cve-2026-77270 MCP Atlassian: Arbitrary File Read via Upload Attachment Tools 2026-10-05T19:49:39Z 2026-10-05T19:49:39Z
brew-mcp-atlassian-cve-2026-77269 MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete fix for CVE-2026-27825) 2026-10-05T19:49:39Z 2026-10-05T19:49:39Z
brew-mcp-atlassian-cve-2026-77268 MCP Atlassian: Insecure File Permissions on OAuth Token Storage 2026-10-05T19:49:39Z 2026-10-05T19:49:39Z
brew-mcp-atlassian-cve-2026-77267 mcp-atlassian has an incomplete SSRF remediation 2026-10-05T19:49:39Z 2026-10-05T19:49:39Z
brew-mcp-atlassian-cve-2026-77266 MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call 2026-10-05T19:49:39Z 2026-10-05T19:49:39Z
brew-mcp-atlassian-cve-2026-77265 MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow 2026-10-05T19:49:39Z 2026-10-05T19:49:39Z
brew-mcp-atlassian-cve-2026-77262 MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of CVE-2026-27825) 2026-10-05T19:49:39Z 2026-10-05T19:49:39Z
brew-mcp-atlassian-cve-2026-77261 MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches 2026-10-05T19:49:39Z 2026-10-05T19:49:39Z
brew-mcp-atlassian-cve-2026-77260 MCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment (Confluence + Jira) 2026-10-05T19:49:39Z 2026-10-05T19:49:39Z
brew-mcp-atlassian-cve-2026-77259 MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials 2026-10-05T19:49:39Z 2026-10-05T19:49:39Z
brew-mcp-atlassian-cve-2026-77258 MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path() 2026-10-05T19:49:39Z 2026-10-05T19:49:39Z
brew-mcp-atlassian-cve-2026-77257 MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths 2026-10-05T19:49:39Z 2026-10-05T19:49:39Z
brew-mcp-atlassian-cve-2026-77255 MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue 2026-10-05T19:49:39Z 2026-10-05T19:49:39Z
brew-mcp-atlassian-cve-2026-77253 MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files 2026-10-05T19:49:39Z 2026-10-05T19:49:39Z
brew-mcp-atlassian-cve-2026-77251 MCP Atlassian: JIRA_PROJECTS_FILTER / CONFLUENCE_SPACES_FILTER allow forbidden-project content exfiltration (one LIVE-proven on Atlassian Cloud) 2026-10-05T19:49:39Z 2026-10-05T19:49:39Z
brew-mcp-atlassian-cve-2026-77250 MCP Atlassian: OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissions 2026-10-05T19:49:39Z 2026-10-05T19:49:39Z
brew-mcp-atlassian-cve-2026-77249 MCP Atlassian: Incomplete fix for CVE-2026-27826: redirect-based SSRF via unhooked requests session in Jira user-permission lookup 2026-10-05T19:49:39Z 2026-10-05T19:49:39Z
brew-mcp-atlassian-cve-2026-77248 MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport 2026-10-05T19:49:39Z 2026-10-05T19:49:39Z
brew-mcp-atlassian-cve-2026-77247 MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters 2026-10-05T19:49:39Z 2026-10-05T19:49:39Z
brew-mcp-atlassian-cve-2026-77246 MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path 2026-10-05T19:49:39Z 2026-10-05T19:49:39Z
brew-mcp-atlassian-cve-2026-77244 [mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token 2026-10-05T19:49:39Z 2026-10-05T19:49:39Z
brew-mcp-atlassian-cve-2026-77243 MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass 2026-10-05T19:49:39Z 2026-10-05T19:49:39Z
brew-mcp-atlassian-ghsa-wm45-qh3g-v83f MCP Atlassian: Arbitrary server-side file read via attachment upload 2026-08-13T17:13:13Z 2026-10-05T19:48:04Z
brew-mcp-atlassian-ghsa-489g-7rxv-6c8q MCP Atlassian is a Model Context Protocol (MCP): DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826): unauthenticated SSRF to cloud metadata 2026-08-13T17:13:13Z 2026-10-05T19:48:04Z