Search
Find a vulnerability
Search criteria
20709 vulnerabilities
CVE-2026-96780 (GCVE-0-2026-96780)
Vulnerability from cvelistv5 – Published: 2026-10-01 20:21 – Updated: 2026-10-01 20:40
VLAI
EPSS
VEX
Title
figlet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used with a small width
Summary
figlet.js is a FIG driver written in JavaScript that aims to implement the FIGfont specification. Prior to 1.11.3, text() and textSync() can enter an unbounded loop when whitespaceBreak is enabled and width is smaller than the rendered width of a single FIGlet character. Under these conditions, breakWord() cannot find a valid break point and returns without consuming a character, so generateFigTextLines() repeatedly processes the same input while consuming CPU and growing memory. The non-default option and attacker-controlled width must both reach an affected call. This issue is fixed in version 1.11.3.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 20:40 UTC
CWE
- CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/patorjk/figlet.js/security/adv… | x_refsource_CONFIRM |
| https://github.com/patorjk/figlet.js/pull/169 | x_refsource_MISC |
| https://github.com/patorjk/figlet.js/commit/cb283… | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-96780",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T20:40:21.395217Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T20:40:30.208Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "figlet.js",
"vendor": "patorjk",
"versions": [
{
"status": "affected",
"version": "\u003c 1.11.3"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "figlet.js is a FIG driver written in JavaScript that aims to implement the FIGfont specification. Prior to 1.11.3, text() and textSync() can enter an unbounded loop when whitespaceBreak is enabled and width is smaller than the rendered width of a single FIGlet character. Under these conditions, breakWord() cannot find a valid break point and returns without consuming a character, so generateFigTextLines() repeatedly processes the same input while consuming CPU and growing memory. The non-default option and attacker-controlled width must both reach an affected call. This issue is fixed in version 1.11.3."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 8.2,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-835",
"description": "CWE-835: Loop with Unreachable Exit Condition (\u0027Infinite Loop\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T20:21:54.408Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/patorjk/figlet.js/security/advisories/GHSA-62ch-8vmq-8xm7",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/patorjk/figlet.js/security/advisories/GHSA-62ch-8vmq-8xm7"
},
{
"name": "https://github.com/patorjk/figlet.js/pull/169",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/patorjk/figlet.js/pull/169"
},
{
"name": "https://github.com/patorjk/figlet.js/commit/cb2839d0e53aeafbd361e9587abc72e49e41cbb3",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/patorjk/figlet.js/commit/cb2839d0e53aeafbd361e9587abc72e49e41cbb3"
}
],
"source": {
"advisory": "GHSA-62ch-8vmq-8xm7",
"discovery": "UNKNOWN"
},
"title": "figlet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used with a small width"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-96780",
"datePublished": "2026-10-01T20:21:54.408Z",
"dateReserved": "2026-09-23T16:25:20.414Z",
"dateUpdated": "2026-10-01T20:40:30.208Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104183 (GCVE-0-2026-104183)
Vulnerability from cvelistv5 – Published: 2026-10-01 20:17 – Updated: 2026-10-01 20:30
VLAI
EPSS
VEX
Title
stream-json: Prototype pollution: Assembler writes this.current[this.key] on plain objects
Summary
stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, Assembler materializes object properties with plain assignment, so an input key named __proto__ invokes the inherited setter and causes parsed object prototype replacement instead of creating an own data property. Applications that make authorization or feature decisions from inherited values can therefore consume attacker-controlled properties, and a null prototype can disrupt code that expects Object.prototype methods. The researcher treats parsing untrusted JSON as part of the project contract, while the maintainer states that documented inputs are locally owned dumps, exports, or logs and characterizes the attack vector as local. The global Object.prototype is not polluted. This issue is fixed in version 3.6.0.
Severity
5.1 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 20:29 UTC
CWE
- CWE-1321 - Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/uhop/stream-json/security/advi… | x_refsource_CONFIRM |
| https://github.com/uhop/stream-json/commit/2f2d35… | x_refsource_MISC |
| https://github.com/uhop/stream-json/releases/tag/3.6.0 | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| uhop | stream-json |
Affected:
< 3.6.0
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-104183",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T20:29:33.204136Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T20:30:54.674Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/uhop/stream-json/security/advisories/GHSA-mjw6-4jj6-33hc"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "stream-json",
"vendor": "uhop",
"versions": [
{
"status": "affected",
"version": "\u003c 3.6.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, Assembler materializes object properties with plain assignment, so an input key named __proto__ invokes the inherited setter and causes parsed object prototype replacement instead of creating an own data property. Applications that make authorization or feature decisions from inherited values can therefore consume attacker-controlled properties, and a null prototype can disrupt code that expects Object.prototype methods. The researcher treats parsing untrusted JSON as part of the project contract, while the maintainer states that documented inputs are locally owned dumps, exports, or logs and characterizes the attack vector as local. The global Object.prototype is not polluted. This issue is fixed in version 3.6.0."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "LOW",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1321",
"description": "CWE-1321: Improperly Controlled Modification of Object Prototype Attributes (\u0027Prototype Pollution\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T20:17:21.645Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/uhop/stream-json/security/advisories/GHSA-mjw6-4jj6-33hc",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/uhop/stream-json/security/advisories/GHSA-mjw6-4jj6-33hc"
},
{
"name": "https://github.com/uhop/stream-json/commit/2f2d35bbb547306991ded6487a279154d865a358",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/uhop/stream-json/commit/2f2d35bbb547306991ded6487a279154d865a358"
},
{
"name": "https://github.com/uhop/stream-json/releases/tag/3.6.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/uhop/stream-json/releases/tag/3.6.0"
}
],
"source": {
"advisory": "GHSA-mjw6-4jj6-33hc",
"discovery": "UNKNOWN"
},
"title": "stream-json: Prototype pollution: Assembler writes this.current[this.key] on plain objects"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-104183",
"datePublished": "2026-10-01T20:17:21.645Z",
"dateReserved": "2026-10-01T18:54:15.118Z",
"dateUpdated": "2026-10-01T20:30:54.674Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104182 (GCVE-0-2026-104182)
Vulnerability from cvelistv5 – Published: 2026-10-01 20:15 – Updated: 2026-10-01 20:15
VLAI
EPSS
VEX
Title
stream-json: JSONC parser and verifier re-scan the whole accumulated comment on every input chunk
Summary
stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, the JSONC parser at stream-json/jsonc/parser.js and verifier at stream-json/jsonc/verifier.js restart comment-terminator scanning from the opening slash whenever a block or line comment spans an input chunk, while retaining the accumulated comment buffer. Delivering a large valid comment across many small chunks therefore causes quadratic CPU work and can stall the Node.js event loop. The maintainer characterizes the attack vector as local because the documented JSONC input is locally owned or user-controlled configuration, rather than input intended for the open internet. This JSONC-only scope does not include the plain JSON parser, which advances through and discards consumed string and number data. This issue is fixed in version 3.6.0.
Severity
6.2 (Medium)
CWE
- CWE-407 - Inefficient Algorithmic Complexity
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/uhop/stream-json/security/advi… | x_refsource_CONFIRM |
| https://github.com/uhop/stream-json/commit/c0299d… | x_refsource_MISC |
| https://github.com/uhop/stream-json/releases/tag/3.6.0 | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| uhop | stream-json |
Affected:
< 3.6.0
|
{
"containers": {
"cna": {
"affected": [
{
"product": "stream-json",
"vendor": "uhop",
"versions": [
{
"status": "affected",
"version": "\u003c 3.6.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, the JSONC parser at stream-json/jsonc/parser.js and verifier at stream-json/jsonc/verifier.js restart comment-terminator scanning from the opening slash whenever a block or line comment spans an input chunk, while retaining the accumulated comment buffer. Delivering a large valid comment across many small chunks therefore causes quadratic CPU work and can stall the Node.js event loop. The maintainer characterizes the attack vector as local because the documented JSONC input is locally owned or user-controlled configuration, rather than input intended for the open internet. This JSONC-only scope does not include the plain JSON parser, which advances through and discards consumed string and number data. This issue is fixed in version 3.6.0."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 6.2,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-407",
"description": "CWE-407: Inefficient Algorithmic Complexity",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T20:15:39.108Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/uhop/stream-json/security/advisories/GHSA-hqr4-qq8f-hg3x",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/uhop/stream-json/security/advisories/GHSA-hqr4-qq8f-hg3x"
},
{
"name": "https://github.com/uhop/stream-json/commit/c0299dc168ce9455ef5ca5b6a0f6850ee7fa0468",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/uhop/stream-json/commit/c0299dc168ce9455ef5ca5b6a0f6850ee7fa0468"
},
{
"name": "https://github.com/uhop/stream-json/releases/tag/3.6.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/uhop/stream-json/releases/tag/3.6.0"
}
],
"source": {
"advisory": "GHSA-hqr4-qq8f-hg3x",
"discovery": "UNKNOWN"
},
"title": "stream-json: JSONC parser and verifier re-scan the whole accumulated comment on every input chunk"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-104182",
"datePublished": "2026-10-01T20:15:39.108Z",
"dateReserved": "2026-10-01T18:54:15.118Z",
"dateUpdated": "2026-10-01T20:15:39.108Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104181 (GCVE-0-2026-104181)
Vulnerability from cvelistv5 – Published: 2026-10-01 20:02 – Updated: 2026-10-01 20:02
VLAI
EPSS
VEX
Title
Filament: Multi-factor authentication (app) management actions do not require password reauthentication
Summary
Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.13.3 and 5.8.3, app-based multi-factor authentication management actions do not consistently require confirmation of the current password. An attacker with access to an authenticated user session can set up app-based MFA and obtain recovery codes, or disable app-based MFA and regenerate recovery codes by supplying an existing app code or recovery code, without knowing the account password. Email-based MFA is not affected, and the issue does not independently permit an unauthenticated sign-in, but changing the app-MFA configuration may lock the legitimate user out. This issue is fixed in versions 4.13.3 and 5.8.3.
Severity
5.4 (Medium)
CWE
- CWE-306 - Missing Authentication for Critical Function
Assigner
References
5 references
| URL | Tags |
|---|---|
| https://github.com/filamentphp/filament/security/… | x_refsource_CONFIRM |
| https://github.com/filamentphp/filament/pull/20522 | x_refsource_MISC |
| https://github.com/filamentphp/filament/commit/6d… | x_refsource_MISC |
| https://github.com/filamentphp/filament/releases/… | x_refsource_MISC |
| https://github.com/filamentphp/filament/releases/… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| filamentphp | filament |
Affected:
>= 4.0.0, < 4.13.2
Affected: >= 5.0.0, < 5.8.2 |
{
"containers": {
"cna": {
"affected": [
{
"product": "filament",
"vendor": "filamentphp",
"versions": [
{
"status": "affected",
"version": "\u003e= 4.0.0, \u003c 4.13.2"
},
{
"status": "affected",
"version": "\u003e= 5.0.0, \u003c 5.8.2"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.13.3 and 5.8.3, app-based multi-factor authentication management actions do not consistently require confirmation of the current password. An attacker with access to an authenticated user session can set up app-based MFA and obtain recovery codes, or disable app-based MFA and regenerate recovery codes by supplying an existing app code or recovery code, without knowing the account password. Email-based MFA is not affected, and the issue does not independently permit an unauthenticated sign-in, but changing the app-MFA configuration may lock the legitimate user out. This issue is fixed in versions 4.13.3 and 5.8.3."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "CWE-306: Missing Authentication for Critical Function",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T20:02:30.970Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/filamentphp/filament/security/advisories/GHSA-7m6h-rg42-m449",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/filamentphp/filament/security/advisories/GHSA-7m6h-rg42-m449"
},
{
"name": "https://github.com/filamentphp/filament/pull/20522",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/filamentphp/filament/pull/20522"
},
{
"name": "https://github.com/filamentphp/filament/commit/6d4dae6d7a94ce5aefd7ed4dc836acb0e6b71bb1",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/filamentphp/filament/commit/6d4dae6d7a94ce5aefd7ed4dc836acb0e6b71bb1"
},
{
"name": "https://github.com/filamentphp/filament/releases/tag/v4.13.3",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/filamentphp/filament/releases/tag/v4.13.3"
},
{
"name": "https://github.com/filamentphp/filament/releases/tag/v5.8.3",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/filamentphp/filament/releases/tag/v5.8.3"
}
],
"source": {
"advisory": "GHSA-7m6h-rg42-m449",
"discovery": "UNKNOWN"
},
"title": "Filament: Multi-factor authentication (app) management actions do not require password reauthentication"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-104181",
"datePublished": "2026-10-01T20:02:30.970Z",
"dateReserved": "2026-10-01T18:54:15.117Z",
"dateUpdated": "2026-10-01T20:02:30.970Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53964 (GCVE-0-2026-53964)
Vulnerability from cvelistv5 – Published: 2026-10-01 19:55 – Updated: 2026-10-01 20:13
VLAI
EPSS
VEX
Title
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
Summary
Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Prior to version 9.1.0, a remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the xltpl library uses a npn-sandboxed Jinja environment for the processing of the template. This issue has been patched in version 9.1.0.
Severity
7.2 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 20:12 UTC
CWE
- CWE-1336 - Improper Neutralization of Special Elements Used in a Template Engine
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/adfinis/document-merge-service… | x_refsource_CONFIRM |
| https://github.com/adfinis/document-merge-service… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| adfinis | document-merge-service |
Affected:
< 9.1.0
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-53964",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T20:12:41.561346Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T20:13:16.003Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "document-merge-service",
"vendor": "adfinis",
"versions": [
{
"status": "affected",
"version": "\u003c 9.1.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Prior to version 9.1.0, a remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server\u0027s context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the xltpl library uses a npn-sandboxed Jinja environment for the processing of the template. This issue has been patched in version 9.1.0."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1336",
"description": "CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T19:55:07.504Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/adfinis/document-merge-service/security/advisories/GHSA-w47q-945m-q9pc",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/adfinis/document-merge-service/security/advisories/GHSA-w47q-945m-q9pc"
},
{
"name": "https://github.com/adfinis/document-merge-service/releases/tag/v9.1.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/adfinis/document-merge-service/releases/tag/v9.1.0"
}
],
"source": {
"advisory": "GHSA-w47q-945m-q9pc",
"discovery": "UNKNOWN"
},
"title": "Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-53964",
"datePublished": "2026-10-01T19:55:07.504Z",
"dateReserved": "2026-06-11T15:50:01.282Z",
"dateUpdated": "2026-10-01T20:13:16.003Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-55252 (GCVE-0-2026-55252)
Vulnerability from cvelistv5 – Published: 2026-10-01 19:52 – Updated: 2026-10-01 19:52
VLAI
EPSS
VEX
Title
OpenRun: Redirect URL validation bypass using //host paths leads to Open Redirect
Summary
OpenRun is an open-source, self-hosted GitOps platform for deploying web apps and internal tools to Docker or Kubernetes. Prior to version 0.17.7, the restrictions on redirect URLs in openrun can be bypassed by attackers, leading to open redirect attacks. This issue has been patched in version 0.17.7.
Severity
CWE
- CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/openrundev/openrun/security/ad… | x_refsource_CONFIRM |
| https://github.com/openrundev/openrun/commit/709d… | x_refsource_MISC |
| https://github.com/openrundev/openrun/releases/ta… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| openrundev | openrun |
Affected:
< 0.17.7
|
{
"containers": {
"cna": {
"affected": [
{
"product": "openrun",
"vendor": "openrundev",
"versions": [
{
"status": "affected",
"version": "\u003c 0.17.7"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "OpenRun is an open-source, self-hosted GitOps platform for deploying web apps and internal tools to Docker or Kubernetes. Prior to version 0.17.7, the restrictions on redirect URLs in openrun can be bypassed by attackers, leading to open redirect attacks. This issue has been patched in version 0.17.7."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "NONE",
"userInteraction": "ACTIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-601",
"description": "CWE-601: URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T19:52:31.031Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/openrundev/openrun/security/advisories/GHSA-h5g6-xmh4-hc37",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/openrundev/openrun/security/advisories/GHSA-h5g6-xmh4-hc37"
},
{
"name": "https://github.com/openrundev/openrun/commit/709da784fcf1311c85f30f3542cfa3601a78bbf0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/openrundev/openrun/commit/709da784fcf1311c85f30f3542cfa3601a78bbf0"
},
{
"name": "https://github.com/openrundev/openrun/releases/tag/v0.17.7",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/openrundev/openrun/releases/tag/v0.17.7"
}
],
"source": {
"advisory": "GHSA-h5g6-xmh4-hc37",
"discovery": "UNKNOWN"
},
"title": "OpenRun: Redirect URL validation bypass using //host paths leads to Open Redirect"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-55252",
"datePublished": "2026-10-01T19:52:31.031Z",
"dateReserved": "2026-06-16T16:44:00.625Z",
"dateUpdated": "2026-10-01T19:52:31.031Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-55251 (GCVE-0-2026-55251)
Vulnerability from cvelistv5 – Published: 2026-10-01 19:49 – Updated: 2026-10-01 19:49
VLAI
EPSS
VEX
Title
NetBox Device Type Library: Arbitrary Code Execution on CI Runner Through Malicious requirements.txt, .pre-commit-hooks-config.yaml, and .gitmodules Files
Summary
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. Prior to commit f41fc1e, the CI workflow .github/workflows/validation.yml runs on pull_request and executes code supplied by the pull request before any maintainer review. Three PR-editable files drive this: "requirements.txt", ".pre-commit-hooks-config.yaml" / ".pre-commit-yamlfmt-config.yaml", and ".gitmodules". A contributor with no special repository access could open a pull request that modifies these files and have their code run on the CI runner. This issue has been patched via commit f41fc1e.
Severity
6.5 (Medium)
CWE
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/netbox-community/devicetype-li… | x_refsource_CONFIRM |
| https://github.com/netbox-community/devicetype-li… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| netbox-community | devicetype-library |
Affected:
< f41fc1e48dec8d7d31afba5f13a8c73652ff5796
|
{
"containers": {
"cna": {
"affected": [
{
"product": "devicetype-library",
"vendor": "netbox-community",
"versions": [
{
"status": "affected",
"version": "\u003c f41fc1e48dec8d7d31afba5f13a8c73652ff5796"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. Prior to commit f41fc1e, the CI workflow .github/workflows/validation.yml runs on pull_request and executes code supplied by the pull request before any maintainer review. Three PR-editable files drive this: \"requirements.txt\", \".pre-commit-hooks-config.yaml\" / \".pre-commit-yamlfmt-config.yaml\", and \".gitmodules\". A contributor with no special repository access could open a pull request that modifies these files and have their code run on the CI runner. This issue has been patched via commit f41fc1e."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-94",
"description": "CWE-94: Improper Control of Generation of Code (\u0027Code Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-494",
"description": "CWE-494: Download of Code Without Integrity Check",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-829",
"description": "CWE-829: Inclusion of Functionality from Untrusted Control Sphere",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T19:49:32.741Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/netbox-community/devicetype-library/security/advisories/GHSA-5x2m-x42f-g4cm",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/netbox-community/devicetype-library/security/advisories/GHSA-5x2m-x42f-g4cm"
},
{
"name": "https://github.com/netbox-community/devicetype-library/commit/f41fc1e48dec8d7d31afba5f13a8c73652ff5796",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/netbox-community/devicetype-library/commit/f41fc1e48dec8d7d31afba5f13a8c73652ff5796"
}
],
"source": {
"advisory": "GHSA-5x2m-x42f-g4cm",
"discovery": "UNKNOWN"
},
"title": "NetBox Device Type Library: Arbitrary Code Execution on CI Runner Through Malicious requirements.txt, .pre-commit-hooks-config.yaml, and .gitmodules Files"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-55251",
"datePublished": "2026-10-01T19:49:32.741Z",
"dateReserved": "2026-06-16T16:44:00.625Z",
"dateUpdated": "2026-10-01T19:49:32.741Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-54049 (GCVE-0-2026-54049)
Vulnerability from cvelistv5 – Published: 2026-10-01 19:42 – Updated: 2026-10-01 19:42
VLAI
EPSS
VEX
Title
Sakai Conversations has a Stored XSS Issue
Summary
Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to before 23.5, and versions 25.0 to before 25.3, the Sakai Conversations tool stores topic and post messages without HTML sanitization, and the frontend renders them using LitElement's unsafeHTML() directive, resulting in stored cross-site scripting (XSS). Any authenticated user with access to a site that has the Conversations tool enabled can inject arbitrary HTML and JavaScript that executes in the browsers of all other users who view that topic or post. This issue has been patched in versions 23.5, 25.3, and 26.0.
Severity
8.7 (High)
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/sakaiproject/sakai/security/ad… | x_refsource_CONFIRM |
| https://github.com/sakaiproject/sakai/commit/2696… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| sakaiproject | sakai |
Affected:
>= 23.0, < 23.5
Affected: >= 25.0, < 25.3 |
{
"containers": {
"cna": {
"affected": [
{
"product": "sakai",
"vendor": "sakaiproject",
"versions": [
{
"status": "affected",
"version": "\u003e= 23.0, \u003c 23.5"
},
{
"status": "affected",
"version": "\u003e= 25.0, \u003c 25.3"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to before 23.5, and versions 25.0 to before 25.3, the Sakai Conversations tool stores topic and post messages without HTML sanitization, and the frontend renders them using LitElement\u0027s unsafeHTML() directive, resulting in stored cross-site scripting (XSS). Any authenticated user with access to a site that has the Conversations tool enabled can inject arbitrary HTML and JavaScript that executes in the browsers of all other users who view that topic or post. This issue has been patched in versions 23.5, 25.3, and 26.0."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T19:42:50.422Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/sakaiproject/sakai/security/advisories/GHSA-w2x5-gv52-9ccv",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/sakaiproject/sakai/security/advisories/GHSA-w2x5-gv52-9ccv"
},
{
"name": "https://github.com/sakaiproject/sakai/commit/2696b4b48cbef2e81512f52f84f7477adff78b27",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/sakaiproject/sakai/commit/2696b4b48cbef2e81512f52f84f7477adff78b27"
}
],
"source": {
"advisory": "GHSA-w2x5-gv52-9ccv",
"discovery": "UNKNOWN"
},
"title": "Sakai Conversations has a Stored XSS Issue"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-54049",
"datePublished": "2026-10-01T19:42:50.422Z",
"dateReserved": "2026-06-11T18:24:35.095Z",
"dateUpdated": "2026-10-01T19:42:50.422Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-71542 (GCVE-0-2026-71542)
Vulnerability from cvelistv5 – Published: 2026-10-01 19:40 – Updated: 2026-10-01 19:51
VLAI
EPSS
VEX
Title
GetSimple CMS: Stored Cross-Site Scripting (XSS) via the "title" parameter in admin/components.php
Summary
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, GetSimpleCMS-CE is vulnerable to stored Cross-Site Scripting (XSS) in the "Theme to Components" functionality (admin/components.php) via the title parameter. The stored title is rendered inside a double-quoted HTML attribute in the administrative interface through an output path that HTML-entity-decodes the value before printing it, without re-encoding for the attribute context. This allows persistent execution of arbitrary JavaScript in the admin panel. At time of publication, there are no publicly available patches.
Severity
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 19:51 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://github.com/GetSimpleCMS-CE/GetSimpleCMS-C… | x_refsource_CONFIRM |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| GetSimpleCMS-CE | GetSimpleCMS-CE |
Affected:
<= 3.3.22
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-71542",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T19:51:10.583264Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T19:51:29.324Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-vqfh-838q-xfqh"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "GetSimpleCMS-CE",
"vendor": "GetSimpleCMS-CE",
"versions": [
{
"status": "affected",
"version": "\u003c= 3.3.22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, GetSimpleCMS-CE is vulnerable to stored Cross-Site Scripting (XSS) in the \"Theme to Components\" functionality (admin/components.php) via the title parameter. The stored title is rendered inside a double-quoted HTML attribute in the administrative interface through an output path that HTML-entity-decodes the value before printing it, without re-encoding for the attribute context. This allows persistent execution of arbitrary JavaScript in the admin panel. At time of publication, there are no publicly available patches."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T19:40:04.001Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-vqfh-838q-xfqh",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-vqfh-838q-xfqh"
}
],
"source": {
"advisory": "GHSA-vqfh-838q-xfqh",
"discovery": "UNKNOWN"
},
"title": "GetSimple CMS: Stored Cross-Site Scripting (XSS) via the \"title\" parameter in admin/components.php"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-71542",
"datePublished": "2026-10-01T19:40:04.001Z",
"dateReserved": "2026-08-06T21:24:15.375Z",
"dateUpdated": "2026-10-01T19:51:29.324Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-71426 (GCVE-0-2026-71426)
Vulnerability from cvelistv5 – Published: 2026-10-01 19:39 – Updated: 2026-10-01 19:52
VLAI
EPSS
VEX
Title
GetSimple CMS: Authenticated Stored Local File Inclusion (LFI) via page "template" field
Summary
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated user with page-editing rights can store an arbitrary filesystem path in a page's template attribute. On the public front-end, this value is passed unsanitized to a PHP include() when the page is rendered. Because the include path is never confined, this allows directory-traversal Local File Inclusion: arbitrary local files are included (and, if they contain PHP, executed) when any visitor requests the page. At time of publication, there are no publicly available patches.
Severity
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 19:51 UTC
CWE
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://github.com/GetSimpleCMS-CE/GetSimpleCMS-C… | x_refsource_CONFIRM |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| GetSimpleCMS-CE | GetSimpleCMS-CE |
Affected:
<= 3.3.22
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-71426",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T19:51:37.247113Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T19:52:46.391Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-559q-hqrv-m84x"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "GetSimpleCMS-CE",
"vendor": "GetSimpleCMS-CE",
"versions": [
{
"status": "affected",
"version": "\u003c= 3.3.22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated user with page-editing rights can store an arbitrary filesystem path in a page\u0027s template attribute. On the public front-end, this value is passed unsanitized to a PHP include() when the page is rendered. Because the include path is never confined, this allows directory-traversal Local File Inclusion: arbitrary local files are included (and, if they contain PHP, executed) when any visitor requests the page. At time of publication, there are no publicly available patches."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-98",
"description": "CWE-98: Improper Control of Filename for Include/Require Statement in PHP Program (\u0027PHP Remote File Inclusion\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T19:39:29.439Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-559q-hqrv-m84x",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-559q-hqrv-m84x"
}
],
"source": {
"advisory": "GHSA-559q-hqrv-m84x",
"discovery": "UNKNOWN"
},
"title": "GetSimple CMS: Authenticated Stored Local File Inclusion (LFI) via page \"template\" field"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-71426",
"datePublished": "2026-10-01T19:39:29.439Z",
"dateReserved": "2026-08-06T16:28:51.182Z",
"dateUpdated": "2026-10-01T19:52:46.391Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-70650 (GCVE-0-2026-70650)
Vulnerability from cvelistv5 – Published: 2026-10-01 19:39 – Updated: 2026-10-01 19:39
VLAI
EPSS
VEX
Title
GetSimple CMS: Authenticated Stored XSS in backup viewer (backup-edit.php) via output decoding of page meta fields and content
Summary
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated stored Cross-Site Scripting (XSS) vulnerability exists in the page backup viewer (admin/backup-edit.php). Page fields are correctly HTML-encoded when a page is saved, but the backup viewer decodes them again (htmldecode() / strip_decode()) and prints the result without re-escaping. A user who can edit a page can store JavaScript in a page's Keywords, Description, Menu text or Content; it executes in the browser of any administrator who later views that page's backup, in the context of the admin control panel. At time of publication, there are no publicly available patches.
Severity
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://github.com/GetSimpleCMS-CE/GetSimpleCMS-C… | x_refsource_CONFIRM |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| GetSimpleCMS-CE | GetSimpleCMS-CE |
Affected:
<= 3.3.22
|
{
"containers": {
"cna": {
"affected": [
{
"product": "GetSimpleCMS-CE",
"vendor": "GetSimpleCMS-CE",
"versions": [
{
"status": "affected",
"version": "\u003c= 3.3.22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated stored Cross-Site Scripting (XSS) vulnerability exists in the page backup viewer (admin/backup-edit.php). Page fields are correctly HTML-encoded when a page is saved, but the backup viewer decodes them again (htmldecode() / strip_decode()) and prints the result without re-escaping. A user who can edit a page can store JavaScript in a page\u0027s Keywords, Description, Menu text or Content; it executes in the browser of any administrator who later views that page\u0027s backup, in the context of the admin control panel. At time of publication, there are no publicly available patches."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T19:39:00.958Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-p6vf-2xr7-mcf4",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-p6vf-2xr7-mcf4"
}
],
"source": {
"advisory": "GHSA-p6vf-2xr7-mcf4",
"discovery": "UNKNOWN"
},
"title": "GetSimple CMS: Authenticated Stored XSS in backup viewer (backup-edit.php) via output decoding of page meta fields and content"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-70650",
"datePublished": "2026-10-01T19:39:00.958Z",
"dateReserved": "2026-08-04T21:48:08.612Z",
"dateUpdated": "2026-10-01T19:39:00.958Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-56662 (GCVE-0-2026-56662)
Vulnerability from cvelistv5 – Published: 2026-10-01 19:38 – Updated: 2026-10-01 19:38
VLAI
EPSS
VEX
Title
GetSimple CMS: Missing CSRF protection in UpdateCE allows forging a privileged server-side update request
Summary
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the UpdateCE update form contained no anti-CSRF token, and the POST handler performed no token or request-origin verification. A remote attacker can host a page that auto-submits a forged POST to the update endpoint; when an authenticated administrator visits it, the server performs an attacker-directed download-and-deploy operation in the administrator's session — with no further interaction. Because the deployed content is executed (see the related ZIP-extraction advisory), this yields remote code execution. The url field is additionally written into the form unescaped, providing a secondary HTML-injection sink via a malicious upgrade.json. This issue has been patched in version 1.5.
Severity
9.6 (Critical)
CWE
- CWE-352 - Cross-Site Request Forgery (CSRF)
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://github.com/GetSimpleCMS-CE/GetSimpleCMS-C… | x_refsource_CONFIRM |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| GetSimpleCMS-CE | GetSimpleCMS-CE |
Affected:
< 1.5
|
{
"containers": {
"cna": {
"affected": [
{
"product": "GetSimpleCMS-CE",
"vendor": "GetSimpleCMS-CE",
"versions": [
{
"status": "affected",
"version": "\u003c 1.5"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the UpdateCE update form contained no anti-CSRF token, and the POST handler performed no token or request-origin verification. A remote attacker can host a page that auto-submits a forged POST to the update endpoint; when an authenticated administrator visits it, the server performs an attacker-directed download-and-deploy operation in the administrator\u0027s session \u2014 with no further interaction. Because the deployed content is executed (see the related ZIP-extraction advisory), this yields remote code execution. The url field is additionally written into the form unescaped, providing a secondary HTML-injection sink via a malicious upgrade.json. This issue has been patched in version 1.5."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.6,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-352",
"description": "CWE-352: Cross-Site Request Forgery (CSRF)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T19:38:30.623Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-2rxv-4g4m-573w",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-2rxv-4g4m-573w"
}
],
"source": {
"advisory": "GHSA-2rxv-4g4m-573w",
"discovery": "UNKNOWN"
},
"title": "GetSimple CMS: Missing CSRF protection in UpdateCE allows forging a privileged server-side update request"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-56662",
"datePublished": "2026-10-01T19:38:30.623Z",
"dateReserved": "2026-06-22T16:39:01.043Z",
"dateUpdated": "2026-10-01T19:38:30.623Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-56661 (GCVE-0-2026-56661)
Vulnerability from cvelistv5 – Published: 2026-10-01 19:38 – Updated: 2026-10-01 19:50
VLAI
EPSS
VEX
Title
GetSimple CMS: Server-Side Request Forgery in the UpdateCE update endpoint
Summary
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler fetches a user-supplied URL with file_get_contents() after only format validation (FILTER_VALIDATE_URL) — there is no validation of the request destination. An attacker who can submit the form can make the server issue requests to arbitrary destinations, including internal-only services and cloud metadata endpoints (169.254.169.254). The fetched response body is written to a web-accessible file (/Tmpfile.zip) and is not deleted when the content is not a valid ZIP, turning this into a full-read SSRF: the attacker can retrieve the response of the internal request directly. This issue has been patched in version 1.5.
Severity
7.5 (High)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 19:50 UTC
CWE
- CWE-918 - Server-Side Request Forgery (SSRF)
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://github.com/GetSimpleCMS-CE/GetSimpleCMS-C… | x_refsource_CONFIRM |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| GetSimpleCMS-CE | GetSimpleCMS-CE |
Affected:
< 1.5
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-56661",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T19:50:31.476852Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T19:50:54.335Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-r7v8-mx29-5q8h"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "GetSimpleCMS-CE",
"vendor": "GetSimpleCMS-CE",
"versions": [
{
"status": "affected",
"version": "\u003c 1.5"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler fetches a user-supplied URL with file_get_contents() after only format validation (FILTER_VALIDATE_URL) \u2014 there is no validation of the request destination. An attacker who can submit the form can make the server issue requests to arbitrary destinations, including internal-only services and cloud metadata endpoints (169.254.169.254). The fetched response body is written to a web-accessible file (/Tmpfile.zip) and is not deleted when the content is not a valid ZIP, turning this into a full-read SSRF: the attacker can retrieve the response of the internal request directly. This issue has been patched in version 1.5."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "LOW",
"privilegesRequired": "HIGH",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-918",
"description": "CWE-918: Server-Side Request Forgery (SSRF)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T19:38:08.498Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-r7v8-mx29-5q8h",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-r7v8-mx29-5q8h"
}
],
"source": {
"advisory": "GHSA-r7v8-mx29-5q8h",
"discovery": "UNKNOWN"
},
"title": "GetSimple CMS: Server-Side Request Forgery in the UpdateCE update endpoint"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-56661",
"datePublished": "2026-10-01T19:38:08.498Z",
"dateReserved": "2026-06-22T16:39:01.043Z",
"dateUpdated": "2026-10-01T19:50:54.335Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-56660 (GCVE-0-2026-56660)
Vulnerability from cvelistv5 – Published: 2026-10-01 19:37 – Updated: 2026-10-01 19:54
VLAI
EPSS
VEX
Title
GetSimple CMS: CSRF, SSRF, and Unrestricted Zip Extraction
Summary
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler in UpdateCE.php downloads a ZIP archive and extracts its contents into the web root without validating file types or extraction paths. Because PHP files are written into a web-accessible directory, an attacker who can cause a malicious archive to be processed achieves remote code execution as the web-server user. Entry names are also used unsafely, allowing directory traversal (../) to write files outside the intended extraction directory. This issue has been patched in version 1.5.
Severity
9.1 (Critical)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 19:53 UTC
CWE
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://github.com/GetSimpleCMS-CE/GetSimpleCMS-C… | x_refsource_CONFIRM |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| GetSimpleCMS-CE | GetSimpleCMS-CE |
Affected:
< 1.5
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-56660",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T19:53:21.941385Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T19:54:11.631Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-q5rx-gppg-768r"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "GetSimpleCMS-CE",
"vendor": "GetSimpleCMS-CE",
"versions": [
{
"status": "affected",
"version": "\u003c 1.5"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler in UpdateCE.php downloads a ZIP archive and extracts its contents into the web root without validating file types or extraction paths. Because PHP files are written into a web-accessible directory, an attacker who can cause a malicious archive to be processed achieves remote code execution as the web-server user. Entry names are also used unsafely, allowing directory traversal (../) to write files outside the intended extraction directory. This issue has been patched in version 1.5."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-352",
"description": "CWE-352: Cross-Site Request Forgery (CSRF)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-434",
"description": "CWE-434: Unrestricted Upload of File with Dangerous Type",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-918",
"description": "CWE-918: Server-Side Request Forgery (SSRF)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T19:37:46.187Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-q5rx-gppg-768r",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-q5rx-gppg-768r"
}
],
"source": {
"advisory": "GHSA-q5rx-gppg-768r",
"discovery": "UNKNOWN"
},
"title": "GetSimple CMS: CSRF, SSRF, and Unrestricted Zip Extraction"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-56660",
"datePublished": "2026-10-01T19:37:46.187Z",
"dateReserved": "2026-06-22T16:39:01.043Z",
"dateUpdated": "2026-10-01T19:54:11.631Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53953 (GCVE-0-2026-53953)
Vulnerability from cvelistv5 – Published: 2026-10-01 19:36 – Updated: 2026-10-01 19:36
VLAI
EPSS
VEX
Title
GetSimple CMS: Predictable Password Reset Password Allows Administrator Account Takeover
Summary
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3.22, the password reset endpoint can be accessed without authentication. When a reset request is submitted for an existing user, the application generates a new temporary password and immediately stores its hash as the user's new password. The temporary password is generated using PHP rand() seeded with microtime(). Because this seed is time-based and has a limited effective search space, an attacker can generate possible reset password candidates. Since the admin login endpoint does not enforce rate limiting or account lockout, these candidates can be tested online until the correct password is found. Successful exploitation may lead to administrator account takeover. At time of publication, there are no publicly available patches.
Severity
9.1 (Critical)
CWE
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://github.com/GetSimpleCMS-CE/GetSimpleCMS-C… | x_refsource_CONFIRM |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| GetSimpleCMS-CE | GetSimpleCMS-CE |
Affected:
= 3.3.22
|
{
"containers": {
"cna": {
"affected": [
{
"product": "GetSimpleCMS-CE",
"vendor": "GetSimpleCMS-CE",
"versions": [
{
"status": "affected",
"version": "= 3.3.22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3.22, the password reset endpoint can be accessed without authentication. When a reset request is submitted for an existing user, the application generates a new temporary password and immediately stores its hash as the user\u0027s new password. The temporary password is generated using PHP rand() seeded with microtime(). Because this seed is time-based and has a limited effective search space, an attacker can generate possible reset password candidates. Since the admin login endpoint does not enforce rate limiting or account lockout, these candidates can be tested online until the correct password is found. Successful exploitation may lead to administrator account takeover. At time of publication, there are no publicly available patches."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-338",
"description": "CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-640",
"description": "CWE-640: Weak Password Recovery Mechanism for Forgotten Password",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T19:36:17.930Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-vvhx-56q2-gcjq",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-vvhx-56q2-gcjq"
}
],
"source": {
"advisory": "GHSA-vvhx-56q2-gcjq",
"discovery": "UNKNOWN"
},
"title": "GetSimple CMS: Predictable Password Reset Password Allows Administrator Account Takeover"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-53953",
"datePublished": "2026-10-01T19:36:17.930Z",
"dateReserved": "2026-06-11T15:50:01.281Z",
"dateUpdated": "2026-10-01T19:36:17.930Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-55232 (GCVE-0-2026-55232)
Vulnerability from cvelistv5 – Published: 2026-10-01 18:43 – Updated: 2026-10-01 18:43
VLAI
EPSS
VEX
Title
Vvveb: Server-side request forgery in Vvveb via IPv6 bypass of validateUrl() in editor oEmbed proxy
Summary
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's SSRF guard resolves a host with an IPv4-only function and never inspects IPv6, so any host that lacks an A record passes a private-range check. Editor oEmbed proxy fetches an attacker-supplied URL server side and reflects a response body, so an authenticated admin-panel user (default role site_admin or higher) can read internal-only services and cloud metadata, including IAM credentials, using an IPv6 literal or a domain that carries only an AAAA record. This issue has been patched in version 1.0.8.6.
Severity
7.6 (High)
CWE
- CWE-918 - Server-Side Request Forgery (SSRF)
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/givanz/Vvveb/security/advisori… | x_refsource_CONFIRM |
| https://github.com/givanz/Vvveb/commit/e27d1ef097… | x_refsource_MISC |
| https://github.com/givanz/Vvveb/releases/tag/1.0.8.6 | x_refsource_MISC |
{
"containers": {
"cna": {
"affected": [
{
"product": "Vvveb",
"vendor": "givanz",
"versions": [
{
"status": "affected",
"version": "\u003c 1.0.8.6"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb\u0027s SSRF guard resolves a host with an IPv4-only function and never inspects IPv6, so any host that lacks an A record passes a private-range check. Editor oEmbed proxy fetches an attacker-supplied URL server side and reflects a response body, so an authenticated admin-panel user (default role site_admin or higher) can read internal-only services and cloud metadata, including IAM credentials, using an IPv6 literal or a domain that carries only an AAAA record. This issue has been patched in version 1.0.8.6."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.6,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "LOW",
"privilegesRequired": "HIGH",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-918",
"description": "CWE-918: Server-Side Request Forgery (SSRF)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:43:19.102Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/givanz/Vvveb/security/advisories/GHSA-r6g4-5m3x-xrqj",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/givanz/Vvveb/security/advisories/GHSA-r6g4-5m3x-xrqj"
},
{
"name": "https://github.com/givanz/Vvveb/commit/e27d1ef097a8502c33f8cc94271c948407c5dce3",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/givanz/Vvveb/commit/e27d1ef097a8502c33f8cc94271c948407c5dce3"
},
{
"name": "https://github.com/givanz/Vvveb/releases/tag/1.0.8.6",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/givanz/Vvveb/releases/tag/1.0.8.6"
}
],
"source": {
"advisory": "GHSA-r6g4-5m3x-xrqj",
"discovery": "UNKNOWN"
},
"title": "Vvveb: Server-side request forgery in Vvveb via IPv6 bypass of validateUrl() in editor oEmbed proxy"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-55232",
"datePublished": "2026-10-01T18:43:19.102Z",
"dateReserved": "2026-06-16T16:44:00.623Z",
"dateUpdated": "2026-10-01T18:43:19.102Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-55230 (GCVE-0-2026-55230)
Vulnerability from cvelistv5 – Published: 2026-10-01 18:42 – Updated: 2026-10-01 19:23
VLAI
EPSS
VEX
Title
Vvveb: Stored XSS in Vvveb via sanitizeHTML() filter bypass using a quoted greater-than character
Summary
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's HTML sanitizer fails to strip event-handler attributes when a tag carries a greater-than character inside a quoted attribute value. A low-privilege content author (default role author or contributor) can store a payload in post or product content that runs JavaScript in a browser of every visitor and of any administrator who views or previews that content, which opens a path to admin account takeover. This issue has been patched in version 1.0.8.6.
Severity
8.7 (High)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 19:22 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/givanz/Vvveb/security/advisori… | x_refsource_CONFIRM |
| https://github.com/givanz/Vvveb/releases/tag/1.0.8.6 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-55230",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T19:22:58.340870Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T19:23:19.200Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/givanz/Vvveb/security/advisories/GHSA-97xr-82vc-wj2v"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "Vvveb",
"vendor": "givanz",
"versions": [
{
"status": "affected",
"version": "\u003c 1.0.8.6"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb\u0027s HTML sanitizer fails to strip event-handler attributes when a tag carries a greater-than character inside a quoted attribute value. A low-privilege content author (default role author or contributor) can store a payload in post or product content that runs JavaScript in a browser of every visitor and of any administrator who views or previews that content, which opens a path to admin account takeover. This issue has been patched in version 1.0.8.6."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:42:50.082Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/givanz/Vvveb/security/advisories/GHSA-97xr-82vc-wj2v",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/givanz/Vvveb/security/advisories/GHSA-97xr-82vc-wj2v"
},
{
"name": "https://github.com/givanz/Vvveb/releases/tag/1.0.8.6",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/givanz/Vvveb/releases/tag/1.0.8.6"
}
],
"source": {
"advisory": "GHSA-97xr-82vc-wj2v",
"discovery": "UNKNOWN"
},
"title": "Vvveb: Stored XSS in Vvveb via sanitizeHTML() filter bypass using a quoted greater-than character"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-55230",
"datePublished": "2026-10-01T18:42:50.082Z",
"dateReserved": "2026-06-16T16:16:32.628Z",
"dateUpdated": "2026-10-01T19:23:19.200Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-55231 (GCVE-0-2026-55231)
Vulnerability from cvelistv5 – Published: 2026-10-01 18:42 – Updated: 2026-10-01 18:59
VLAI
EPSS
VEX
Title
Vvveb: Path traversal in Vvveb via sanitizeFileName() bypass enables arbitrary file read and delete through backup tools
Summary
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, a flawed central path sanitizer lets an authenticated admin-panel user who holds backup access (default role site_admin or higher) read and delete arbitrary files on a server. An attacker can recover database credentials from config/db.php, read host files such as /etc/passwd, and delete config/db.php to push a site back into install mode for a full takeover. This issue has been patched in version 1.0.8.6.
Severity
7.2 (High)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:59 UTC
CWE
- CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/givanz/Vvveb/security/advisori… | x_refsource_CONFIRM |
| https://github.com/givanz/Vvveb/releases/tag/1.0.8.6 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-55231",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T18:59:22.893518Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:59:51.696Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/givanz/Vvveb/security/advisories/GHSA-327v-4f9p-5qxq"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "Vvveb",
"vendor": "givanz",
"versions": [
{
"status": "affected",
"version": "\u003c 1.0.8.6"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, a flawed central path sanitizer lets an authenticated admin-panel user who holds backup access (default role site_admin or higher) read and delete arbitrary files on a server. An attacker can recover database credentials from config/db.php, read host files such as /etc/passwd, and delete config/db.php to push a site back into install mode for a full takeover. This issue has been patched in version 1.0.8.6."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:42:39.182Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/givanz/Vvveb/security/advisories/GHSA-327v-4f9p-5qxq",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/givanz/Vvveb/security/advisories/GHSA-327v-4f9p-5qxq"
},
{
"name": "https://github.com/givanz/Vvveb/releases/tag/1.0.8.6",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/givanz/Vvveb/releases/tag/1.0.8.6"
}
],
"source": {
"advisory": "GHSA-327v-4f9p-5qxq",
"discovery": "UNKNOWN"
},
"title": "Vvveb: Path traversal in Vvveb via sanitizeFileName() bypass enables arbitrary file read and delete through backup tools"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-55231",
"datePublished": "2026-10-01T18:42:39.182Z",
"dateReserved": "2026-06-16T16:44:00.623Z",
"dateUpdated": "2026-10-01T18:59:51.696Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-55083 (GCVE-0-2026-55083)
Vulnerability from cvelistv5 – Published: 2026-10-01 18:00 – Updated: 2026-10-01 18:30
VLAI
EPSS
VEX
Title
DHIS2: Unsafe Java Deserialization - Remote Code Execution (RCE)
Summary
DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. From versions 2.42.0 to before 2.42.5.1, and from versions 2.43.0 to before 2.43.0.1, DHIS2 is vulnerable to remote code execution (RCE) via unsafe Java deserialization. This issue has been patched in versions 2.42.5.1, 2.43.0.1, and 2.44.
Severity
9.1 (Critical)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:30 UTC
CWE
- CWE-502 - Deserialization of Untrusted Data
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/dhis2/dhis2-core/security/advi… | x_refsource_CONFIRM |
| https://github.com/dhis2/dhis2-core/releases/tag/… | x_refsource_MISC |
| https://github.com/dhis2/dhis2-core/releases/tag/… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| dhis2 | dhis2-core |
Affected:
>= 2.42.0, < 2.42.5.1
Affected: >= 2.43.0, < 2.43.0.1 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-55083",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T18:30:31.099135Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:30:36.526Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "dhis2-core",
"vendor": "dhis2",
"versions": [
{
"status": "affected",
"version": "\u003e= 2.42.0, \u003c 2.42.5.1"
},
{
"status": "affected",
"version": "\u003e= 2.43.0, \u003c 2.43.0.1"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. From versions 2.42.0 to before 2.42.5.1, and from versions 2.43.0 to before 2.43.0.1, DHIS2 is vulnerable to remote code execution (RCE) via unsafe Java deserialization. This issue has been patched in versions 2.42.5.1, 2.43.0.1, and 2.44."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-502",
"description": "CWE-502: Deserialization of Untrusted Data",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:00:05.332Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/dhis2/dhis2-core/security/advisories/GHSA-3fr2-wvqx-cmr5",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/dhis2/dhis2-core/security/advisories/GHSA-3fr2-wvqx-cmr5"
},
{
"name": "https://github.com/dhis2/dhis2-core/releases/tag/2.42.5.1",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/dhis2/dhis2-core/releases/tag/2.42.5.1"
},
{
"name": "https://github.com/dhis2/dhis2-core/releases/tag/2.43.0.1",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/dhis2/dhis2-core/releases/tag/2.43.0.1"
}
],
"source": {
"advisory": "GHSA-3fr2-wvqx-cmr5",
"discovery": "UNKNOWN"
},
"title": "DHIS2: Unsafe Java Deserialization - Remote Code Execution (RCE)"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-55083",
"datePublished": "2026-10-01T18:00:05.332Z",
"dateReserved": "2026-06-16T14:33:35.711Z",
"dateUpdated": "2026-10-01T18:30:36.526Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103923 (GCVE-0-2026-103923)
Vulnerability from cvelistv5 – Published: 2026-10-01 17:37 – Updated: 2026-10-01 17:37
VLAI
EPSS
VEX
Title
KaTeX: Existing prototype pollution can bypass trust restrictions
Summary
KaTeX is a fast, easy-to-use JavaScript library for TeX math rendering on the web. From 0.11.0 until 0.18.2, KaTeX uses ordinary JavaScript property access for the renderer options object, the trust setting, default and processor setting metadata, and namespace lookup and group restoration, allowing inherited properties to be treated as explicitly supplied values. When Object.prototype is already polluted or an attacker controls the options object's prototype, attacker-controlled mathematical expressions can use an inherited trust value to enable trusted rendering and produce links capable of user-interaction cross-site scripting or loading attacker-selected external resources in a consuming application that inserts unsanitized KaTeX output into a page. KaTeX does not itself create the prototype pollution, and rendering an expression alone does not execute script. This issue is fixed in version 0.18.2.
Severity
CWE
- CWE-807 - Reliance on Untrusted Inputs in a Security Decision
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://github.com/KaTeX/KaTeX/security/advisorie… | x_refsource_CONFIRM |
| https://github.com/KaTeX/KaTeX/pull/4260 | x_refsource_MISC |
| https://github.com/KaTeX/KaTeX/commit/0adf7e77db6… | x_refsource_MISC |
| https://github.com/KaTeX/KaTeX/releases/tag/v0.18.2 | x_refsource_MISC |
{
"containers": {
"cna": {
"affected": [
{
"product": "KaTeX",
"vendor": "KaTeX",
"versions": [
{
"status": "affected",
"version": "\u003e= 0.11.0, \u003c 0.18.2"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "KaTeX is a fast, easy-to-use JavaScript library for TeX math rendering on the web. From 0.11.0 until 0.18.2, KaTeX uses ordinary JavaScript property access for the renderer options object, the trust setting, default and processor setting metadata, and namespace lookup and group restoration, allowing inherited properties to be treated as explicitly supplied values. When Object.prototype is already polluted or an attacker controls the options object\u0027s prototype, attacker-controlled mathematical expressions can use an inherited trust value to enable trusted rendering and produce links capable of user-interaction cross-site scripting or loading attacker-selected external resources in a consuming application that inserts unsanitized KaTeX output into a page. KaTeX does not itself create the prototype pollution, and rendering an expression alone does not execute script. This issue is fixed in version 0.18.2."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 2.1,
"baseSeverity": "LOW",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "ACTIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-807",
"description": "CWE-807: Reliance on Untrusted Inputs in a Security Decision",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T17:37:47.953Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/KaTeX/KaTeX/security/advisories/GHSA-238p-pmpm-9mq7",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/KaTeX/KaTeX/security/advisories/GHSA-238p-pmpm-9mq7"
},
{
"name": "https://github.com/KaTeX/KaTeX/pull/4260",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/KaTeX/KaTeX/pull/4260"
},
{
"name": "https://github.com/KaTeX/KaTeX/commit/0adf7e77db6915d991803b29699f82b1ccf8d4f4",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/KaTeX/KaTeX/commit/0adf7e77db6915d991803b29699f82b1ccf8d4f4"
},
{
"name": "https://github.com/KaTeX/KaTeX/releases/tag/v0.18.2",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/KaTeX/KaTeX/releases/tag/v0.18.2"
}
],
"source": {
"advisory": "GHSA-238p-pmpm-9mq7",
"discovery": "UNKNOWN"
},
"title": "KaTeX: Existing prototype pollution can bypass trust restrictions"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-103923",
"datePublished": "2026-10-01T17:37:47.953Z",
"dateReserved": "2026-10-01T14:20:19.154Z",
"dateUpdated": "2026-10-01T17:37:47.953Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103922 (GCVE-0-2026-103922)
Vulnerability from cvelistv5 – Published: 2026-10-01 17:27 – Updated: 2026-10-01 18:01
VLAI
EPSS
VEX
Title
Capacitor Android and iOS: remote content can be loaded at the app origin via the internal HTTP proxy path
Summary
Capacitor is a cross-platform native runtime for web applications. From 6.0.0 until 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1, the Android and iOS WebView navigation guard validates a target URL's host and scheme but not its path, allowing a victim who activates an untrusted link to navigate a frame to /_capacitor_http_interceptor_. The native proxy can fetch an attacker-selected URL and return the response as a document at the application's own origin, allowing script in that response to access same-origin storage, cookies, and registered Capacitor plugin capabilities. Applications remain affected when CapacitorHttp is disabled because affected releases serve the proxy path regardless of that setting. This issue is fixed in versions 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1.
Severity
9.3 (Critical)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:01 UTC
CWE
Assigner
References
8 references
| URL | Tags |
|---|---|
| https://github.com/ionic-team/capacitor/security/… | x_refsource_CONFIRM |
| https://github.com/ionic-team/capacitor/commit/43… | x_refsource_MISC |
| https://github.com/ionic-team/capacitor/commit/80… | x_refsource_MISC |
| https://github.com/ionic-team/capacitor/commit/85… | x_refsource_MISC |
| https://github.com/ionic-team/capacitor/commit/af… | x_refsource_MISC |
| https://github.com/ionic-team/capacitor/commit/d5… | x_refsource_MISC |
| https://github.com/ionic-team/capacitor/commit/ee… | x_refsource_MISC |
| https://github.com/ionic-team/capacitor/releases/… | x_refsource_MISC |
Impacted products
5 products
| Vendor | Product | Version | |
|---|---|---|---|
| ionic-team | capacitor |
Affected:
>= 6.0.0, < 6.2.2
Affected: >= 7.0.0, < 7.6.9 Affected: >= 8.0.0, < 8.3.5 Affected: >= 8.3.5, < 8.4.3 Affected: >= 8.5.0, < 8.5.1 |
|
| @capacitor | android |
Affected:
>= 8.5.0, < 8.5.1
Affected: >= 8.3.5, < 8.4.3 Affected: >= 8.0.0, < 8.3.5 Affected: >= 7.0.0, < 7.6.9 Affected: >= 6.0.0, < 6.2.2 |
|
| @capacitor | ios |
Affected:
>= 8.5.0, < 8.5.1
Affected: >= 8.3.5, < 8.4.3 Affected: >= 8.0.0, < 8.3.5 Affected: >= 7.0.0, < 7.6.9 Affected: >= 6.0.0, < 6.2.2 |
|
| com.capacitorjs | core |
Affected:
>= 8.5.0, < 8.5.1
Affected: >= 8.3.5, < 8.4.3 Affected: >= 8.0.0, < 8.3.5 Affected: >= 7.0.0, < 7.6.9 Affected: >= 6.0.0, < 6.2.2 |
|
| swift | github.com/ionic-team/capacitor-swift-pm |
Affected:
>= 8.5.0, < 8.5.1
Affected: >= 8.3.5, < 8.4.3 Affected: >= 8.0.0, < 8.3.5 Affected: >= 7.0.0, < 7.6.9 Affected: >= 6.0.0, < 6.2.2 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103922",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T18:01:35.925716Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:01:54.381Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "capacitor",
"vendor": "ionic-team",
"versions": [
{
"status": "affected",
"version": "\u003e= 6.0.0, \u003c 6.2.2"
},
{
"status": "affected",
"version": "\u003e= 7.0.0, \u003c 7.6.9"
},
{
"status": "affected",
"version": "\u003e= 8.0.0, \u003c 8.3.5"
},
{
"status": "affected",
"version": "\u003e= 8.3.5, \u003c 8.4.3"
},
{
"status": "affected",
"version": "\u003e= 8.5.0, \u003c 8.5.1"
}
]
},
{
"product": "android",
"vendor": "@capacitor",
"versions": [
{
"status": "affected",
"version": "\u003e= 8.5.0, \u003c 8.5.1"
},
{
"status": "affected",
"version": "\u003e= 8.3.5, \u003c 8.4.3"
},
{
"status": "affected",
"version": "\u003e= 8.0.0, \u003c 8.3.5"
},
{
"status": "affected",
"version": "\u003e= 7.0.0, \u003c 7.6.9"
},
{
"status": "affected",
"version": "\u003e= 6.0.0, \u003c 6.2.2"
}
]
},
{
"product": "ios",
"vendor": "@capacitor",
"versions": [
{
"status": "affected",
"version": "\u003e= 8.5.0, \u003c 8.5.1"
},
{
"status": "affected",
"version": "\u003e= 8.3.5, \u003c 8.4.3"
},
{
"status": "affected",
"version": "\u003e= 8.0.0, \u003c 8.3.5"
},
{
"status": "affected",
"version": "\u003e= 7.0.0, \u003c 7.6.9"
},
{
"status": "affected",
"version": "\u003e= 6.0.0, \u003c 6.2.2"
}
]
},
{
"product": "core",
"vendor": "com.capacitorjs",
"versions": [
{
"status": "affected",
"version": "\u003e= 8.5.0, \u003c 8.5.1"
},
{
"status": "affected",
"version": "\u003e= 8.3.5, \u003c 8.4.3"
},
{
"status": "affected",
"version": "\u003e= 8.0.0, \u003c 8.3.5"
},
{
"status": "affected",
"version": "\u003e= 7.0.0, \u003c 7.6.9"
},
{
"status": "affected",
"version": "\u003e= 6.0.0, \u003c 6.2.2"
}
]
},
{
"product": "github.com/ionic-team/capacitor-swift-pm",
"vendor": "swift",
"versions": [
{
"status": "affected",
"version": "\u003e= 8.5.0, \u003c 8.5.1"
},
{
"status": "affected",
"version": "\u003e= 8.3.5, \u003c 8.4.3"
},
{
"status": "affected",
"version": "\u003e= 8.0.0, \u003c 8.3.5"
},
{
"status": "affected",
"version": "\u003e= 7.0.0, \u003c 7.6.9"
},
{
"status": "affected",
"version": "\u003e= 6.0.0, \u003c 6.2.2"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Capacitor is a cross-platform native runtime for web applications. From 6.0.0 until 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1, the Android and iOS WebView navigation guard validates a target URL\u0027s host and scheme but not its path, allowing a victim who activates an untrusted link to navigate a frame to /_capacitor_http_interceptor_. The native proxy can fetch an attacker-selected URL and return the response as a document at the application\u0027s own origin, allowing script in that response to access same-origin storage, cookies, and registered Capacitor plugin capabilities. Applications remain affected when CapacitorHttp is disabled because affected releases serve the proxy path regardless of that setting. This issue is fixed in versions 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-346",
"description": "CWE-346: Origin Validation Error",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-441",
"description": "CWE-441: Unintended Proxy or Intermediary (\u0027Confused Deputy\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T17:27:05.758Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/ionic-team/capacitor/security/advisories/GHSA-rvm3-566m-v7fv",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/ionic-team/capacitor/security/advisories/GHSA-rvm3-566m-v7fv"
},
{
"name": "https://github.com/ionic-team/capacitor/commit/430356a91e1419fc66862dc09835081aa501677e",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/ionic-team/capacitor/commit/430356a91e1419fc66862dc09835081aa501677e"
},
{
"name": "https://github.com/ionic-team/capacitor/commit/80b6c5e81d062e1e158914040f49e044d95b7ccb",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/ionic-team/capacitor/commit/80b6c5e81d062e1e158914040f49e044d95b7ccb"
},
{
"name": "https://github.com/ionic-team/capacitor/commit/85ccc44151fdd5ae5e0d806d875766ef4b84ad5d",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/ionic-team/capacitor/commit/85ccc44151fdd5ae5e0d806d875766ef4b84ad5d"
},
{
"name": "https://github.com/ionic-team/capacitor/commit/af9a287fef45f0ac68ce640cb42fed2d06b0f1b4",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/ionic-team/capacitor/commit/af9a287fef45f0ac68ce640cb42fed2d06b0f1b4"
},
{
"name": "https://github.com/ionic-team/capacitor/commit/d5e3170ba0ff155fc542b7e6d16cff5201406540",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/ionic-team/capacitor/commit/d5e3170ba0ff155fc542b7e6d16cff5201406540"
},
{
"name": "https://github.com/ionic-team/capacitor/commit/ee586ae680887ba99d066616f976db149542d922",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/ionic-team/capacitor/commit/ee586ae680887ba99d066616f976db149542d922"
},
{
"name": "https://github.com/ionic-team/capacitor/releases/tag/8.5.1",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/ionic-team/capacitor/releases/tag/8.5.1"
}
],
"source": {
"advisory": "GHSA-rvm3-566m-v7fv",
"discovery": "UNKNOWN"
},
"title": "Capacitor Android and iOS: remote content can be loaded at the app origin via the internal HTTP proxy path"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-103922",
"datePublished": "2026-10-01T17:27:05.758Z",
"dateReserved": "2026-10-01T14:20:19.154Z",
"dateUpdated": "2026-10-01T18:01:54.381Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-73976 (GCVE-0-2026-73976)
Vulnerability from cvelistv5 – Published: 2026-10-01 17:08 – Updated: 2026-10-01 17:58
VLAI
EPSS
VEX
Title
djehuty: Unauthenticated SPARQL injection in the search API (`order`, `operator`, `key`)
Summary
djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, An unauthenticated attacker can inject SPARQL into the search/listing queries through three separate parameters. Because the affected queries are read (SELECT) queries, this does not write to the store, but it allows: Cross-graph data exfiltration — e.g. UNION-ing in triples from graphs the request was never scoped to (drafts/private/internal data held in the RDF store); denial of service — expensive or malformed queries that tie up the SPARQL backend / web workers. No account or user interaction is required. This issue has been patched in version 26.3.2.
Severity
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 17:55 UTC
CWE
- CWE-943 - Improper Neutralization of Special Elements in Data Query Logic
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/4TUResearchData/djehuty/securi… | x_refsource_CONFIRM |
| https://github.com/4TUResearchData/djehuty/releas… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| 4TUResearchData | djehuty |
Affected:
< 26.3.2
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-73976",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T17:55:44.494192Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T17:58:15.800Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/4TUResearchData/djehuty/security/advisories/GHSA-7gp2-rxw9-vw6p"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "djehuty",
"vendor": "4TUResearchData",
"versions": [
{
"status": "affected",
"version": "\u003c 26.3.2"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, An unauthenticated attacker can inject SPARQL into the search/listing queries through three separate parameters. Because the affected queries are read (SELECT) queries, this does not write to the store, but it allows: Cross-graph data exfiltration \u2014 e.g. UNION-ing in triples from graphs the request was never scoped to (drafts/private/internal data held in the RDF store); denial of service \u2014 expensive or malformed queries that tie up the SPARQL backend / web workers. No account or user interaction is required. This issue has been patched in version 26.3.2."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-943",
"description": "CWE-943: Improper Neutralization of Special Elements in Data Query Logic",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T17:08:11.924Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/4TUResearchData/djehuty/security/advisories/GHSA-7gp2-rxw9-vw6p",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/4TUResearchData/djehuty/security/advisories/GHSA-7gp2-rxw9-vw6p"
},
{
"name": "https://github.com/4TUResearchData/djehuty/releases/tag/v26.3.2",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/4TUResearchData/djehuty/releases/tag/v26.3.2"
}
],
"source": {
"advisory": "GHSA-7gp2-rxw9-vw6p",
"discovery": "UNKNOWN"
},
"title": "djehuty: Unauthenticated SPARQL injection in the search API (`order`, `operator`, `key`)"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-73976",
"datePublished": "2026-10-01T17:08:11.924Z",
"dateReserved": "2026-08-13T21:42:04.045Z",
"dateUpdated": "2026-10-01T17:58:15.800Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-73975 (GCVE-0-2026-73975)
Vulnerability from cvelistv5 – Published: 2026-10-01 16:41 – Updated: 2026-10-01 16:41
VLAI
EPSS
VEX
Title
djehuty: Authenticated SPARQL injection in session editing allows writing arbitrary RDF triples
Summary
djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, an authenticated depositor can inject arbitrary SPARQL into a state-modifying (DELETE/INSERT) query by supplying a crafted session name, letting them write (and delete) arbitrary triples anywhere in the RDF store. Because the RDF store is shared across all accounts and datasets, this is an integrity compromise of the whole repository's metadata, not just the attacker's own records. Having a logged-in account is a precondition. djehuty allows self-registration via ORCID/SAML, so this is a low barrier in typical deployments. This issue has been patched in version 26.3.2.
Severity
CWE
- CWE-943 - Improper Neutralization of Special Elements in Data Query Logic
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/4TUResearchData/djehuty/securi… | x_refsource_CONFIRM |
| https://github.com/4TUResearchData/djehuty/releas… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| 4TUResearchData | djehuty |
Affected:
< 26.3.2
|
{
"containers": {
"cna": {
"affected": [
{
"product": "djehuty",
"vendor": "4TUResearchData",
"versions": [
{
"status": "affected",
"version": "\u003c 26.3.2"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, an authenticated depositor can inject arbitrary SPARQL into a state-modifying (DELETE/INSERT) query by supplying a crafted session name, letting them write (and delete) arbitrary triples anywhere in the RDF store. Because the RDF store is shared across all accounts and datasets, this is an integrity compromise of the whole repository\u0027s metadata, not just the attacker\u0027s own records. Having a logged-in account is a precondition. djehuty allows self-registration via ORCID/SAML, so this is a low barrier in typical deployments. This issue has been patched in version 26.3.2."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.4,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "HIGH",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-943",
"description": "CWE-943: Improper Neutralization of Special Elements in Data Query Logic",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T16:41:18.845Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/4TUResearchData/djehuty/security/advisories/GHSA-9864-23x8-762h",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/4TUResearchData/djehuty/security/advisories/GHSA-9864-23x8-762h"
},
{
"name": "https://github.com/4TUResearchData/djehuty/releases/tag/v26.3.2",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/4TUResearchData/djehuty/releases/tag/v26.3.2"
}
],
"source": {
"advisory": "GHSA-9864-23x8-762h",
"discovery": "UNKNOWN"
},
"title": "djehuty: Authenticated SPARQL injection in session editing allows writing arbitrary RDF triples"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-73975",
"datePublished": "2026-10-01T16:41:18.845Z",
"dateReserved": "2026-08-13T21:42:04.045Z",
"dateUpdated": "2026-10-01T16:41:18.845Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-77387 (GCVE-0-2026-77387)
Vulnerability from cvelistv5 – Published: 2026-10-01 16:38 – Updated: 2026-10-01 17:50
VLAI
EPSS
VEX
Title
geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point
Summary
geopy is a geocoding library for Python. Prior to 2.5.0, geopy.Point and Point.from_string() can spend excessive CPU time due to inefficient regular-expression behavior when an application passes a long malformed coordinate string without the 256-character input limit used by the fix. Geocoder reverse methods also reach the vulnerable parsing path when called with string inputs. Repeated attacker-controlled requests can cause a denial of service, while the numeric Point constructor is unaffected. This issue is fixed in version 2.5.0.
Severity
4 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 17:50 UTC
CWE
- CWE-1333 - Inefficient Regular Expression Complexity
Assigner
References
5 references
| URL | Tags |
|---|---|
| https://github.com/geopy/geopy/security/advisorie… | x_refsource_CONFIRM |
| https://github.com/geopy/geopy/issues/608 | x_refsource_MISC |
| https://github.com/geopy/geopy/pull/610 | x_refsource_MISC |
| https://github.com/geopy/geopy/commit/5d09fa843f9… | x_refsource_MISC |
| https://github.com/geopy/geopy/releases/tag/2.5.0 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-77387",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T17:50:15.527973Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T17:50:39.404Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/geopy/geopy/issues/608"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "geopy",
"vendor": "geopy",
"versions": [
{
"status": "affected",
"version": "\u003c 2.5.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "geopy is a geocoding library for Python. Prior to 2.5.0, geopy.Point and Point.from_string() can spend excessive CPU time due to inefficient regular-expression behavior when an application passes a long malformed coordinate string without the 256-character input limit used by the fix. Geocoder reverse methods also reach the vulnerable parsing path when called with string inputs. Repeated attacker-controlled requests can cause a denial of service, while the numeric Point constructor is unaffected. This issue is fixed in version 2.5.0."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "LOW",
"baseScore": 4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1333",
"description": "CWE-1333: Inefficient Regular Expression Complexity",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T16:38:54.176Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/geopy/geopy/security/advisories/GHSA-mhvh-fq92-pfmr",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/geopy/geopy/security/advisories/GHSA-mhvh-fq92-pfmr"
},
{
"name": "https://github.com/geopy/geopy/issues/608",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/geopy/geopy/issues/608"
},
{
"name": "https://github.com/geopy/geopy/pull/610",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/geopy/geopy/pull/610"
},
{
"name": "https://github.com/geopy/geopy/commit/5d09fa843f90ec80788b61552539c9fd3ae6c528",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/geopy/geopy/commit/5d09fa843f90ec80788b61552539c9fd3ae6c528"
},
{
"name": "https://github.com/geopy/geopy/releases/tag/2.5.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/geopy/geopy/releases/tag/2.5.0"
}
],
"source": {
"advisory": "GHSA-mhvh-fq92-pfmr",
"discovery": "UNKNOWN"
},
"title": "geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-77387",
"datePublished": "2026-10-01T16:38:54.176Z",
"dateReserved": "2026-08-20T19:36:13.806Z",
"dateUpdated": "2026-10-01T17:50:39.404Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103921 (GCVE-0-2026-103921)
Vulnerability from cvelistv5 – Published: 2026-10-01 16:32 – Updated: 2026-10-01 18:04
VLAI
EPSS
VEX
Title
GraphQL Tools: TLS Certificate Validation Disabled in Legacy GraphQL WebSocket Executor
Summary
GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 1.1.35, the executor-legacy-ws buildWSLegacyExecutor() function hardcodes TLS certificate rejection off for Node.js connections to wss:// endpoints. Applications using the executor directly, or url-loader with SubscriptionProtocol.LEGACY_WS, can therefore accept an attacker-controlled certificate when a network-positioned attacker intercepts the connection. Authentication material in connectionParams or headers can be disclosed, and subscription data can be modified. Browser WebSocket clients are unaffected because browsers enforce certificate validation. This issue is fixed in version 1.1.35.
Severity
7.4 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:04 UTC
CWE
- CWE-295 - Improper Certificate Validation
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://github.com/ardatan/graphql-tools/security… | x_refsource_CONFIRM |
| https://github.com/ardatan/graphql-tools/pull/8426 | x_refsource_MISC |
| https://github.com/ardatan/graphql-tools/commit/3… | x_refsource_MISC |
| https://github.com/ardatan/graphql-tools/releases… | x_refsource_MISC |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| ardatan | graphql-tools |
Affected:
< 1.1.35
|
|
| @graphql-tools | executor-legacy-ws |
Affected:
< 1.1.35
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103921",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T18:04:13.318417Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:04:28.083Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "graphql-tools",
"vendor": "ardatan",
"versions": [
{
"status": "affected",
"version": "\u003c 1.1.35"
}
]
},
{
"product": "executor-legacy-ws",
"vendor": "@graphql-tools",
"versions": [
{
"status": "affected",
"version": "\u003c 1.1.35"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 1.1.35, the executor-legacy-ws buildWSLegacyExecutor() function hardcodes TLS certificate rejection off for Node.js connections to wss:// endpoints. Applications using the executor directly, or url-loader with SubscriptionProtocol.LEGACY_WS, can therefore accept an attacker-controlled certificate when a network-positioned attacker intercepts the connection. Authentication material in connectionParams or headers can be disclosed, and subscription data can be modified. Browser WebSocket clients are unaffected because browsers enforce certificate validation. This issue is fixed in version 1.1.35."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-295",
"description": "CWE-295: Improper Certificate Validation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T16:32:37.865Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/ardatan/graphql-tools/security/advisories/GHSA-6fw5-9hq8-w87g",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/ardatan/graphql-tools/security/advisories/GHSA-6fw5-9hq8-w87g"
},
{
"name": "https://github.com/ardatan/graphql-tools/pull/8426",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/ardatan/graphql-tools/pull/8426"
},
{
"name": "https://github.com/ardatan/graphql-tools/commit/3831a0661514c91d99971052f983552556880402",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/ardatan/graphql-tools/commit/3831a0661514c91d99971052f983552556880402"
},
{
"name": "https://github.com/ardatan/graphql-tools/releases/tag/@graphql-tools/executor-legacy-ws@1.1.35",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/ardatan/graphql-tools/releases/tag/@graphql-tools/executor-legacy-ws@1.1.35"
}
],
"source": {
"advisory": "GHSA-6fw5-9hq8-w87g",
"discovery": "UNKNOWN"
},
"title": "GraphQL Tools: TLS Certificate Validation Disabled in Legacy GraphQL WebSocket Executor"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-103921",
"datePublished": "2026-10-01T16:32:37.865Z",
"dateReserved": "2026-10-01T14:20:19.154Z",
"dateUpdated": "2026-10-01T18:04:28.083Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-94620 (GCVE-0-2026-94620)
Vulnerability from cvelistv5 – Published: 2026-10-01 15:38 – Updated: 2026-10-01 16:18
VLAI
EPSS
VEX
Title
Classroom 50 vulnerable to arbitrary file overwrite on the teacher's machine via symlink in a student repo (gh teacher download)
Summary
Classroom 50 is a free and open-source tool for managing and grading programming assignments via GitHub. Prior to version 1.11.0, `gh teacher download` clones each student's assignment repository and then writes autograde artifacts (`result.json` and `results.json`) into the just-cloned working tree. The write followed symlinks, so a student who committed `result.json` or `results.json` as a **symlink** (materialized verbatim by `git clone`) could redirect the teacher's write to an arbitrary path — e.g. `~/.zshrc`, `~/.ssh/authorized_keys`, a cron file, or an in-clone `.git/hooks/*` file that git subsequently executes. The written bytes are attacker-controlled (the student's uploaded release asset for `result.json`; student-chosen submit-tag names for `results.json`). This is an arbitrary file write leading to code execution as the teacher, whose `gh` token carries `admin:org`, `repo`, and `workflow` across the entire classroom organization. Version 1.11.0 contains a patch. Some workarounds are available. Avoid running `gh teacher download` against untrusted student repositories, or run it inside a disposable sandbox / container with no access to sensitive host files or credentials. Inspect cloned trees for symlinked, hardlinked, or special (`result.json`/`results.json`) entries before allowing the artifact-refresh step to run.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 16:17 UTC
CWE
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/foundation50/classroom50/secur… | x_refsource_CONFIRM |
| https://github.com/foundation50/classroom50/commi… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| foundation50 | classroom50 |
Affected:
< 1.11.0
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-94620",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T16:17:49.043303Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T16:18:58.240Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "classroom50",
"vendor": "foundation50",
"versions": [
{
"status": "affected",
"version": "\u003c 1.11.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Classroom 50 is a free and open-source tool for managing and grading programming assignments via GitHub. Prior to version 1.11.0, `gh teacher download` clones each student\u0027s assignment repository and then writes autograde artifacts (`result.json` and `results.json`) into the just-cloned working tree. The write followed symlinks, so a student who committed `result.json` or `results.json` as a **symlink** (materialized verbatim by `git clone`) could redirect the teacher\u0027s write to an arbitrary path \u2014 e.g. `~/.zshrc`, `~/.ssh/authorized_keys`, a cron file, or an in-clone `.git/hooks/*` file that git subsequently executes. The written bytes are attacker-controlled (the student\u0027s uploaded release asset for `result.json`; student-chosen submit-tag names for `results.json`). This is an arbitrary file write leading to code execution as the teacher, whose `gh` token carries `admin:org`, `repo`, and `workflow` across the entire classroom organization. Version 1.11.0 contains a patch. Some workarounds are available. Avoid running `gh teacher download` against untrusted student repositories, or run it inside a disposable sandbox / container with no access to sensitive host files or credentials. Inspect cloned trees for symlinked, hardlinked, or special (`result.json`/`results.json`) entries before allowing the artifact-refresh step to run."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.4,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "HIGH",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-59",
"description": "CWE-59: Improper Link Resolution Before File Access (\u0027Link Following\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:38:09.062Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/foundation50/classroom50/security/advisories/GHSA-qx2g-vpwq-466c",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/foundation50/classroom50/security/advisories/GHSA-qx2g-vpwq-466c"
},
{
"name": "https://github.com/foundation50/classroom50/commit/79112f33932d1b5c398a8801d97a8813d52d55ce",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/foundation50/classroom50/commit/79112f33932d1b5c398a8801d97a8813d52d55ce"
}
],
"source": {
"advisory": "GHSA-qx2g-vpwq-466c",
"discovery": "UNKNOWN"
},
"title": "Classroom 50 vulnerable to arbitrary file overwrite on the teacher\u0027s machine via symlink in a student repo (gh teacher download)"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-94620",
"datePublished": "2026-10-01T15:38:09.062Z",
"dateReserved": "2026-09-21T21:32:23.742Z",
"dateUpdated": "2026-10-01T16:18:58.240Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103004 (GCVE-0-2026-103004)
Vulnerability from cvelistv5 – Published: 2026-10-01 14:50 – Updated: 2026-10-01 16:09
VLAI
EPSS
VEX
Title
next.js cache leak on warm `use cache` handlers accessing root param
Summary
Next.js versions from 16.3.0 to 16.3.7 warm `use cache` handlers using `next/root-params` and can leak their return value to pages with different root params. With Cache Components enabled (cacheComponents: true), a 'use cache' function that calls another 'use cache' function that reads a root param can be keyed incorrectly when the inner call is served from an existing entry: the enclosing function's cache key then omits that root param. The enclosing entry is written once and reused for all root param values, so a response for one root param value can serve content produced for a different value — whether the page is prerendered at build time or at runtime, or rendered dynamically. Shared cache headers let downstream caches redistribute the content further.
What values are leaked cannot be attacker controlled. Which value's content is served depends only on which invocation wrote the entry first.
This has been patched in 16.3.8.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 16:09 UTC
CWE
- CWE-524 - Use of Cache Containing Sensitive Information
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/vercel/next.js/security/adviso… | x_refsource_CONFIRM |
| https://github.com/vercel/next.js/releases/tag/v16.3.8 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103004",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T16:09:43.511822Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T16:09:53.178Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "next.js",
"vendor": "vercel",
"versions": [
{
"status": "affected",
"version": "\u003c 16.3.8"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Next.js versions from 16.3.0 to 16.3.7 warm `use cache` handlers using `next/root-params` and can leak their return value to pages with different root params. With Cache Components enabled (cacheComponents: true), a \u0027use cache\u0027 function that calls another \u0027use cache\u0027 function that reads a root param can be keyed incorrectly when the inner call is served from an existing entry: the enclosing function\u0027s cache key then omits that root param. The enclosing entry is written once and reused for all root param values, so a response for one root param value can serve content produced for a different value \u2014 whether the page is prerendered at build time or at runtime, or rendered dynamically. Shared cache headers let downstream caches redistribute the content further.\n\nWhat values are leaked cannot be attacker controlled. Which value\u0027s content is served depends only on which invocation wrote the entry first.\n\nThis has been patched in 16.3.8."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-524",
"description": "CWE-524: Use of Cache Containing Sensitive Information",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T14:50:27.033Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/vercel/next.js/security/advisories/GHSA-h694-7cp9-m8p3",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/vercel/next.js/security/advisories/GHSA-h694-7cp9-m8p3"
},
{
"name": "https://github.com/vercel/next.js/releases/tag/v16.3.8",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/vercel/next.js/releases/tag/v16.3.8"
}
],
"source": {
"advisory": "GHSA-h694-7cp9-m8p3",
"discovery": "UNKNOWN"
},
"title": "next.js cache leak on warm `use cache` handlers accessing root param"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-103004",
"datePublished": "2026-10-01T14:50:27.033Z",
"dateReserved": "2026-09-29T20:46:08.335Z",
"dateUpdated": "2026-10-01T16:09:53.178Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103001 (GCVE-0-2026-103001)
Vulnerability from cvelistv5 – Published: 2026-09-30 21:15 – Updated: 2026-09-30 21:17
VLAI
EPSS
VEX
Title
PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse
Summary
PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when verify_signature is false. If an application reuses that same mapping for a later decode() or decode_complete() call and changes verify_signature to true, the mapping can retain false values for expiration, not-before, issued-at, audience, issuer, subject, and JWT ID checks. A signed token with invalid registered claims can then be accepted without disabling signature verification, but applications that create a fresh options mapping for each call are not affected.
Severity
6.5 (Medium)
CWE
- CWE-471 - Modification of Assumed-Immutable Data (MAID)
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/jpadilla/pyjwt/security/adviso… | x_refsource_CONFIRM |
| https://github.com/jpadilla/pyjwt/issues/679 | x_refsource_MISC |
| https://github.com/jpadilla/pyjwt/commit/0c87c8c8… | x_refsource_MISC |
{
"containers": {
"cna": {
"affected": [
{
"product": "pyjwt",
"vendor": "jpadilla",
"versions": [
{
"status": "affected",
"version": "\u003e= 2.11.0, \u003c= 2.13.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT\u0027s PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when verify_signature is false. If an application reuses that same mapping for a later decode() or decode_complete() call and changes verify_signature to true, the mapping can retain false values for expiration, not-before, issued-at, audience, issuer, subject, and JWT ID checks. A signed token with invalid registered claims can then be accepted without disabling signature verification, but applications that create a fresh options mapping for each call are not affected."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-471",
"description": "CWE-471: Modification of Assumed-Immutable Data (MAID)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T21:17:58.116Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/jpadilla/pyjwt/security/advisories/GHSA-gvp8-978c-rx2q",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/jpadilla/pyjwt/security/advisories/GHSA-gvp8-978c-rx2q"
},
{
"name": "https://github.com/jpadilla/pyjwt/issues/679",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/jpadilla/pyjwt/issues/679"
},
{
"name": "https://github.com/jpadilla/pyjwt/commit/0c87c8c8b1a74cac99ad8115f3050efcb7fbed35",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/jpadilla/pyjwt/commit/0c87c8c8b1a74cac99ad8115f3050efcb7fbed35"
}
],
"source": {
"advisory": "GHSA-gvp8-978c-rx2q",
"discovery": "UNKNOWN"
},
"title": "PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-103001",
"datePublished": "2026-09-30T21:15:12.862Z",
"dateReserved": "2026-09-29T20:46:08.335Z",
"dateUpdated": "2026-09-30T21:17:58.116Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103000 (GCVE-0-2026-103000)
Vulnerability from cvelistv5 – Published: 2026-09-30 20:13 – Updated: 2026-09-30 20:49
VLAI
EPSS
VEX
Title
pypdf: Possible large memory usage when retrieving alphabetical page labels
Summary
pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF can provide unusually large alphabetical page-label values that cause pypdf/_page_labels.py to generate strings beyond a reasonable page-label length when an application retrieves document page labels, consuming excessive memory and potentially making the application unavailable. This issue is fixed in version 6.19.0.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 20:49 UTC
CWE
- CWE-400 - Uncontrolled Resource Consumption
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://github.com/py-pdf/pypdf/security/advisori… | x_refsource_CONFIRM |
| https://github.com/py-pdf/pypdf/pull/4096 | x_refsource_MISC |
| https://github.com/py-pdf/pypdf/commit/0d8b5a8832… | x_refsource_MISC |
| https://github.com/py-pdf/pypdf/releases/tag/6.19.0 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103000",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T20:49:14.062135Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T20:49:21.058Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "pypdf",
"vendor": "py-pdf",
"versions": [
{
"status": "affected",
"version": "\u003c 6.19.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF can provide unusually large alphabetical page-label values that cause pypdf/_page_labels.py to generate strings beyond a reasonable page-label length when an application retrieves document page labels, consuming excessive memory and potentially making the application unavailable. This issue is fixed in version 6.19.0."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-400",
"description": "CWE-400: Uncontrolled Resource Consumption",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T20:13:00.379Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/py-pdf/pypdf/security/advisories/GHSA-w23x-9jrw-r45c",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/py-pdf/pypdf/security/advisories/GHSA-w23x-9jrw-r45c"
},
{
"name": "https://github.com/py-pdf/pypdf/pull/4096",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/py-pdf/pypdf/pull/4096"
},
{
"name": "https://github.com/py-pdf/pypdf/commit/0d8b5a8832cde1ba308b5c27567b879b7b7eed4a",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/py-pdf/pypdf/commit/0d8b5a8832cde1ba308b5c27567b879b7b7eed4a"
},
{
"name": "https://github.com/py-pdf/pypdf/releases/tag/6.19.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/py-pdf/pypdf/releases/tag/6.19.0"
}
],
"source": {
"advisory": "GHSA-w23x-9jrw-r45c",
"discovery": "UNKNOWN"
},
"title": "pypdf: Possible large memory usage when retrieving alphabetical page labels"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-103000",
"datePublished": "2026-09-30T20:13:00.379Z",
"dateReserved": "2026-09-29T20:46:08.335Z",
"dateUpdated": "2026-09-30T20:49:21.058Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102999 (GCVE-0-2026-102999)
Vulnerability from cvelistv5 – Published: 2026-09-30 20:10 – Updated: 2026-10-01 18:51
VLAI
EPSS
VEX
Title
pypdf: Possible long runtimes with large amount of embedded files
Summary
pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF containing many embedded files can cause the dictionary-based attachments API in pypdf/_doc_common.py to reparse the full attachment list for each content lookup, producing repeated work and long runtimes when an application accesses the embedded-file mapping. This issue is fixed in version 6.19.0.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:51 UTC
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://github.com/py-pdf/pypdf/security/advisori… | x_refsource_CONFIRM |
| https://github.com/py-pdf/pypdf/pull/4081 | x_refsource_MISC |
| https://github.com/py-pdf/pypdf/commit/6b10556d13… | x_refsource_MISC |
| https://github.com/py-pdf/pypdf/releases/tag/6.19.0 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102999",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T18:51:12.395176Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:51:27.463Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "pypdf",
"vendor": "py-pdf",
"versions": [
{
"status": "affected",
"version": "\u003c 6.19.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF containing many embedded files can cause the dictionary-based attachments API in pypdf/_doc_common.py to reparse the full attachment list for each content lookup, producing repeated work and long runtimes when an application accesses the embedded-file mapping. This issue is fixed in version 6.19.0."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-400",
"description": "CWE-400: Uncontrolled Resource Consumption",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-407",
"description": "CWE-407: Inefficient Algorithmic Complexity",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T20:10:38.433Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/py-pdf/pypdf/security/advisories/GHSA-v247-6f48-mgcj",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/py-pdf/pypdf/security/advisories/GHSA-v247-6f48-mgcj"
},
{
"name": "https://github.com/py-pdf/pypdf/pull/4081",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/py-pdf/pypdf/pull/4081"
},
{
"name": "https://github.com/py-pdf/pypdf/commit/6b10556d13609a68f9ed18bb29fdd8bba88eb2c3",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/py-pdf/pypdf/commit/6b10556d13609a68f9ed18bb29fdd8bba88eb2c3"
},
{
"name": "https://github.com/py-pdf/pypdf/releases/tag/6.19.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/py-pdf/pypdf/releases/tag/6.19.0"
}
],
"source": {
"advisory": "GHSA-v247-6f48-mgcj",
"discovery": "UNKNOWN"
},
"title": "pypdf: Possible long runtimes with large amount of embedded files"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-102999",
"datePublished": "2026-09-30T20:10:38.433Z",
"dateReserved": "2026-09-29T20:46:08.335Z",
"dateUpdated": "2026-10-01T18:51:27.463Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}