Search

Find a vulnerability

Search criteria

    4 vulnerabilities by zoriya

    CVE-2026-77386 (GCVE-0-2026-77386)

    Vulnerability from nvd – Published: 2026-09-18 17:16 – Updated: 2026-09-22 15:09
    VLAI
    Title
    Kyoo: OIDC login token can be redirected to an attacker-controlled URL
    Summary
    Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, an unauthenticated attacker could initiate the OIDC login flow with an attacker-controlled redirectUrl. The login handling in auth/oidc.go stored that URL with the opaque login state, and /auth/oidc/logged/{provider} appended the provider, token, and error values before redirecting the victim's browser without validating the destination. Because the one-use token was not bound to the browser session that initiated login, an attacker who induced a victim to complete OIDC authentication could capture the token at the attacker-controlled destination and exchange it through /auth/oidc/callback/{provider} for the victim's Kyoo session. This issue is fixed in version 5.1.0.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-22 15:08 UTC
    CWE
    • CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')
    Impacted products
    Vendor Product Version
    zoriya Kyoo Affected: < 5.1.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77386",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-22T15:08:48.131175Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-22T15:09:09.067Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/zoriya/Kyoo/security/advisories/GHSA-xhg6-v78p-xf44"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Kyoo",
              "vendor": "zoriya",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 5.1.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, an unauthenticated attacker could initiate the OIDC login flow with an attacker-controlled redirectUrl. The login handling in auth/oidc.go stored that URL with the opaque login state, and /auth/oidc/logged/{provider} appended the provider, token, and error values before redirecting the victim\u0027s browser without validating the destination. Because the one-use token was not bound to the browser session that initiated login, an attacker who induced a victim to complete OIDC authentication could capture the token at the attacker-controlled destination and exchange it through /auth/oidc/callback/{provider} for the victim\u0027s Kyoo session. This issue is fixed in version 5.1.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-601",
                  "description": "CWE-601: URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-18T17:16:37.282Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/zoriya/Kyoo/security/advisories/GHSA-xhg6-v78p-xf44",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/zoriya/Kyoo/security/advisories/GHSA-xhg6-v78p-xf44"
            },
            {
              "name": "https://github.com/zoriya/Kyoo/pull/1576",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/zoriya/Kyoo/pull/1576"
            },
            {
              "name": "https://github.com/zoriya/Kyoo/commit/02ab3af8127a081295fd7bed103847173c0d7632",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/zoriya/Kyoo/commit/02ab3af8127a081295fd7bed103847173c0d7632"
            },
            {
              "name": "https://github.com/zoriya/Kyoo/releases/tag/v5.1.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/zoriya/Kyoo/releases/tag/v5.1.0"
            }
          ],
          "source": {
            "advisory": "GHSA-xhg6-v78p-xf44",
            "discovery": "UNKNOWN"
          },
          "title": "Kyoo: OIDC login token can be redirected to an attacker-controlled URL"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-77386",
        "datePublished": "2026-09-18T17:16:37.282Z",
        "dateReserved": "2026-08-20T19:36:13.806Z",
        "dateUpdated": "2026-09-22T15:09:09.067Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77385 (GCVE-0-2026-77385)

    Vulnerability from nvd – Published: 2026-09-18 17:15 – Updated: 2026-09-18 19:52
    VLAI
    Title
    Kyoo: Transcoder serves uncataloged files from the media directory
    Summary
    Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core.play permission could supply a base64-encoded filesystem path to the transcoder. The path handling in transcoder/src/api/path.go cleaned the value and checked only that it began with Settings.SafePath before getHash processed it, while transcoder/src/api/streams.go served the accepted path without verifying a Kyoo catalog record. This missing catalog-level authorization allowed the user to retrieve hidden, temporary, operational, or other uncataloged files beneath the media directory when the path was known or guessed. This vulnerability is fixed in 5.1.0.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-18 19:52 UTC
    CWE
    • CWE-639 - Authorization Bypass Through User-Controlled Key
    • CWE-862 - Missing Authorization
    Impacted products
    Vendor Product Version
    zoriya Kyoo Affected: < 5.1.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77385",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-18T19:52:23.748951Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-18T19:52:50.924Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/zoriya/Kyoo/security/advisories/GHSA-fc8v-vr3q-hc46"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Kyoo",
              "vendor": "zoriya",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 5.1.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core.play permission could supply a base64-encoded filesystem path to the transcoder. The path handling in transcoder/src/api/path.go cleaned the value and checked only that it began with Settings.SafePath before getHash processed it, while transcoder/src/api/streams.go served the accepted path without verifying a Kyoo catalog record. This missing catalog-level authorization allowed the user to retrieve hidden, temporary, operational, or other uncataloged files beneath the media directory when the path was known or guessed. This vulnerability is fixed in 5.1.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "CWE-639: Authorization Bypass Through User-Controlled Key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862: Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-18T17:15:28.745Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/zoriya/Kyoo/security/advisories/GHSA-fc8v-vr3q-hc46",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/zoriya/Kyoo/security/advisories/GHSA-fc8v-vr3q-hc46"
            },
            {
              "name": "https://github.com/zoriya/Kyoo/pull/1577",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/zoriya/Kyoo/pull/1577"
            },
            {
              "name": "https://github.com/zoriya/Kyoo/commit/c542adb5dc6d681e6491b28b5ac618c35c446d91",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/zoriya/Kyoo/commit/c542adb5dc6d681e6491b28b5ac618c35c446d91"
            },
            {
              "name": "https://github.com/zoriya/Kyoo/releases/tag/v5.1.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/zoriya/Kyoo/releases/tag/v5.1.0"
            }
          ],
          "source": {
            "advisory": "GHSA-fc8v-vr3q-hc46",
            "discovery": "UNKNOWN"
          },
          "title": "Kyoo: Transcoder serves uncataloged files from the media directory"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-77385",
        "datePublished": "2026-09-18T17:15:28.745Z",
        "dateReserved": "2026-08-20T19:36:13.806Z",
        "dateUpdated": "2026-09-18T19:52:50.924Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77386 (GCVE-0-2026-77386)

    Vulnerability from cvelistv5 – Published: 2026-09-18 17:16 – Updated: 2026-09-22 15:09
    VLAI
    Title
    Kyoo: OIDC login token can be redirected to an attacker-controlled URL
    Summary
    Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, an unauthenticated attacker could initiate the OIDC login flow with an attacker-controlled redirectUrl. The login handling in auth/oidc.go stored that URL with the opaque login state, and /auth/oidc/logged/{provider} appended the provider, token, and error values before redirecting the victim's browser without validating the destination. Because the one-use token was not bound to the browser session that initiated login, an attacker who induced a victim to complete OIDC authentication could capture the token at the attacker-controlled destination and exchange it through /auth/oidc/callback/{provider} for the victim's Kyoo session. This issue is fixed in version 5.1.0.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-22 15:08 UTC
    CWE
    • CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')
    Impacted products
    Vendor Product Version
    zoriya Kyoo Affected: < 5.1.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77386",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-22T15:08:48.131175Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-22T15:09:09.067Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/zoriya/Kyoo/security/advisories/GHSA-xhg6-v78p-xf44"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Kyoo",
              "vendor": "zoriya",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 5.1.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, an unauthenticated attacker could initiate the OIDC login flow with an attacker-controlled redirectUrl. The login handling in auth/oidc.go stored that URL with the opaque login state, and /auth/oidc/logged/{provider} appended the provider, token, and error values before redirecting the victim\u0027s browser without validating the destination. Because the one-use token was not bound to the browser session that initiated login, an attacker who induced a victim to complete OIDC authentication could capture the token at the attacker-controlled destination and exchange it through /auth/oidc/callback/{provider} for the victim\u0027s Kyoo session. This issue is fixed in version 5.1.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-601",
                  "description": "CWE-601: URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-18T17:16:37.282Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/zoriya/Kyoo/security/advisories/GHSA-xhg6-v78p-xf44",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/zoriya/Kyoo/security/advisories/GHSA-xhg6-v78p-xf44"
            },
            {
              "name": "https://github.com/zoriya/Kyoo/pull/1576",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/zoriya/Kyoo/pull/1576"
            },
            {
              "name": "https://github.com/zoriya/Kyoo/commit/02ab3af8127a081295fd7bed103847173c0d7632",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/zoriya/Kyoo/commit/02ab3af8127a081295fd7bed103847173c0d7632"
            },
            {
              "name": "https://github.com/zoriya/Kyoo/releases/tag/v5.1.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/zoriya/Kyoo/releases/tag/v5.1.0"
            }
          ],
          "source": {
            "advisory": "GHSA-xhg6-v78p-xf44",
            "discovery": "UNKNOWN"
          },
          "title": "Kyoo: OIDC login token can be redirected to an attacker-controlled URL"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-77386",
        "datePublished": "2026-09-18T17:16:37.282Z",
        "dateReserved": "2026-08-20T19:36:13.806Z",
        "dateUpdated": "2026-09-22T15:09:09.067Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77385 (GCVE-0-2026-77385)

    Vulnerability from cvelistv5 – Published: 2026-09-18 17:15 – Updated: 2026-09-18 19:52
    VLAI
    Title
    Kyoo: Transcoder serves uncataloged files from the media directory
    Summary
    Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core.play permission could supply a base64-encoded filesystem path to the transcoder. The path handling in transcoder/src/api/path.go cleaned the value and checked only that it began with Settings.SafePath before getHash processed it, while transcoder/src/api/streams.go served the accepted path without verifying a Kyoo catalog record. This missing catalog-level authorization allowed the user to retrieve hidden, temporary, operational, or other uncataloged files beneath the media directory when the path was known or guessed. This vulnerability is fixed in 5.1.0.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-18 19:52 UTC
    CWE
    • CWE-639 - Authorization Bypass Through User-Controlled Key
    • CWE-862 - Missing Authorization
    Impacted products
    Vendor Product Version
    zoriya Kyoo Affected: < 5.1.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77385",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-18T19:52:23.748951Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-18T19:52:50.924Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/zoriya/Kyoo/security/advisories/GHSA-fc8v-vr3q-hc46"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Kyoo",
              "vendor": "zoriya",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 5.1.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core.play permission could supply a base64-encoded filesystem path to the transcoder. The path handling in transcoder/src/api/path.go cleaned the value and checked only that it began with Settings.SafePath before getHash processed it, while transcoder/src/api/streams.go served the accepted path without verifying a Kyoo catalog record. This missing catalog-level authorization allowed the user to retrieve hidden, temporary, operational, or other uncataloged files beneath the media directory when the path was known or guessed. This vulnerability is fixed in 5.1.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "CWE-639: Authorization Bypass Through User-Controlled Key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862: Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-18T17:15:28.745Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/zoriya/Kyoo/security/advisories/GHSA-fc8v-vr3q-hc46",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/zoriya/Kyoo/security/advisories/GHSA-fc8v-vr3q-hc46"
            },
            {
              "name": "https://github.com/zoriya/Kyoo/pull/1577",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/zoriya/Kyoo/pull/1577"
            },
            {
              "name": "https://github.com/zoriya/Kyoo/commit/c542adb5dc6d681e6491b28b5ac618c35c446d91",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/zoriya/Kyoo/commit/c542adb5dc6d681e6491b28b5ac618c35c446d91"
            },
            {
              "name": "https://github.com/zoriya/Kyoo/releases/tag/v5.1.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/zoriya/Kyoo/releases/tag/v5.1.0"
            }
          ],
          "source": {
            "advisory": "GHSA-fc8v-vr3q-hc46",
            "discovery": "UNKNOWN"
          },
          "title": "Kyoo: Transcoder serves uncataloged files from the media directory"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-77385",
        "datePublished": "2026-09-18T17:15:28.745Z",
        "dateReserved": "2026-08-20T19:36:13.806Z",
        "dateUpdated": "2026-09-18T19:52:50.924Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }