Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2026-58174

Hermes WebUI < 0.51.521 - Cross-Profile Authorization Bypass via Unset Session Profile on Import_CVE-2026-58174

Hermes WebUI before 0.51.521 validates the workspace of an imported session under the active named profile but constructs the Session object withou...

nesquena hermes-webui CVE
MEDIUM 6.5 CVE-2026-58173

Vibe-Trading < 0.1.10 - Path Traversal via Persistent Memory Type_CVE-2026-58173

Vibe-Trading before 0.1.10 contains a path traversal vulnerability that allows attackers to write files outside the intended memory root directory ...

HKUDS Vibe-Trading CVE
CRITICAL 9.1 CVE-2026-58172

Ocelot – IP Allow/Block List Bypass for WebSocket Upgrade Requests_CVE-2026-58172

Ocelot through 24.1.0, fixed in commit f156fd4, contains a security control bypass vulnerability that allows denied clients to circumvent IP-based ...

ThreeMammals Ocelot CVE
MEDIUM 4.2 CVE-2026-58171

Vibe-Trading < 0.1.10 - Path Traversal via Swarm Run Identifier_CVE-2026-58171

Vibe-Trading before 0.1.10 constructs the swarm run directory by joining a caller-supplied run identifier onto the runs base directory without vali...

HKUDS Vibe-Trading CVE
HIGH 8.3 CVE-2026-58170

Vibe-Trading < 0.1.10 - Path Traversal in Proposal Identifier Allows Forging Live Trading Mandates_CVE-2026-58170

Vibe-Trading before 0.1.10 builds the proposal file path by joining a caller-supplied proposal identifier onto the broker proposals directory witho...

HKUDS Vibe-Trading CVE
HIGH 7.5 CVE-2026-58169

Vibe-Trading < 0.1.10 - Loopback Trust and Missing Host Validation Enable DNS-Rebinding Authentication Bypass and Remote Code Execution_CVE-2026-58169

Vibe-Trading before 0.1.10's local API server trusts the TCP peer address to bypass the API_AUTH_KEY bearer-token check for loopback clients and pe...

HKUDS Vibe-Trading CVE
HIGH 8.8 CVE-2026-58168

DeepTutor < 1.4.10 - Insecure Default Grants Unrestricted MCP Tool Access to Non-Admin Users_CVE-2026-58168

DeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to invoke unrestricted MCP tools due...

HKUDS DeepTutor CVE
MEDIUM 6.5 CVE-2026-58167

Nightingale < 9.0.0-beta.2 - Datasource Credential Disclosure to Low-Privilege Users_CVE-2026-58167

Nightingale (n9e) before 9.0.0-beta.2 exposes full datasource configurations, including plaintext database passwords, HTTP bearer tokens, HTTP basi...

ccfos nightingale CVE
CRITICAL 9.1 CVE-2026-58166

OpenBMB ChatDev – Unauthenticated Path Traversal in Upload Handler Allows Arbitrary File Write and Delete_CVE-2026-58166

OpenBMB ChatDev through 2.2.0, fixed in commit 4fd4da6, contains a path traversal vulnerability that allows unauthenticated remote attackers to wri...

OpenBMB ChatDev CVE
HIGH 8.8 CVE-2026-58165

OpenZiti – Privilege Escalation to Admin via Unauthorized Enrollment Creation_CVE-2026-58165

OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated non-admin identities with ...

openziti ziti CVE