Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.7 CVE-2026-50287

Missing Authentication for Critical Function in @agenticmail/mcp_CVE-2026-50287

AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a Streamable HTTP transport w...

agenticmail agenticmail < 0.9.27 CVE
HIGH 7.7 CVE-2026-47260

Koel Vulnerable to SSRF via Podcast Episode Enclosure URLs_CVE-2026-47260

Koel is a free, open-source music streaming solution. Prior to version 9.3.5, Koel validates the podcast feed URL via the SafeUrl rule (DNS resolut...

koel koel < 9.3.5 CVE
MEDIUM 5.3 CVE-2026-43872

actual-server has a path traversal vulnerability_CVE-2026-43872

Actual is an open-source personal finance application. Prior to version 26.5.0, several endpoints are affected by a path traversal vulnerability. V...

actualbudget actual < 26.5.0 CVE
MEDIUM 4.8 CVE-2026-42890

actual Allows Electron to Run As Node_CVE-2026-42890

Actual is an open-source personal finance application. In the macOS desktop application version 25.x (built on Electron 39.2.7), the ELECTRON_RUN_A...

actualbudget actual < 26.5.0 CVE
MEDIUM 6.9 CVE-2026-42604

Actual has an OpenID `client_secret` Disclosure via Broken Authorization Guard in `/openid/config`_CVE-2026-42604

Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's sync-server versions

actualbudget actual < 26.5.0 CVE
HIGH 8.8 CVE-2026-7387

Mattermost group syncable endpoints allow privilege escalation via scheme_admin_CVE-2026-7387

Mattermost versions 11.6.x

Mattermost Mattermost 11.6.0 CVE
MEDIUM 6.5 CVE-2026-7184

Mattermost Remote Cluster PATCH API Leaks Authentication Tokens_CVE-2026-7184

Mattermost versions 11.6.x

Mattermost Mattermost 11.6.0 CVE
HIGH 7.6 CVE-2026-6961

CVE-2026-6961: Path traversal via unsanitized FileInfo.Name in Mattermost federation sync_CVE-2026-6961

Mattermost versions 11.6.x

Mattermost Mattermost 11.6.0 CVE
MEDIUM 6.7 CVE-2026-6739

Mattermost: Delegated admins could patch protected default system roles_CVE-2026-6739

Mattermost versions 11.6.x

Mattermost Mattermost 11.6.0 CVE
MEDIUM 4.3 CVE-2026-6689

*Missing* {{invite_user}} *permission check on team creation allows unprivileged users to set open-invite and allowed-domains team settings*_CVE-2026-6689

Mattermost versions 11.6.x

Mattermost Mattermost 11.6.0 CVE