Recent Advisories

Severity ID Title Vendor Product Date Type
NONE HACKREAD:B18ECD...

Internet Society Foundation Opens Global Call for Common Good Cyber Fund to Strengthen Cybersecurity_HACKREAD:B18ECD3BC16D6012AA85453F7891373F

DC, United States, 23rd June 2026, CyberNewswire

N/A N/A HACKREAD
MEDIUM 5.9 CVE-2026-55736

Private action arguments can be set by user input in Ash_CVE-2026-55736

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a...

ash-project ash 3.0.0 CVE
MEDIUM 6.3 CVE-2026-55249

@rtk-ai/rtk-rewrite: OpenClaw Rewrite Plugin Command Injection via execSync Template String_CVE-2026-55249

@rtk-ai/rtk-rewrite transparently rewrites shell commands executed via OpenClaw's exec tool to their RTK equivalents. In 1.0.0, the @rtk-ai/rtk-rew...

rtk-ai rtk 1.0.0 CVE
HIGH 7.7 CVE-2026-54322

Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org’s roles_CVE-2026-54322

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, Daytona's organizatio...

daytonaio daytona < 0.185.0 CVE
HIGH 7 CVE-2026-54321

Daytona: Public sandbox previews remain accessible for up to one hour after being made private_CVE-2026-54321

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. From 0.101.0 until 0.184.0, sandbox pre...

daytonaio daytona >= 0.101.0, < 0.184.0 CVE
HIGH 8.4 CVE-2026-54320

Daytona: Cross-tenant organization takeover via invitation acceptance with an unverified email_CVE-2026-54320

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.184.0, organization invitati...

daytonaio daytona < 0.184.0 CVE
MEDIUM 4.2 CVE-2026-54319

Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape_CVE-2026-54319

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.186, a sandbox volume refere...

daytonaio daytona < 0.186 CVE
HIGH 8.6 CVE-2026-53755

Crawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check_CVE-2026-53755

Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.9, the Docker API server applied its SSRF destination check to the craw...

unclecode crawl4ai < 0.8.9 CVE
HIGH 7.5 CVE-2026-53754

Crawl4AI: SSRF filter bypass in Docker server via IPv6 transition forms (NAT64 / 6to4 / unspecified / v4-mapped)_CVE-2026-53754

Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.8, the Docker API server's SSRF protection (validate_webhook_url / vali...

unclecode crawl4ai < 0.8.8 CVE
CRITICAL 9.8 CVE-2026-53753

Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain – Pre-Auth RCE in Docker API_CVE-2026-53753

Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature ...

unclecode crawl4ai < 0.8.7 CVE