Vulnerabilities
Recent vulnerabilities
Recent vulnerabilities from
Select from 81 available sources using the dropdown above.
OSV Homebrew πΊ is not individually searchable yet β the search will cover the sources available on the search page.
| ID | Description | Published | Updated |
|---|---|---|---|
| brew-mlx-lm-cve-2026-104851 | fsspec: Server-Side Template Injection in ReferenceFileSystem leads to Remote Code Execution | 2026-10-05T23:18:28Z | 2026-10-05T23:18:28Z |
| brew-pnpm-ghsa-vx52-2968-3vc6 | pnpm 11.0.0 before 11.11.0 Environment Variable Exfiltration via Proxy Settings | 2026-09-02T09:40:48Z | 2026-10-05T22:35:38Z |
| brew-pillow-cve-2026-55798 | Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path | 2026-08-13T17:28:20Z | 2026-10-05T20:29:37Z |
| brew-mcp-atlassian-cve-2026-77274 | MCP Atlassian: SSRF Protection Bypass | 2026-10-05T19:49:40Z | 2026-10-05T19:49:40Z |
| brew-mcp-atlassian-cve-2026-77272 | MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler | 2026-10-05T19:49:40Z | 2026-10-05T19:49:40Z |
| brew-mcp-atlassian-cve-2026-77271 | MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (bypass of CVE-2026-27825) | 2026-10-05T19:49:40Z | 2026-10-05T19:49:40Z |
| brew-mcp-atlassian-cve-2026-77270 | MCP Atlassian: Arbitrary File Read via Upload Attachment Tools | 2026-10-05T19:49:39Z | 2026-10-05T19:49:39Z |
| brew-mcp-atlassian-cve-2026-77269 | MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete fix for CVE-2026-27825) | 2026-10-05T19:49:39Z | 2026-10-05T19:49:39Z |
| brew-mcp-atlassian-cve-2026-77268 | MCP Atlassian: Insecure File Permissions on OAuth Token Storage | 2026-10-05T19:49:39Z | 2026-10-05T19:49:39Z |
| brew-mcp-atlassian-cve-2026-77267 | mcp-atlassian has an incomplete SSRF remediation | 2026-10-05T19:49:39Z | 2026-10-05T19:49:39Z |
| brew-mcp-atlassian-cve-2026-77266 | MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call | 2026-10-05T19:49:39Z | 2026-10-05T19:49:39Z |
| brew-mcp-atlassian-cve-2026-77265 | MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow | 2026-10-05T19:49:39Z | 2026-10-05T19:49:39Z |
| brew-mcp-atlassian-cve-2026-77262 | MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of CVE-2026-27825) | 2026-10-05T19:49:39Z | 2026-10-05T19:49:39Z |
| brew-mcp-atlassian-cve-2026-77261 | MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches | 2026-10-05T19:49:39Z | 2026-10-05T19:49:39Z |
| brew-mcp-atlassian-cve-2026-77260 | MCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment (Confluence + Jira) | 2026-10-05T19:49:39Z | 2026-10-05T19:49:39Z |
| brew-mcp-atlassian-cve-2026-77259 | MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials | 2026-10-05T19:49:39Z | 2026-10-05T19:49:39Z |
| brew-mcp-atlassian-cve-2026-77258 | MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path() | 2026-10-05T19:49:39Z | 2026-10-05T19:49:39Z |
| brew-mcp-atlassian-cve-2026-77257 | MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths | 2026-10-05T19:49:39Z | 2026-10-05T19:49:39Z |
| brew-mcp-atlassian-cve-2026-77255 | MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue | 2026-10-05T19:49:39Z | 2026-10-05T19:49:39Z |
| brew-mcp-atlassian-cve-2026-77253 | MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files | 2026-10-05T19:49:39Z | 2026-10-05T19:49:39Z |
| brew-mcp-atlassian-cve-2026-77251 | MCP Atlassian: JIRA_PROJECTS_FILTER / CONFLUENCE_SPACES_FILTER allow forbidden-project content exfiltration (one LIVE-proven on Atlassian Cloud) | 2026-10-05T19:49:39Z | 2026-10-05T19:49:39Z |
| brew-mcp-atlassian-cve-2026-77250 | MCP Atlassian: OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissions | 2026-10-05T19:49:39Z | 2026-10-05T19:49:39Z |
| brew-mcp-atlassian-cve-2026-77249 | MCP Atlassian: Incomplete fix for CVE-2026-27826: redirect-based SSRF via unhooked requests session in Jira user-permission lookup | 2026-10-05T19:49:39Z | 2026-10-05T19:49:39Z |
| brew-mcp-atlassian-cve-2026-77248 | MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport | 2026-10-05T19:49:39Z | 2026-10-05T19:49:39Z |
| brew-mcp-atlassian-cve-2026-77247 | MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters | 2026-10-05T19:49:39Z | 2026-10-05T19:49:39Z |
| brew-mcp-atlassian-cve-2026-77246 | MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path | 2026-10-05T19:49:39Z | 2026-10-05T19:49:39Z |
| brew-mcp-atlassian-cve-2026-77244 | [mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token | 2026-10-05T19:49:39Z | 2026-10-05T19:49:39Z |
| brew-mcp-atlassian-cve-2026-77243 | MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass | 2026-10-05T19:49:39Z | 2026-10-05T19:49:39Z |
| brew-mcp-atlassian-ghsa-wm45-qh3g-v83f | MCP Atlassian: Arbitrary server-side file read via attachment upload | 2026-08-13T17:13:13Z | 2026-10-05T19:48:04Z |
| brew-mcp-atlassian-ghsa-489g-7rxv-6c8q | MCP Atlassian is a Model Context Protocol (MCP): DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826): unauthenticated SSRF to cloud metadata | 2026-08-13T17:13:13Z | 2026-10-05T19:48:04Z |