CVE-2026-90617
GH05TCREW · PentestAgent MCP HTTP server
HIGH · shipped local check
MCP server config
PentestAgent through commit cf882dabea3ed91cef016cdd115e5426315665a2 binds its SSE MCP server to every interface by default without authentication.
public advisory ledger · shipped checks first
A public snapshot of shipped local checks and selected advisory triage for AI-agent configuration risk.
Only rows marked “shipped local check” are detected by Audr today. Candidate and investigating rows show advisory triage discipline, not detection coverage.
shipped local checks
141
latest advisory reviewed
2026-09-14
agent products represented
88
public snapshot updated
2026-09-19
shipped local check
Audr has a local scanner rule for this advisory signal today.
candidate local signal
Audr has identified a plausible local config, manifest, or posture signal. This is triage, not current detection.
under investigation
Audr is still validating whether there is an honest local signal. This is not current detection.
current supply-chain campaign
The worm is not just an npm advisory. It leaves local developer-machine evidence: package versions, AI-tool persistence hooks, workflow secret exfiltration, and dropped payload files.
detected today
141 public shipped rows
CVE-2026-90617
GH05TCREW · PentestAgent MCP HTTP server
HIGH · shipped local check
MCP server config
PentestAgent through commit cf882dabea3ed91cef016cdd115e5426315665a2 binds its SSE MCP server to every interface by default without authentication.
CVE-2026-85025
IBM / Langflow · Langflow public MCP project and session isolation
CRITICAL · shipped local check
dependency manifest
Langflow OSS 1.0.0 through 1.11.5 fails to enforce public-flow restrictions and session isolation on publicly shared MCP project endpoints.
CVE-2026-87911
Amazon Web Services · AWS PostgreSQL MCP Server read-only SQL validation
CRITICAL · shipped local check
dependency manifest
awslabs.postgres-mcp-server before 1.1.7 lets crafted COPY TO PROGRAM SQL escape its default read-only validator and execute operating-system commands on…
CVE-2026-86124
HKUDS · AutoAgent sandbox TCP command server
CRITICAL · shipped local check
dependency manifest
AutoAgent's sandbox TCP server binds to every interface, accepts commands without authentication, and executes received input through a shell.
CVE-2026-19592
OpenAI · OpenAI Codex Git fsmonitor handling
HIGH · shipped local check
agent config
OpenAI Codex CLI and Desktop trusted repository-local core.fsmonitor while collecting Git metadata, allowing preserved configs to launch an attacker helper.
CVE-2026-19590
OpenAI · OpenAI Codex Desktop Git hook handling
HIGH · shipped local check
plugin/hook config
OpenAI Codex Desktop trusted repository-local core.hooksPath during automated Git operations, allowing preserved configs to launch malicious hooks.
CVE-2026-75062
Google · langfun lf.query Python protocol
CRITICAL · shipped local check
dependency manifest
Google langfun 0.0.1 through 0.1.1 evaluates model-generated Python expressions without a sandbox in the default lf.query Python protocol.
CVE-2026-50027
doobidoo · mcp-memory-service document API
CRITICAL · shipped local check
MCP server config
mcp-memory-service before 10.67.1 omits authentication from every HTTP route under /api/documents even when MCP_API_KEY or OAuth is configured.
CVE-2026-73601
FlowiseAI · Flowise Custom MCP stdio
CRITICAL · shipped local check
dependency manifest
Flowise before 3.1.3 lets authenticated Custom MCP editors bypass stdio command validation through environment variables and command arguments.
CVE-2026-66418
tugcantopaloglu · OpenClaw Dashboard notification center
CRITICAL · shipped local check
source code
OpenClaw Dashboard v3.0.0 records attacker-supplied failed-login usernames and renders them unescaped through innerHTML in the administrator notification panel.
CVE-2026-66012
SiYuan · SiYuan MCP endpoint through anonymous Publish
CRITICAL · shipped local check
source code
SiYuan before 3.7.2 lets anonymous Publish proxy reader credentials into an MCP endpoint that lacks administrator-role and read-only enforcement.
CVE-2026-46701
Network-AI · Network-AI MCP SSE server
HIGH · shipped local check
MCP server config
Network-AI before 5.4.5 authorizes every MCP SSE request when NETWORK_AI_MCP_SECRET is unset and allows wildcard browser origins.
CVE-2026-9135
IBM / Langflow · Langflow OSS ToolGuard policies
CRITICAL · shipped local check
dependency manifest
Langflow OSS 1.0.0 through 1.10.0 fails to validate dynamic ToolGuard CodeInput fields even when custom components are disabled.
CVE-2026-62241
ClawVet · ClawVet self-hosted API server
CRITICAL · shipped local check
permissions/trust config
ClawVet self-hosted apps/api before 0.7.5 can use a public fallback JWT secret and expose user IDs through an unauthenticated scan listing endpoint.
CVE-2026-57860
Tailcall · ForgeCode repository MCP startup
HIGH · shipped local check
dependency manifest
ForgeCode 2.11.1 automatically executes MCP server commands from a repository-root .mcp.json without user confirmation.
CVE-2026-59864
Microsoft · Kiota Copilot/Teams plugin generation
CRITICAL · shipped local check
dependency manifest
Kiota before 1.32.5 copies unsafe x-ai-* static template paths into generated Copilot and Teams plugin manifests.
CVE-2026-59950
Model Context Protocol · MCP Python SDK WebSocket transport
HIGH · shipped local check
dependency manifest
MCP Python SDK before 1.28.1 accepts WebSocket handshakes without validating Host or Origin headers.
CVE-2026-15643
AWS Labs · AWS HealthLake MCP Server pagination handling
HIGH · shipped local check
dependency manifest
AWS HealthLake MCP Server before 0.0.14 accepts crafted pagination URLs without verifying the expected HealthLake endpoint.
CVE-2026-62200
OpenClaw · OpenClaw host exec environment filtering
HIGH · shipped local check
dependency manifest
OpenClaw before 2026.6.6 incompletely filters host exec environment variables, allowing Git ext transport abuse.
CVE-2026-62199
OpenClaw · OpenClaw interpreter startup environment filtering
HIGH · shipped local check
dependency manifest
OpenClaw before 2026.6.6 incompletely filters interpreter startup environment variables passed to host exec.
CVE-2026-61459
Flux159 · MCP Server Kubernetes structured kubectl tools
CRITICAL · shipped local check
dependency manifest
MCP Server Kubernetes before 3.9.0 accepts leading kubectl flags through structured tool resourceType or name arguments.
CVE-2026-59726
ruvnet · Ruflo agent meta-harness MCP bridge
CRITICAL · shipped local check
dependency manifest
Ruflo before 3.16.3 exposes unauthenticated MCP bridge POST /mcp tool-call endpoints in the default docker-compose deployment.
CVE-2026-55605
arikusi · DeepSeek MCP Server self-hosted HTTP transport
MEDIUM · shipped local check
dependency manifest
@arikusi/deepseek-mcp-server before 1.8.0 can expose self-hosted POST /mcp HTTP transport without authentication.
CVE-2026-55604
arikusi · DeepSeek MCP Server shared sessions
HIGH · shipped local check
dependency manifest
@arikusi/deepseek-mcp-server 1.4.2 through 1.6.x accepts caller-supplied process-global session IDs without binding them to an authenticated principal.
CVE-2026-15189
aerostackdev · Aerostack MCP WhatsApp server
MEDIUM · shipped local check
dependency manifest
Aerostack MCP mcp-whatsapp upload_media accepts attacker-controlled media_url values without sufficient SSRF protection.
CVE-2026-59723
Cline · Cline Hub dashboard
HIGH · shipped local check
dependency manifest
Cline Hub dashboard before 3.0.30 accepts /browser WebSocket connections without validating Origin and can trust local requests without ROOM_SECRET.
CVE-2026-59261
OpenClaw · OpenClaw workspace dotenv/provider credentials
HIGH · shipped local check
dependency manifest
OpenClaw before 2026.5.28 can let lower-trust workspace dotenv files override provider credential environment values.
CVE-2026-49471
Serena · Serena MCP toolkit
HIGH · shipped local check
dependency manifest
Serena before 1.5.2 exposes an unauthenticated Flask dashboard API on a predictable local port without CSRF or Host header validation.
CVE-2026-14748
AIAnytime · Awesome-MCP-Server mcp-wiki
MEDIUM · shipped local check
dependency manifest
AIAnytime Awesome-MCP-Server mcp-wiki wiki-summary can let attacker-controlled URL arguments trigger server-side requests.
CVE-2026-13341
Kong · Kong Konnect MCP Server
HIGH · shipped local check
dependency manifest
Kong Konnect MCP before 1.0.0 can return untrusted analytics/configuration content to agents and construct unintended Konnect API paths.
CVE-2026-52830
fast-mcp-telegram · fast-mcp-telegram
CRITICAL · shipped local check
dependency manifest
HTTP bearer-token validation before 0.19.1 can traverse into the default legacy Telegram session file.
CVE-2026-58446
Presenton · Presenton MCP
MEDIUM · shipped local check
dependency manifest
Server/Docker deployments before 0.8.8-beta can leave the bundled /mcp endpoint outside the session auth gate.
CVE-2026-58168
DeepTutor · DeepTutor MCP grants
HIGH · shipped local check
dependency manifest
DeepTutor before 1.4.10 can treat omitted MCP tool grants as unrestricted access for low-privilege users.
CVE-2026-55607
Anthropic · Claude Code
HIGH · shipped local check
dependency manifest
Claude Code before 2.1.163 could confuse Git worktree boundaries and run Git helper configuration outside the sandbox.
CVE-2026-50021
pnpm · pnpm
MEDIUM · shipped local check
dependency manifest
pnpm before 10.34.0 / 11.4.0 can skip tarball integrity verification when pnpm-lock.yaml resolution entries omit integrity.
CVE-2026-50017
pnpm · pnpm
MEDIUM · shipped local check
dependency manifest
pnpm before 10.34.0 / 11.4.0 can forward user-level unscoped npm credentials to a repository-selected registry.
CVE-2026-58057
FlowiseAI · Flowise Custom MCP
MEDIUM · shipped local check
dependency manifest
Flowise before 3.1.3 can accept case-variant NODE_OPTIONS in Custom MCP stdio environments on Windows.
CVE-2026-54557
mise · mise
MEDIUM · shipped local check
workspace filesystem
HTTP backend versions before 2026.6.1 can use raw absolute version/bin_path values when creating install symlinks.
CVE-2026-48529
GitHub · GitHub MCP Server
MEDIUM · shipped local check
dependency manifest
HTTP lockdown mode from 0.22.0 before 1.1.2 reused a process-global repo access cache across authenticated users.
CVE-2026-54030
LibreChat · LibreChat MCP OAuth
HIGH · shipped local check
dependency manifest
MCP OAuth resource metadata can redirect access tokens to a malicious server before 0.8.5.
CVE-2026-50549
Cursor · Cursor agent terminal sandbox
CRITICAL · shipped local check
workspace filesystem
Cursor before 3.0 can fall back after path canonicalization failure and write through an in-workspace symlink outside the workspace boundary.
CVE-2026-50548
Cursor · Cursor agent terminal sandbox
CRITICAL · shipped local check
dependency manifest
Cursor before 3.0 lets an agent-controlled working directory expand the terminal sandbox's writable scope outside the intended workspace.
CVE-2025-71336
FlowiseAI · Flowise Custom MCP
CRITICAL · shipped local check
dependency manifest
Custom MCP node-load handling before 3.0.6 can execute OS commands when Flowise is left without built-in auth.
CVE-2026-54232
vLLM · vLLM Dockerfile
HIGH · shipped local check
source code
vLLM before 0.22.1 could install flashinfer-jit-cache from PyPI during Docker builds because unsafe-best-match was paired with a FlashInfer extra index.
CVE-2026-53766
Chrome DevTools · chrome-devtools-mcp
MEDIUM · shipped local check
dependency manifest
versions from 0.24.0 before 1.1.0 validate MCP workspace roots through path.resolve() instead of canonical symlink-aware paths.
CVE-2026-53765
Chrome DevTools · chrome-devtools-mcp
MEDIUM · shipped local check
workspace filesystem
versions from 0.20.0 before 1.1.0 can follow symlinks while writing daemon.pid in a deterministic /tmp runtime path.
CVE-2026-55249
rtk-ai · @rtk-ai/rtk-rewrite OpenClaw plugin
MEDIUM · shipped local check
dependency manifest
version 1.0.0 passes OpenClaw exec tool input into a shell-backed execSync template without shell-safe escaping.
CVE-2026-54555
rtk-ai · rtk
HIGH · shipped local check
dependency manifest
permission splitter before 0.42.2 can miss shell execution boundaries and return allow for hidden commands.
CVE-2026-50178
Angular · Angular Language Service VS Code Extension
HIGH · shipped local check
dependency manifest
VS Code extension versions before 21.2.4 render hover Markdown with trusted command URIs.
CVE-2026-49357
Line Desktop MCP · line-desktop-mcp
HIGH · shipped local check
dependency manifest
Streamable HTTP mode before 1.1.2 binds the MCP endpoint on 0.0.0.0 without MCP-layer authentication.
CVE-2026-49257
StarTreeData · mcp-pinot
CRITICAL · shipped local check
dependency manifest
mcp-pinot 3.0.1 and earlier default to an unauthenticated HTTP MCP server on 0.0.0.0:8080.
CVE-2026-11719
Google APIs · MCP Toolbox for Databases
HIGH · shipped local check
dependency manifest
legacy MCP protocol handlers before 1.4.0 skip per-tool scopesRequired checks.
CVE-2026-48989
CursorTouch · Windows-MCP
HIGH · shipped local check
dependency manifest
HTTP modes before 0.7.5 exposed the MCP control plane without authentication while allowing wildcard CORS.
CVE-2026-48814
Network-AI · Network-AI
CRITICAL · shipped local check
dependency manifest
Network-AI 5.7.1 and earlier keep the MCP SSE server authorized when its secret is empty/default.
CVE-2026-48124
Cursor · Cursor Desktop
HIGH · shipped local check
plugin/hook config
workspace-defined Claude hook commands could run without dedicated approval before 3.0.0.
CVE-2026-11624
Google APIs · MCP Toolbox for Databases
HIGH · shipped local check
dependency manifest
wildcard Origin and Host defaults allow DNS rebinding against local Toolbox MCP servers before hardened startup flags are used.
CVE-2026-53839
OpenClaw · OpenClaw
MEDIUM · shipped local check
dependency manifest
retry endpoint checks before 2026.5.7 use hostname-prefix matching instead of exact hostname validation.
CVE-2026-53838
OpenClaw · OpenClaw
CRITICAL · shipped local check
dependency manifest
node pairing reconnection can confuse approval scope decisions before 2026.5.27.
CVE-2026-53836
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
PowerShell encoded-command alias handling can bypass exec allowlist checks before 2026.5.12.
CVE-2026-53834
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
QQBot pre-dispatch slash commands can skip allowFrom policy checks before 2026.4.27.
CVE-2026-53833
OpenClaw · OpenClaw QQBot streaming config
HIGH · shipped local check
dependency manifest
QQBot streaming commands before 2026.4.29 can mutate configuration without explicit allowFrom restrictions.
CVE-2026-53832
OpenClaw · OpenClaw trusted proxy Gateway
HIGH · shipped local check
dependency manifest
before 2026.5.18, trusted-proxy identity headers can be forged by same-host callers reaching the proxy-facing Gateway port.
CVE-2026-53831
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
system.run safe-bin allowlist validation before 2026.5.18 lets POSIX shell expansion alter approved command interpretation.
CVE-2026-53829
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
approval prompt rendering before 2026.5.18 can truncate command suffixes or privileged action details.
CVE-2026-53828
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
native command handling before 2026.5.6 could skip owner-only command policy enforcement.
CVE-2026-53823
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
Slack allowFrom checks before 2026.5.3 trusted mutable display-name metadata.
CVE-2026-53822
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
Shell wrapper arguments can be rebuilt after allowlist approval before 2026.5.18.
CVE-2026-53821
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
WebSocket client-declared operator scopes can be accepted before server-approved pairing or trusted-proxy authorization before 2026.5.18.
CVE-2026-53819
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
workspace .env files can override Homebrew executable selection during skill install before 2026.5.27.
CVE-2026-53817
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
Control UI pairing can trust spoofed locality information before 2026.5.22.
CVE-2026-53816
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
paired or compromised nodes can forge exec lifecycle events before 2026.5.18.
CVE-2026-53814
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
hook-triggered agent runs can incorrectly receive owner-scoped MCP loopback access before 2026.5.20.
CVE-2026-53813
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
memory-core artifact root resolution can traverse to unintended local package roots before 2026.4.25.
CVE-2026-53812
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
browser-control redirects can bypass private-network navigation blocks before 2026.5.18.
CVE-2026-53811
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
Matrix allowFrom policy can match mutable display-name metadata before 2026.5.7.
CVE-2026-53810
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
marketplace runtime extension metadata can redirect loading toward unscanned package payloads before 2026.5.18.
CVE-2026-53807
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
Telegram interactive callbacks can skip commands.allowFrom validation before 2026.5.6.
CVE-2026-53806
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
combined POSIX shell flags can bypass exec revalidation before 2026.5.12.
CVE-2026-47250
MCP Server Kubernetes · MCP Server Kubernetes
MEDIUM · shipped local check
dependency manifest
kubectl_generic passed user-supplied flags to kubectl before 3.7.0.
CVE-2026-46519
MCP Server Kubernetes · MCP Server Kubernetes
HIGH · shipped local check
dependency manifest
tool allowlist environment variables were enforced only during tools/list before 3.6.0.
CVE-2026-44653
LibreChat · LibreChat
MEDIUM · shipped local check
dependency manifest
VIEW users can receive decrypted admin-managed MCP secrets through 0.8.3.
CVE-2026-32625
LibreChat · LibreChat
CRITICAL · shipped local check
dependency manifest
MCP URL placeholders resolve server environment secrets through 0.8.3.
CVE-2026-31942
LibreChat · LibreChat
HIGH · shipped local check
dependency manifest
API key updates can target another user through request body userId fields before 0.8.3.
CVE-2026-10280
horizon921 · mcpilot
HIGH · shipped local check
dependency manifest
serverBaseUrl handling can allow SSRF in mcpilot client 0.1.0.
CVE-2026-35674
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
Gateway chat.send scope checks allow privileged command paths before 2026.5.18.
CVE-2026-35673
OpenClaw · OpenClaw
MEDIUM · shipped local check
dependency manifest
browser debug/export routes can reuse blocked tabs before 2026.4.29.
CVE-2026-35630
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
QQBot native approval buttons miss approver identity checks before 2026.5.18.
CVE-2026-34507
OpenClaw · OpenClaw
MEDIUM · shipped local check
dependency manifest
QQBot admin commands can skip DM-only and allowFrom policy before 2026.4.29.
CVE-2026-32906
OpenClaw · OpenClaw
MEDIUM · shipped local check
dependency manifest
Slack plugin approvals use the wrong approval gate before 2026.5.12.
CVE-2026-32905
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
device-pair plugin can issue bootstrap codes from non-owner chats before 2026.5.4.
CVE-2026-48116
AnythingLLM · AnythingLLM
HIGH · shipped local check
workspace filesystem
filesystem search passes prompt-controlled terms to ripgrep as options before 1.13.0.
CVE-2026-44830
Nocturne Memory · Nocturne Memory
HIGH · shipped local check
dependency manifest
empty API_TOKEN disables bearer-token auth before 2.4.1.
CVE-2026-44895
yoda-digital · GitLab MCP Server
CRITICAL · shipped local check
MCP server config
HTTP/SSE transport exposes GitLab token-backed MCP tools without authentication before 0.6.0.
CVE-2026-44450
prolix-oc · Lumiverse
CRITICAL · shipped local check
dependency manifest
MCP server args are forwarded to code-capable allowlisted binaries before 0.9.7.
CVE-2026-9468
dazeb · cline-mcp-memory-bank
MEDIUM · shipped local check
dependency manifest
initialize projectPath handling can write outside the intended memory-bank directory.
CVE-2026-9353
NousResearch · hermes-agent
HIGH · shipped local check
source code
Skills Guard multi-word prompt pattern hardening is missing before 0.15.0.
CVE-2026-2611
MLflow · MLflow Assistant
CRITICAL · shipped local check
dependency manifest
Assistant ajax-api origin validation lets hostile pages reconfigure local agents.
CVE-2026-47092
Claude HUD · Claude HUD
HIGH · shipped local check
dependency manifest
COMSPEC is trusted during Windows version checks through 0.0.12.
CVE-2026-47090
Claude HUD · Claude HUD
MEDIUM · shipped local check
dependency manifest
OSC 8 hyperlinks use raw cwd and branch URL values through 0.0.12.
CVE-2026-44717
611711Dark · MCP Calculate Server
CRITICAL · shipped local check
dependency manifest
SymPy expression tool input reaches Python eval before 0.1.1.
CVE-2026-44641
Microsoft · Microsoft APM
HIGH · shipped local check
dependency manifest
plugin.json component paths can escape the plugin directory before 0.8.12.
CVE-2026-45033
GitHub · GitHub Copilot CLI
HIGH · shipped local check
plugin/hook config
nested bare Git repositories can execute configured helpers during agent git operations before 1.0.43.
CVE-2026-5029
formulahendry · Code Runner MCP Server
CRITICAL · shipped local check
dependency manifest
HTTP transport exposes the run-code MCP tool without authentication on port 3088.
CVE-2026-44246
Anthropic / Claude Code Action · nnU-Net issue triage workflow
HIGH · shipped local check
permissions/trust config
Issue-triggered Claude Code workflows embed untrusted issue title/body content.
CVE-2026-43991
JunoClaw · JunoClaw plugin-shell
HIGH · shipped local check
dependency manifest
raw command blocklist checks can be bypassed in plugin-shell 0.1.0.
CVE-2026-43990
JunoClaw · JunoClaw plugin-shell
HIGH · shipped local check
dependency manifest
agent commands are wrapped in sh -c or cmd /C in plugin-shell 0.1.0.
CVE-2026-8305
OpenClaw · OpenClaw
MEDIUM · shipped local check
dependency manifest
BlueBubbles webhook handling is authorization-bypass prone before 2026.2.12.
CVE-2026-43901
MCP · Wireshark MCP
MEDIUM · shipped local check
dependency manifest
export_objects accepts attacker-controlled destination directories when no allowlist is configured.
CVE-2026-44110
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
Matrix room control commands trust DM pairing-store entries before 2026.4.15.
CVE-2026-44109
OpenClaw · OpenClaw
CRITICAL · shipped local check
dependency manifest
Feishu webhook validation fails open when auth material is blank.
CVE-2026-43585
OpenClaw · OpenClaw
CRITICAL · shipped local check
dependency manifest
Bearer SecretRefs are cached through token rotation.
CVE-2026-43581
OpenClaw · OpenClaw
CRITICAL · shipped local check
dependency manifest
Sandbox CDP relay binds Chrome DevTools to all interfaces.
CVE-2026-43578
OpenClaw · OpenClaw
CRITICAL · shipped local check
dependency manifest
Async exec completions bypass heartbeat owner downgrade checks.
CVE-2026-43575
OpenClaw · OpenClaw
CRITICAL · shipped local check
dependency manifest
Sandbox noVNC helper route exposes browser session credentials.
CVE-2026-43566
OpenClaw · OpenClaw
CRITICAL · shipped local check
dependency manifest
Heartbeat owner downgrade weakens channel ownership boundaries.
CVE-2026-43534
OpenClaw · OpenClaw
CRITICAL · shipped local check
dependency manifest
External hook metadata is queued as trusted system events.
CVE-2026-7729
pixelsock · directus-mcp
LOW · shipped local check
dependency manifest
fileUrl validation can allow SSRF in directus-mcp 1.0.0.
CVE-2026-41370
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
ACP attachment paths can traverse outside the workspace before 2026.3.31.
CVE-2026-41368
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
jq safe-bin expressions can disclose process environment before 2026.3.28.
CVE-2026-41366
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
local media roots can be self-whitelisted before 2026.3.31.
CVE-2026-7417
Algovate · xhs-mcp
MEDIUM · shipped local check
dependency manifest
MCP media_paths handling can be steered into SSRF in 0.8.11.
CVE-2026-7221
TencentCloudBase · CloudBase-MCP
MEDIUM · shipped local check
dependency manifest
openUrl can be abused for SSRF before CloudBase-MCP 2.17.1.
CVE-2026-7316
eiliyaabedini · aider-mcp
MEDIUM · shipped local check
dependency manifest
working_dir and editable_files handling can allow command injection in vulnerable GitHub source installs.
CVE-2026-42426
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
node.pair.approve accepts broad operator.write instead of pairing scope.
CVE-2026-42422
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
device.token.rotate can mint roles that were not approved for the device.
CVE-2026-41405
OpenClaw · OpenClaw
HIGH · shipped local check
plugin/hook config
MS Teams webhook bodies are parsed before JWT validation.
CVE-2026-41404
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
Trusted-proxy scope clearing lets non-Control-UI clients self-declare operator scopes.
CVE-2026-41399
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
WebSocket upgrades consume socket and worker capacity before auth.
CVE-2026-41396
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
Workspace .env overrides the bundled plugin trust root.
CVE-2026-41394
OpenClaw · OpenClaw
HIGH · shipped local check
plugin/hook config
plugin-auth routes receive operator runtime write scopes without auth.
CVE-2026-41386
OpenClaw · OpenClaw
CRITICAL · shipped local check
dependency manifest
Bootstrap setup codes are not role-bound during first-use pairing.
CVE-2026-41378
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
node.event requests can reach unrestricted gateway tools.
CVE-2026-7158
dmitryglhf · mcp-url-downloader
MEDIUM · shipped local check
dependency manifest
URL validation can be bypassed for SSRF in 0.1.0.
CVE-2026-7157
disler · aider-mcp-server
MEDIUM · shipped local check
dependency manifest
editable file path handling can lead to command injection in 0.1.0.
CVE-2026-7147
JoeCastrom · mcp-chat-studio
MEDIUM · shipped local check
dependency manifest
model API base_url handling can allow SSRF through 1.5.0.
CVE-2026-7146
AlejandroArciniegas · mcp-data-vis
MEDIUM · shipped local check
dependency manifest
web-scraper URL handling can be abused for SSRF in 1.0.0.
CVE-2026-41349
OpenClaw · OpenClaw
HIGH · shipped local check
dependency manifest
config.patch can silently disable execution approval.
CVE-2026-41336
OpenClaw · OpenClaw
HIGH · shipped local check
plugin/hook config
Workspace .env overrides the bundled hooks trust root.
CVE-2025-59536
Anthropic · Claude Code
CRITICAL · shipped local check
plugin/hook config
Settings hooks execute arbitrary shell on PreToolUse / Stop events.
CVE-2026-25253
OpenClaw · OpenClaw
HIGH · shipped local check
MCP server config
MCP credentials stored plaintext in user-readable config.
CVE-2026-39861
Anthropic · Claude Code
HIGH · shipped local check
permissions/trust config
Symlink in workspace allows sandbox escape on read.
public-safe research snapshot
These rows are not detected by Audr unless marked shipped. They show where Audr is evaluating honest local-config evidence next.
capped at 12 rows
CVE-2026-38924
Oraios AI · Serena
LOW · candidate local signal
source code
Serena before 1.0.0 listens on 0.0.0.0 by default when its MCP server uses HTTP mode. The supplier changed the default to 127.0.0.1 and warns about…
CVE-2026-90474
samanhappy · MCPHub
HIGH · candidate local signal
dependency manifest
MCPHub before 1.0.32 does not consistently authenticate confidential OAuth clients and allows public clients to obtain authorization codes without mandatory…
CVE-2026-88938
knowns-dev · knowns code.find MCP tool through 0.33.0
HIGH · candidate local signal
dependency manifest
knowns through 0.33.0 fails to confine the path argument of the code.find MCP tool to the project root, allowing AI agent sessions to read source files…
CVE-2026-88937
knowns-dev · knowns code-generation template engine through 0.33.0
HIGH · candidate local signal
dependency manifest
knowns through 0.33.0 fails to properly validate template destination paths in the code generation template engine, allowing attackers to read and write…
CVE-2026-88061
career-ops-hq · career-ops local web dashboard before web-v0.8.0
MEDIUM · candidate local signal
dependency manifest
career-ops is an open-source AI-assisted job search and application management tool. Prior to 0.8.0, the career-ops local web dashboard web/ exposed…
CVE-2026-87913
Amazon Web Services / awslabs · AWS Security Agent MCP server before 0.2.0
MEDIUM · candidate local signal
dependency manifest
A missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 version might allow remote attackers to obtain the private…
CVE-2026-87912
Amazon Web Services · AWS Agents for DevSecOps Security Agent plugin before 1.1.0
MEDIUM · candidate local signal
dependency manifest
A missing S3 bucket ownership verification in the AWS Security Agent plugin in Amazon aws-agents-for-devsecops before 1.1.0 might allow remote attackers to…
CVE-2026-81941
IBM / Langflow OSS · Langflow OSS 1.0.0 through 1.11.5
HIGH · candidate local signal
dependency manifest
IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the…
CVE-2026-81940
IBM / Langflow OSS · Langflow OSS 1.0.0 through 1.11.5
HIGH · candidate local signal
dependency manifest
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special…
CVE-2026-81211
IBM / Langflow OSS · Langflow OSS 1.0.0 through 1.11.5
HIGH · candidate local signal
dependency manifest
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom…
CVE-2026-81204
IBM / Langflow OSS · Langflow OSS 1.0.0 through 1.11.5
CRITICAL · candidate local signal
dependency manifest
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.
CVE-2026-79742
IBM / Langflow OSS · Langflow OSS 1.0.0 through 1.11.5
HIGH · candidate local signal
dependency manifest
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.
Static public snapshot generated 2026-09-19T16:45:25Z from advisory triage reviewed through 2026-09-14. This page is not a live vulnerability feed.