FixVibe

// vulnerability research

Vulnerability research for AI-built websites and apps.

Source-grounded notes on vulnerabilities that matter to AI-generated web apps, BaaS stacks, frontend bundles, auth, and dependency security.

126
published
126
matches
Latest researchhigh

Redis RESTORE Memory-Safety Vulnerability (CVE-2026-25243)

CVE-2026-25243 is a high-severity Redis memory-safety flaw in RESTORE processing. It requires authenticated access and permission to run RESTORE, and Redis 8.6.3 includes the security fix.

Read article

All research

126 articles

criticalSep 5, 2026

Active Storage Arbitrary File Read with Potential RCE (CVE-2026-66066)

CVE-2026-66066 is an Active Storage arbitrary file-read vulnerability with potential follow-on RCE in affected Rails branches. FixVibe GitHub repository scans flag affected activestorage versions in Gemfile.lock.

CVE-2026-66066GHSA-xr9x-r78c-5hrmCWE-1188
View research
criticalSep 5, 2026

HubSpot Jinjava JavaType Sandbox Bypass (CVE-2025-59340)

CVE-2025-59340 affects HubSpot Jinjava versions >=2.7.0 and <2.7.5, and version 2.8.0. A JavaType deserialization sandbox bypass may enable arbitrary file reads or SSRF and, in some deployments, follow-on RCE; RCE is not guaranteed. FixVibe repository scans flag affected Jinjava versions.

CVE-2025-59340GHSA-m49c-g9wr-hv6vCWE-1336
View research
highSep 5, 2026

Jenkins config.xml Deserialization Vulnerability (CVE-2026-53435)

CVE-2026-53435 affects Jenkins core releases through weekly 2.567 and LTS 2.555.2 when attacker-controlled configuration is processed under the required permissions. FixVibe repository scans flag affected Jenkins core versions in Maven or Gradle builds.

CVE-2026-53435GHSA-g2xq-2v27-4rh3CWE-502
View research
criticalAug 22, 2026

mcp-server-kubernetes npm Argument Injection Can Expose Cluster Credentials

CVE-2026-61459 is a Critical argument-injection vulnerability in the Node.js npm package mcp-server-kubernetes before 3.9.0. FixVibe covers it with a High-severity, version-based repository advisory that deliberately excludes the unrelated same-named PyPI distribution.

CVE-2026-61459GHSA-WMG3-H8MF-WGVRCWE-88
View research
highAug 22, 2026

jsPDF Node.js Path Traversal and Local File Inclusion (CVE-2025-68428)

The Node.js bundles of npm package jspdf version 3.0.4 and earlier can read local files when attacker-influenced paths reach loadFile, addImage, html, or addFont. Browser builds are not affected, and jsPDF 4.0.0 restricts filesystem access by default. FixVibe GitHub repo scans flag affected jspdf versions.

CVE-2025-68428GHSA-f8cm-6447-x5h2GHSA-f8cm-6447-x5h2
View research
highAug 22, 2026

Microsoft Kiota Generation-Time SSRF and File Inclusion (CVE-2026-59867)

Microsoft Kiota releases before 1.29.1 and releases from 1.30.0 through 1.32.4 can follow unrestricted external OpenAPI references during client generation. If a developer or CI job processes an attacker-influenced description, the build host may make internal network requests or read local files. FixVibe GitHub repo scans flag affected Kiota versions.

CVE-2026-59867GHSA-rg4h-fpcp-2qm8CWE-22
View research
mediumAug 3, 2026

Stored XSS in osTicket Installation Script (CVE-2019-14750)

osTicket releases before 1.10.7 and 1.12.x before 1.12.1 contain a stored cross-site scripting flaw in the installer workflow. FixVibe GitHub repo scans flag the affected installer source.

CVE-2019-14750CWE-79
View research
criticalAug 3, 2026

9router Missing Authorization and OS Command Injection (CVE-2026-59800)

Reviewed advisories identify missing authorization and operating-system command injection in 9router releases before 0.4.44. FixVibe GitHub repo scans flag affected 9router versions in npm manifests and lockfiles.

CVE-2026-59800GHSA-g6g7-pvmx-m74pGHSA-g6g7-pvmx-m74p
View research
highJul 25, 2026

runc Container Breakout via File Descriptor Leak (CVE-2024-21626)

CVE-2024-21626 is a high-severity runc file-descriptor leak that can let malicious images or container processes reach the host filesystem. FixVibe repo scans flag container working-directory configuration associated with the breakout condition.

CVE-2024-21626GHSA-xr7r-f8xq-vfvvCWE-200
View research
criticalJul 25, 2026

Authentication Bypass in MLflow Job Endpoints (CVE-2026-0545)

CVE-2026-0545 is an MLflow authentication-boundary flaw affecting FastAPI job routes when Basic Auth and job execution are enabled. FixVibe verified active scans flag job routes that do not enforce the configured authentication.

CVE-2026-0545CWE-306
View research
criticalJul 25, 2026

NocoBase Sandbox Escape and Remote Code Execution (CVE-2026-34156)

NocoBase @nocobase/plugin-workflow-javascript versions through 2.0.27 are affected by CVE-2026-34156. An authenticated user who can run a Workflow Script Node may escape its sandbox and execute code on the host. FixVibe repo scans flag affected plugin versions.

CVE-2026-34156CWE-913
View research
criticalJul 25, 2026

Microsoft Kiota Command Injection via Malicious OpenAPI Metadata (CVE-2026-59865)

Microsoft Kiota releases before 1.32.5 could trust dependency-install guidance supplied by an OpenAPI description. Exploitation requires an untrusted or compromised description and a developer or integration that follows the supplied install action. Kiota 1.32.5 removes support for description-supplied dependency install commands, and FixVibe now reports affected repository-managed Kiota versions as a version-based advisory.

CVE-2026-59865GHSA-hq9q-27g5-qwpjCWE-94
View research
highJul 25, 2026

CVE-2025-56005: Disputed Unsafe Deserialization Risk in PLY

PLY parser construction can opt into loading parser tables through Python pickle. That becomes a code-execution risk only when a less-trusted actor can influence the existing pickle file or its path. CVE-2025-56005 is disputed; FixVibe repo scans flag explicit use of the unsafe parser-table loading path as a likely issue.

CVE-2025-56005GHSA-qc6m-pwr3-g72pCWE-502
View research
criticalJul 25, 2026

Remote Code Execution in verot/class.upload.php (CVE-2019-19576)

CVE-2019-19576 affects dangerous-file handling in verot/class.upload.php releases before 1.0.3 and from 2.0.0 through 2.0.3. FixVibe GitHub repo scans flag affected versions in Composer files.

CVE-2019-19576GHSA-r5gm-4p5w-pq2pCWE-434
View research
criticalJul 25, 2026

LobeHub Unauthenticated SSRF in /webapi/proxy (CVE-2026-54157)

LobeHub versions through 2.1.56 expose an unauthenticated server-side proxy route. FixVibe verified active scans flag deployments where that route fetches external URLs for unauthenticated callers.

CVE-2026-54157GHSA-xmwj-c75x-6346CWE-918
View research
highJul 20, 2026

Next.js WebSocket SSRF Vulnerability (CVE-2026-44578)

CVE-2026-44578 is a high-severity server-side request forgery vulnerability affecting self-hosted applications that use the built-in Next.js server. Vercel-hosted deployments are not affected. FixVibe authorized GitHub repository scans flag affected Next.js versions.

CVE-2026-44578GHSA-c4j6-fc7j-m34rGHSA-c4j6-fc7j-m34r
View research
highJul 20, 2026

Conditional NGINX HTTP/2 and gRPC Proxy Buffer Overflow (CVE-2026-42055)

CVE-2026-42055 is a conditional heap-based buffer overflow in NGINX HTTP/2 and gRPC upstream proxying. F5 scores it 8.1 High under CVSS v3.1, while nginx.org classifies it Medium. Exploitation requires several uncommon configuration prerequisites, including oversized client-header buffers; worker restart is the direct documented impact, and code execution additionally requires ASLR to be disabled or bypassed. FixVibe repo scans flag affected official NGINX Open Source container deployments with that configuration.

CVE-2026-42055CWE-122CWE-787
View research
criticalJul 20, 2026

vLLM video-processing RCE advisory (CVE-2026-22778)

CVE-2026-22778 affects vLLM releases from 0.8.3 through 0.14.0 when a deployment serves a video-capable model and processes attacker-controlled video input. vLLM 0.14.1 fixes the issue. FixVibe GitHub repo scans flag affected vLLM versions.

CVE-2026-22778GHSA-4r2x-xpjr-7cvvPYSEC-2026-565
View research
criticalJul 20, 2026

ChromaDB Python Backend Pre-Authentication RCE (CVE-2026-45829)

CVE-2026-45829 affects ChromaDB's optional Python FastAPI backend when attacker-controlled embedding configuration is processed before authorization. The default Rust frontend is not affected.

CVE-2026-45829CWE-94CWE-502
View research
highJul 20, 2026

Gitea Insufficient Permission Checks for Composer Package Source Links (CVE-2026-27771)

Gitea versions through 1.26.1 can expose Composer package source-link information when package and linked-repository permissions differ. FixVibe GitHub repo scans flag pinned Gitea server images in the affected range.

CVE-2026-27771GHSA-8qw8-rq86-9pc2GHSA-8qw8-rq86-9pc2
View research
highJul 16, 2026

Denial of Service in Newtonsoft.Json via StackOverflow Exception (CVE-2024-21907)

Newtonsoft.Json versions affected by CVE-2024-21907 (GHSA-5crp-9r3c-p9vr) can crash with a stack overflow on deeply nested JSON. GitHub repo scans flag NuGet project and lockfile entries that resolve an affected version.

CVE-2024-21907GHSA-5crp-9r3c-p9vrGHSA-5crp-9r3c-p9vr
View research
criticalJul 13, 2026

Command Injection in curlrequest (CVE-2020-7646)

`curlrequest` through 1.0.1 is associated with CVE-2020-7646 / GHSA-m8xj-5v73-3hh8, an OS command injection. FixVibe GitHub repo scans flag affected curlrequest versions in npm manifests and lockfiles.

CVE-2020-7646GHSA-m8xj-5v73-3hh8GHSA-m8xj-5v73-3hh8
View research
highJul 13, 2026

Authenticated Command Injection in Nginx-UI (CVE-2024-22198)

Nginx-UI releases before the fixed Go pseudo-version 1.9.10-0.20231219184941-827e76c46e63, and application beta releases before 2.0.0.beta.9, are affected by an authenticated command-injection flaw. FixVibe GitHub repo scans flag affected Nginx-UI Go module versions.

CVE-2024-22198GHSA-8r25-68wm-jw35GO-2024-2462
View research
criticalJul 12, 2026

OS Command Injection in op-browser (CVE-2020-7625)

op-browser is affected by CVE-2020-7625 / GHSA-3hq6-rmv7-39vh, an OS command injection. FixVibe GitHub repo scans flag npm manifests and lockfiles that resolve affected op-browser versions.

CVE-2020-7625GHSA-3hq6-rmv7-39vhGHSA-3hq6-rmv7-39vh
View research
highJul 12, 2026

Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry

FixVibe GitHub repo scans now flag @injectivelabs/sdk-ts 1.20.21 and associated @injectivelabs 1.20.21 package evidence in manifests and lockfiles as a version-based malware advisory.

CWE-506
View research
highJul 12, 2026

Improper Access Control in Apache ActiveMQ Artemis (CVE-2021-26118)

CVE-2021-26118 is an improper access control issue in Apache ActiveMQ Artemis OpenWire handling before 2.16.0. FixVibe GitHub repo scans flag Maven and Gradle build files that resolve affected org.apache.activemq:artemis-openwire-protocol versions.

CVE-2021-26118GHSA-q7fr-vqhq-v5xrCWE-284
View research
criticalJul 12, 2026

Command Injection in get-git-data (CVE-2020-7619)

get-git-data through 1.3.1 is listed as affected by OS command injection. FixVibe GitHub repo scans flag affected get-git-data versions in npm manifests and lockfiles.

CVE-2020-7619GHSA-wj6h-7chw-x4h2CWE-78
View research
highJul 10, 2026

OS Command Injection in strong-nginx-controller (CVE-2020-7621)

The strong-nginx-controller npm package is affected by CVE-2020-7621 / GHSA-4v9w-pvwr-38h3 through version 1.0.2. FixVibe GitHub repo scans flag affected versions in npm manifests and lockfiles.

CVE-2020-7621GHSA-4v9w-pvwr-38h3CWE-78
View research
highJul 9, 2026

NumPy Deserialization of Untrusted Data (CVE-2019-6446)

Numpy versions prior to 1.16.3 allow for the deserialization of untrusted data through the numpy.load() function when the allow_pickle parameter is set to True. This can lead to arbitrary code execution if an attacker can influence the file being loaded.

CVE-2019-6446GHSA-9fq2-x9r6-wfmfCWE-502
View research
highJul 9, 2026

OS Command Injection in karma-mojo (CVE-2020-7626)

karma-mojo 1.0.1 and earlier is affected by CVE-2020-7626, an OS command injection. FixVibe GitHub repo scans flag affected karma-mojo versions in npm manifests and lockfiles.

CVE-2020-7626GHSA-pf8j-vhg8-xmc3CWE-78
View research
highJul 9, 2026

OS Command Injection in install-package (CVE-2020-7629)

install-package 0.4.0 and earlier is affected by CVE-2020-7629, an OS command injection. FixVibe GitHub repo scans flag affected install-package versions in npm manifests and lockfiles.

CVE-2020-7629GHSA-6m4r-m3gc-h4r5CWE-78
View research
highJul 9, 2026

OS Command Injection in node-key-sender (CVE-2020-7627)

FixVibe GitHub repo scans can now flag npm manifests and lockfiles that resolve node-key-sender versions affected by CVE-2020-7627 / GHSA-4xrw-wvmq-8jmh as version-based advisory evidence.

CVE-2020-7627GHSA-4xrw-wvmq-8jmhCWE-78
View research
criticalJul 9, 2026

Milvus Unauthenticated REST API Access on Metrics Port (CVE-2026-26190)

FixVibe verified active scans flag Milvus metrics-port REST API exposure for CVE-2026-26190 / GHSA-7ppg-37fh-vcr6.

CVE-2026-26190GHSA-7ppg-37fh-vcr6CWE-306
View research
highJul 9, 2026

OS Command Injection in git-add-remote (CVE-2020-7630)

The git-add-remote npm package is vulnerable to OS command injection. Attackers can execute arbitrary commands on the host system by providing malicious input to the package's functions, which fail to properly sanitize arguments before passing them to the system shell.

CVE-2020-7630GHSA-H9V8-RM3M-5H5FCWE-78
View research
criticalJul 8, 2026

OS Command Injection in jscover (CVE-2020-7623)

jscover through 1.0.0 is affected by CVE-2020-7623 command injection. FixVibe GitHub repo scans flag affected jscover versions in npm manifests and lockfiles.

CVE-2020-7623GHSA-c5hm-xc74-pqrgGHSA-c5hm-xc74-pqrg
View research
highJul 7, 2026

Denial of Service in Go net/url via Unbounded Query Parameters (CVE-2025-61726)

Go fixed CVE-2025-61726 in the standard library net/url query parser. FixVibe GitHub repository scans flag repositories that build with an affected Go release and parse query or form input.

CVE-2025-61726CWE-770
View research
highJul 6, 2026

Denial of Service in React Server Components (CVE-2026-23864)

Multiple denial of service (DoS) vulnerabilities exist in React Server Components, specifically affecting the react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack packages. Attackers can trigger these vulnerabilities by sending specially crafted HTTP requests to Server Functions, potentially exhausting server resources or crashing the application process.

CVE-2026-23864GHSA-83fc-fqcc-2hmgCVE-2026-23864
View research
criticalJul 6, 2026

Unauthenticated SQL Injection in QCubed profile.php (CVE-2020-24913)

CVE-2020-24913 affects QCubed releases before 3.2 through profile.php SQL injection risk. FixVibe GitHub repo scans flag affected qcubed/qcubed versions in Composer files.

CVE-2020-24913GHSA-8fj6-pc5r-347qGHSA-8fj6-pc5r-347q
View research
criticalJul 6, 2026

QCubed PHP Object Injection in profile.php (CVE-2020-24914)

QCubed releases before 3.2 are affected by a profile.php PHP object-injection advisory. FixVibe GitHub repo scans flag affected qcubed/qcubed versions in Composer files.

CVE-2020-24914GHSA-7w3c-jgh7-cwjwGHSA-7w3c-jgh7-cwjw
View research
criticalJul 6, 2026

Authentication Bypass via SQL Injection in Sourcecodetester Daily Tracker System 1.0 (CVE-2020-24193)

Daily Tracker System 1.0 has a critical CVE-2020-24193 login SQL injection/authentication-bypass issue. FixVibe GitHub repo scans flag the vulnerable login source.

CVE-2020-24193CWE-89
View research
highJul 6, 2026

CVE-2020-24036: PHP Object Injection in ForkCMS Backend Ajax Endpoint

A high-severity PHP object-injection advisory affects ForkCMS versions before 5.8.3. FixVibe GitHub repo scans flag affected forkcms/forkcms versions in Composer files.

CVE-2020-24036CWE-502
View research
criticalJul 6, 2026

Arbitrary Code Execution in Handlebars via AST Injection (CVE-2026-33937)

A critical Handlebars advisory affects versions 4.0.0 through 4.7.8 when attacker-controlled AST objects are passed to compile(). FixVibe GitHub repo scans flag affected handlebars versions in npm manifests and lockfiles.

CVE-2026-33937GHSA-2w6w-674q-4c4qGHSA-2w6w-674q-4c4q
View research
criticalJul 4, 2026

Rancher Command Injection via Unsanitized YAML Parameter (CVE-2026-44939)

CVE-2026-44939 affects Rancher Manager cluster-import manifest generation in affected Rancher release lines. FixVibe now covers it as a GitHub repo version-based advisory when authorized repository evidence shows affected Rancher Manager Go module or deployment image versions. Upgrade Rancher Manager to the fixed release for the branch in use and protect cluster-registration tokens.

CVE-2026-44939GHSA-mhc6-2gfq-xx62GO-2026-5875
View research
criticalJul 4, 2026

Apache Derby LDAP Injection in Authenticator (CVE-2022-46337)

Apache Derby is affected by CVE-2022-46337 / GHSA-rcjc-c4pj-xxrp, an LDAP injection in the authenticator. FixVibe repo scans flag Maven and Gradle projects that resolve affected org.apache.derby:derby versions.

CVE-2022-46337GHSA-rcjc-c4pj-xxrpGHSA-rcjc-c4pj-xxrp
View research
criticalJul 4, 2026

Arbitrary File Write in Rollup via Path Traversal (CVE-2026-27606)

Rollup versions before 2.80.0, 3.30.0, and 4.59.0 are tied to CVE-2026-27606 / GHSA-mw96-cpmx-2vgc. FixVibe repo scans flag affected Rollup versions in npm manifests and lockfiles.

CVE-2026-27606GHSA-mw96-cpmx-2vgcCWE-22
View research
criticalJul 2, 2026

Dolibarr ERP CRM Remote Code Evaluation (CVE-2018-25357)

Dolibarr ERP CRM versions before 6.0.8 and 7.0.0 through 7.0.3 are associated with CVE-2018-25357 / GHSA-hxmh-2xc4-c894. FixVibe passive scans flag public Dolibarr deployments that expose an affected version.

CVE-2018-25357GHSA-hxmh-2xc4-c894CWE-94
View research
criticalJul 2, 2026

Authorization Bypass in gRPC-Go via HTTP/2 :path Pseudo-Header (CVE-2026-33186)

CVE-2026-33186 affects gRPC-Go servers that combine affected versions with path-based authorization and fallback-allow policy behavior. FixVibe GitHub repo scans flag google.golang.org/grpc versions before 1.79.3.

CVE-2026-33186GHSA-p77j-4mvh-x3m3GO-2026-4762
View research
highJul 2, 2026

urllib3 Decompression Bomb Vulnerability (CVE-2026-21441)

urllib3 releases from 1.22 through 2.6.2 can bypass streaming decompression-bomb safeguards when redirect responses are drained. FixVibe reports affected Python dependency evidence and points teams to urllib3 2.6.3 or newer.

CVE-2026-21441GHSA-38jv-5279-wg99GHSA-38jv-5279-wg99
View research
highJul 2, 2026

Axios Denial of Service via mergeConfig TypeError (CVE-2026-25639)

Axios versions before 0.30.3 and 1.13.5 are affected by a mergeConfig TypeError denial-of-service advisory when untrusted configuration objects with prototype-related keys reach request config. FixVibe GitHub repo scans flag affected axios versions.

CVE-2026-25639GHSA-43fc-jf86-j433GHSA-43fc-jf86-j433
View research
criticalJul 1, 2026

TYPO3 Content Element Selector Remote Code Execution (CVE-2026-46725)

TYPO3's third-party Content Element Selector extension (mmc/ceselector) has affected Composer release branches for CVE-2026-46725 / GHSA-8x3j-439w-537c. FixVibe GitHub repo scans flag affected mmc/ceselector versions in Composer files.

CVE-2026-46725GHSA-8x3j-439w-537cCWE-502
View research
highJul 1, 2026

AngularJS Regular Expression Denial of Service (CVE-2024-21490)

AngularJS 1.3.0 through 1.8.3 is affected by CVE-2024-21490, a regular-expression denial of service in ng-srcset handling. FixVibe GitHub repo scans flag affected AngularJS dependencies in npm, Bower, Maven and Gradle projects.

CVE-2024-21490GHSA-4w4v-5hc9-xrr2CWE-1333
View research
highJul 1, 2026

Buffer Overflow in Google.Protobuf (CVE-2015-5237)

Google.Protobuf versions before 3.4.0 are associated with CVE-2015-5237 / GHSA-jwvw-v7c5-m82h. FixVibe GitHub repo scans flag affected Google.Protobuf versions in NuGet projects and lockfiles.

CVE-2015-5237GHSA-jwvw-v7c5-m82hCWE-787
View research
highJun 30, 2026

HTTP Request Smuggling in Netty (CVE-2019-16869)

Netty releases affected by CVE-2019-16869 / GHSA-p979-4mfw-53vg can create HTTP request-smuggling risk in deployments where Netty parses traffic behind an intermediary. FixVibe GitHub repo scans flag affected Netty Maven and Gradle dependencies.

CVE-2019-16869GHSA-p979-4mfw-53vgCWE-444
View research
highJun 29, 2026

Gradio Absolute Path Traversal on Windows with Python 3.13+ (CVE-2026-28414)

Gradio versions before 6.7.0 can expose a path traversal risk on Windows with Python 3.13+. FixVibe GitHub repo scans flag affected Gradio dependencies and note when the repository targets that runtime.

CVE-2026-28414GHSA-39mp-8hj3-5c49CWE-22
View research
criticalJun 29, 2026

Critical Sandbox Breakout in vm2 via Promise Species (CVE-2026-47208)

FixVibe GitHub repo scans can now report npm manifest and lockfile evidence for vm2 versions associated with CVE-2026-47208 / GHSA-76w7-j9cq-rx2j.

CVE-2026-47208GHSA-76w7-j9cq-rx2jCWE-913
View research
highJun 29, 2026

Compromised GitHub Action codfish/semantic-release-action Steals CI/CD Secrets

Compromised codfish/semantic-release-action refs can put release workflows and CI/CD secrets at risk. FixVibe GitHub repo scans flag workflow YAML that references the affected refs.

CWE-506
View research
criticalJun 29, 2026

Critical Command Injection in AVideo via Video Link Embedding

AVideo versions before 12.4 are affected by CVE-2023-25313 / GHSA-pgvh-p3g4-86jw. FixVibe now covers this through safe Composer dependency evidence in GitHub repo scans.

CVE-2023-25313GHSA-pgvh-p3g4-86jwCWE-77
View research
highJun 29, 2026

Reflected XSS in Label Studio via label_config Parameter

Label Studio versions before 1.18.0 have a reflected XSS issue in the label_config upload-example workflow. FixVibe verified active scans flag affected Label Studio deployments for CVE-2025-47783.

CVE-2025-47783GHSA-8jhr-wpcm-hh4hCWE-79
View research
highJun 29, 2026

MindsDB Path Traversal in /api/files Leading to Remote Code Execution (CVE-2026-27483)

A critical path traversal vulnerability exists in the MindsDB `/api/files` endpoint. Attackers can exploit this flaw to read or write arbitrary files on the server, ultimately leading to Remote Code Execution (RCE). Users should upgrade to version 25.9.1.1 or later.

CVE-2026-27483GHSA-4894-xqv6-vrfqCWE-22
View research
highJun 29, 2026

Authenticated Command Injection in MISP STIX Import (CVE-2018-19908)

A critical command injection vulnerability was identified in MISP versions 2.4.9x prior to 2.4.99. The flaw exists within the STIX 1 import functionality where unescaped filename strings are used to construct shell commands, allowing authenticated attackers to achieve remote code execution.

CVE-2018-19908CWE-78
View research
highJun 23, 2026

Denial of Service Vulnerability in proxy npm Package

The npm proxy package has a denial-of-service advisory for versions >=2.0.0 and <2.1.1. FixVibe GitHub repo scans flag affected proxy versions for CVE-2023-2968 / GHSA-mj6p-3pc9-wf5m.

CVE-2023-2968GHSA-mj6p-3pc9-wf5mGHSA-mj6p-3pc9-wf5m
View research
highJun 23, 2026

Apache Airflow Improper Output Encoding (CVE-2024-45498)

Apache Airflow 2.10.0 shipped an example-DAG issue tracked as CVE-2024-45498 / GHSA-c392-whpc-vfpr. FixVibe GitHub repo scans flag the affected apache-airflow dependency.

CVE-2024-45498GHSA-c392-whpc-vfprGHSA-c392-whpc-vfpr
View research
highJun 23, 2026

Arbitrary File Overwrite in ONNX download_model_with_test_data

ONNX before 1.16.2 is affected by CVE-2024-5187 / GHSA-6rq9-53c3-f7vj, an arbitrary file overwrite in download_model_with_test_data. FixVibe repo scans flag affected onnx versions and the calls that use it.

CVE-2024-5187CVE-2025-51480GHSA-6rq9-53c3-f7vj
View research
highJun 23, 2026

Spring Data Commons XMLBeam XXE (CVE-2018-1259)

Spring Data Commons CVE-2018-1259 is an XXE advisory that depends on affected Spring Data Commons and XMLBeam versions. FixVibe GitHub repo scans flag projects that use both.

CVE-2018-1259GHSA-m929-7fr6-cvjgGHSA-m929-7fr6-cvjg
View research
highJun 23, 2026

Glances REST API Unauthenticated Access (CVE-2026-32596)

Glances can expose REST API telemetry without authentication when its web server is reachable from untrusted networks. FixVibe verified active scans flag Glances REST APIs that return monitoring data without credentials on the scanned origin.

CVE-2026-32596GHSA-wvxv-4j8q-4wjqCWE-200
View research
criticalJun 23, 2026

Command Injection and File Overwrite in Perl GD Library (CVE-2026-11526)

Perl GD versions before 2.86 are affected by CVE-2026-11526 when untrusted pathname strings reach filename-accepting GD::Image constructors. FixVibe GitHub repo scans flag affected GD versions in CPAN dependency files.

CVE-2026-11526CWE-73CWE-78
View research
highJun 23, 2026

Nokogiri Affected by libxslt Use-After-Free Vulnerability (CVE-2019-18197)

Nokogiri before 1.10.5 can carry a libxslt use-after-free and uninitialized-data disclosure issue. FixVibe GitHub repo scans flag affected Nokogiri versions in Gemfile, Gemfile.lock, and gemspec files.

CVE-2019-18197GHSA-242x-7cm6-4w8jCWE-416
View research
highJun 23, 2026

SSRF in SillyTavern via SearXNG Search Proxy (CVE-2026-46372)

SillyTavern 1.17.0 and earlier have CVE-2026-46372, an SSRF in the SearXNG search proxy. FixVibe verified active scans flag deployments where the proxy can be used to fetch external URLs.

CVE-2026-46372GHSA-qg89-qwwh-5f3jGHSA-qg89-qwwh-5f3j
View research
highJun 23, 2026

Authorization Plugin Bypass in Moby (CVE-2026-34040)

Moby/Docker Engine versions before 29.3.1 include an AuthZ plugin bypass fixed in 29.3.1. The issue matters for deployments that rely on authorization plugins, especially policies that inspect request bodies. FixVibe GitHub repo scans flag affected Moby Go dependencies.

CVE-2026-34040GHSA-x744-4wpc-v9h2GHSA-x744-4wpc-v9h2
View research
highJun 21, 2026

Heap Buffer Overflow in NGINX ngx_http_rewrite_module (CVE-2026-42945)

CVE-2026-42945 affects NGINX Open Source and NGINX Plus release ranges when vulnerable rewrite-module configuration is loaded. FixVibe GitHub repo scans flag affected NGINX versions paired with matching rewrite configuration.

CVE-2026-42945CWE-122
View research
highJun 21, 2026

OS Command Injection and Data Exfiltration in gemini-mcp-tool (CVE-2026-0755)

gemini-mcp-tool versions 1.1.2 through 1.1.5 are affected by CVE-2026-0755 / GHSA-4h5r-5jm8-jxjm. FixVibe GitHub repo scans flag affected npm manifests and lockfiles and recommend upgrading to 1.1.6 or newer.

CVE-2026-0755GHSA-4h5r-5jm8-jxjmCWE-78
View research
highJun 19, 2026

Mastra npm Package Scope Compromise via Stale Contributor Account

Security researchers described a Mastra npm scope compromise caused by stale publisher access. FixVibe GitHub repo scans flag easy-day-js manifest and lockfile matches associated with the compromised publish.

CWE-276CWE-506
View research
highJun 19, 2026

SQL Injection in Drupal Core (CVE-2026-9082)

Drupal Core CVE-2026-9082 affects several release lines, with vendor guidance tying the SQL-injection condition to PostgreSQL-backed sites. FixVibe GitHub repo scans flag affected drupal/core or drupal/core-recommended Composer evidence.

CVE-2026-9082GHSA-ghwc-95x2-682jCWE-89
View research
highJun 19, 2026

Command Injection in kill-port-process (CVE-2019-15609)

kill-port-process versions before 2.2.0 are affected by a command injection. FixVibe GitHub repo scans flag affected kill-port-process versions in npm manifests and lockfiles.

CVE-2019-15609GHSA-xp4x-j9vh-c3wfCWE-77
View research
highJun 18, 2026

Uncontrolled Resource Consumption in Apache Tomcat (CVE-2020-11996)

Apache Tomcat release lines 8.5.0 through 8.5.55, 9.0.0.M1 through 9.0.35, and 10.0.0-M1 through 10.0.0-M5 are affected by CVE-2020-11996, a high-severity HTTP/2 resource-consumption advisory that can impact availability when the vulnerable runtime and connector are deployed.

CVE-2020-11996GHSA-53hp-jpwq-2jgqCWE-400
View research
criticalJun 18, 2026

Authentication Bypass in Paramiko SSH Server (CVE-2018-7750)

A critical Paramiko advisory affects SSH server-mode usage across several old release branches. FixVibe GitHub repo scans now report affected Python dependency evidence as a version-based advisory and recommend upgrading to the fixed branch release or newer.

CVE-2018-7750GHSA-232r-66cg-79pxCWE-287
View research
criticalJun 18, 2026

Prototype Pollution in @andrei-tatar/nora-firebase-common (CVE-2024-30564)

A critical prototype-pollution advisory affects @andrei-tatar/nora-firebase-common versions 1.0.41 through 1.12.2. FixVibe GitHub repo scans now report affected dependency evidence as a version-based advisory and recommend upgrading to 1.12.3 or later.

CVE-2024-30564GHSA-jjff-q3q4-5hh8CWE-1321
View research
highJun 18, 2026

Apache ActiveMQ Artemis Diagnostic Information Exposure (CVE-2023-50780)

Apache ActiveMQ Artemis allows authenticated users to access diagnostic information and controls through MBeans via Jolokia. FixVibe GitHub repo scans flag affected Artemis dependencies for CVE-2023-50780.

CVE-2023-50780GHSA-443j-grxv-2pgvCWE-285
View research
criticalJun 17, 2026

Unauthenticated Outbound Federation in Apache ActiveMQ Artemis (CVE-2026-27446)

Apache ActiveMQ Artemis CVE-2026-27446 affects outbound Core federation authentication boundaries. FixVibe GitHub repo scans flag affected artemis-server Maven and Gradle declarations.

CVE-2026-27446GHSA-fw88-pf9m-p947CWE-306
View research
highJun 17, 2026

Apache Spark UI Command Injection via ACL Impersonation (CVE-2022-33891)

Apache Spark UI releases in affected version ranges can allow command execution through ACL impersonation handling when vulnerable runtime conditions are present. FixVibe GitHub repo scans flag affected Apache Spark dependencies.

CVE-2022-33891CVE-2023-32007GHSA-4x9r-j582-cgr8
View research
criticalJun 17, 2026

vLLM Remote Code Execution via Pickle Deserialization in AsyncEngineRPCServer

A critical vulnerability (CVE-2024-9053) in vLLM allows attackers to execute arbitrary code on the host machine. The issue stems from the use of Python's pickle module to deserialize data received through the AsyncEngineRPCServer entrypoints, which lacks sufficient validation of incoming payloads.

CVE-2024-9053GHSA-cj47-qj6g-x7r4CWE-502
View research
criticalJun 17, 2026

Type Confusion in YOURLS Leads to Unauthorized Resource Access

YOURLS (Your Own URL Shortener) versions prior to 1.7.4 contain a critical vulnerability where the application improperly handles resource access using incompatible types. This 'Type Confusion' flaw can be exploited by attackers to bypass intended access controls and interact with restricted system resources.

CVE-2019-14537GHSA-vf23-f26f-mjj9CWE-843
View research
criticalJun 17, 2026

Critical XXE Vulnerability in http4k-format-xml (CVE-2024-55875)

The http4k-format-xml library is vulnerable to XML External Entity (XXE) injection. Attackers can exploit this by sending malicious XML payloads to applications using affected versions of the library, potentially leading to sensitive information disclosure, Server-Side Request Forgery (SSRF), and denial of service.

CVE-2024-55875GHSA-7mj5-hjjj-8rgwCWE-611
View research
highJun 14, 2026

Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens

A malicious Codex Remote UI npm package, codexui-android, steals AI tokens. FixVibe GitHub repo scans flag it in package manifests and lockfiles.

CWE-506
View research
highJun 14, 2026

Typosquatted npm packages used to steal cloud and CI/CD secrets

FixVibe GitHub repo scans can flag manifests and lockfiles that resolve known Microsoft-reported npm typosquat package versions associated with cloud and CI/CD credential theft.

CWE-506
View research
highJun 14, 2026

Miasma Campaign: Supply Chain Attack Targeting Red Hat npm Packages

The Miasma campaign compromised npm releases under the @redhat-cloud-services scope. FixVibe GitHub repo scans flag the known compromised package versions in manifests and lockfiles.

CWE-506CWE-494
View research
highJun 11, 2026

Securing CI/CD in an Agentic World: Claude Code GitHub Action Case

FixVibe GitHub repo scans flag Claude Code GitHub Action workflows with mutable action references, broad workflow token permissions, and risky access overrides.

CWE-276
View research
highJun 11, 2026

Compromised Rust Crate 'onering' Performs Code Exfiltration

The Rust crate onering 1.4.1 was reported as compromised with build-time source-diff exfiltration behavior. FixVibe repo scans flag Cargo evidence for the malicious release or the compromised upstream git state.

CWE-506
View research
criticalJun 11, 2026

Node-gyp Supply Chain Compromise: Self-Propagating npm Worm in binding.gyp

Security researchers have identified a supply chain compromise involving a self-propagating npm worm. The malicious payload is designed to hide within binding.gyp files, which are typically used by node-gyp for compiling native addon modules.

CWE-506CWE-494
View research
highJun 10, 2026

PickleScan ZIP Archive Scan Bypass (CVE-2025-10156)

PickleScan versions before 0.0.31 are affected by CVE-2025-10156, a ZIP archive scan bypass. FixVibe GitHub repo scans flag repositories that declare affected PickleScan versions.

CVE-2025-10156GHSA-mjqp-26hc-grxgPYSEC-2025-152
View research
highJun 10, 2026

Arbitrary Code Execution in Keras via Crafted Model Configuration Loading (CVE-2025-1550)

Keras versions 3.0.0 through 3.8.x can execute code while loading crafted .keras model archives. FixVibe GitHub repo scans flag affected Keras versions in Python dependency files.

CVE-2025-1550GHSA-48g7-3x6r-xfhpCWE-94
View research
criticalJun 10, 2026

Malware in @tanstack/arktype-adapter Exfiltrates Credentials (CVE-2026-45321)

The TanStack npm supply-chain compromise included @tanstack/arktype-adapter versions 1.166.12 and 1.166.15. These package versions contained embedded malware; teams should remove them, rebuild cached install environments, and rotate credentials if either version was installed.

CVE-2026-45321GHSA-g7cv-rxg3-hmpxCWE-506
View research
criticalJun 10, 2026

Unauthenticated RCE in Langflow via Public Flow Build Endpoint (CVE-2026-33017)

Langflow 1.8.2 and earlier are associated with CVE-2026-33017 / GHSA-vwmf-pq79-vjvx. FixVibe verified active scans flag Langflow deployments that publicly report an affected version and guide teams to upgrade to 1.9.0 or newer.

CVE-2026-33017GHSA-vwmf-pq79-vjvxCWE-94
View research
criticalJun 9, 2026

Arbitrary Code Execution in NLTK via Zip Slip (CVE-2025-14009)

NLTK versions through 3.9.2 are associated with CVE-2025-14009, a downloader Zip Slip advisory that can lead to arbitrary code execution when malicious or compromised packages are extracted. Upgrade to 3.9.3 or newer.

CVE-2025-14009GHSA-7p94-766c-hgjpCWE-94
View research
criticalJun 4, 2026

Langflow CORS Misconfiguration Enables Account Takeover and RCE (CVE-2025-34291)

GitHub, NVD, and CISA describe CVE-2025-34291 as a critical Langflow CORS issue affecting versions 1.6.9 and earlier. FixVibe verified active scans flag exposed Langflow instances on an affected release that allow credentialed cross-origin requests.

CVE-2025-34291GHSA-577h-p2hh-v4mvCWE-346
View research
highMay 25, 2026

Denial of Service in 'ws' Library via Excessive HTTP Headers (CVE-2024-37890)

Affected ws server deployments can crash when processing WebSocket upgrade requests with excessive HTTP headers. FixVibe GitHub repo scans flag affected ws versions in npm manifests and lockfiles.

CVE-2024-37890GHSA-3h5v-q93c-6h6qCWE-476
View research
highMay 24, 2026

SPIP XML Validator CSRF Advisory (CVE-2016-7980)

SPIP 3.1.2 and earlier are associated with a CSRF flaw in the XML validator workflow. FixVibe flags public SPIP sites that identify an affected release.

CVE-2016-7980CWE-352
View research
criticalMay 24, 2026

SQL Injection in TMT Lockcell (CVE-2023-3047)

TMT Lockcell before version 15 is affected by CVE-2023-3047 SQL injection. FixVibe verified active scans flag Lockcell login pages that behave as the advisory describes.

CVE-2023-3047CWE-89
View research
highMay 23, 2026

Remote Code Execution in Note Mark via Path Traversal (CVE-2026-44522)

Note Mark backend versions before 0.19.4 are affected by an asset-name path traversal issue that can impact administrator data exports. FixVibe GitHub repo scans flag affected Note Mark backend versions.

CVE-2026-44522GHSA-g49p-4qxj-88v3CWE-20
View research
highMay 22, 2026

Cross-Site Request Forgery in Django (CVE-2011-0696)

Django 1.1.x before 1.1.4 and 1.2.x before 1.2.5 contain a CSRF handling flaw tracked as CVE-2011-0696 / GHSA-5j2h-h5hg-3wf8. FixVibe GitHub repo scans flag Python projects that pin or allow those Django versions.

CVE-2011-0696GHSA-5j2h-h5hg-3wf8CWE-352
View research
mediumMay 22, 2026

WordPress REST API User Enumeration (CVE-2017-5487)

WordPress 4.7 before 4.7.1 exposed post-author data through the REST API. FixVibe verified active scans flag public WordPress REST user-slug exposure.

CVE-2017-5487CWE-200
View research
highMay 22, 2026

Command Injection in WebdriverIO BrowserStack Service (CVE-2026-25244)

WebdriverIO BrowserStack service versions up to and including 9.23.2 are affected by CVE-2026-25244 / GHSA-5c46-x3qw-q7j7. FixVibe repo scans flag affected @wdio/browserstack-service versions.

CVE-2026-25244GHSA-5c46-x3qw-q7j7CWE-78
View research
criticalMay 20, 2026

Prototype Pollution in deephas (CVE-2020-28271)

deephas versions 1.0.0 through 1.0.5 are affected by CVE-2020-28271, a prototype pollution. FixVibe GitHub repo scans flag affected deephas versions; runtime exploitability depends on whether untrusted object paths reach the package.

CVE-2020-28271GHSA-4fr2-j4g9-mppfCWE-1321
View research
highMay 20, 2026

Directory Traversal in Gogs (CVE-2018-20303)

CVE-2018-20303 is a path traversal advisory affecting Gogs versions before 0.11.82.1218. Upgrade Gogs to 0.11.82.1218 or a build that includes commit ff93d9dbda5c; FixVibe GitHub repo scans flag affected Gogs versions in Go module files.

CVE-2018-20303GHSA-9hxg-w7qf-hh93CWE-22
View research
highMay 16, 2026

Arbitrary JavaScript Execution in PDF.js (CVE-2024-4367)

CVE-2024-4367 is a high-severity vulnerability in PDF.js (versions 4.1.392 and below) that allows attackers to execute arbitrary JavaScript. By rendering a malicious PDF, the library may execute embedded scripts, leading to potential XSS attacks and data exposure. Remediation involves upgrading to version 4.2.67 or later.

CVE-2024-4367GHSA-wgrm-67xf-hhpqCWE-754
View research
criticalMay 15, 2026

SQL Injection in Ghost Content API (CVE-2026-26980)

Ghost versions 3.24.0 through 6.19.0 contain a critical SQL injection vulnerability in the Content API. This allows unauthenticated attackers to execute arbitrary SQL commands, potentially leading to data exfiltration or unauthorized modifications.

CVE-2026-26980GHSA-w52v-v783-gw97CWE-89
View research
mediumMay 15, 2026

Next.js Security Header Misconfiguration in next.config.js

Next.js applications using next.config.js for header management are susceptible to security gaps if path-matching patterns are imprecise. This research explores how wildcard and regex misconfigurations lead to missing security headers on sensitive routes and how to harden the configuration.

CWE-1021CWE-200
View research
highMay 15, 2026

Detecting and Preventing Cross-Site Scripting (XSS) Vulnerabilities

Cross-Site Scripting (XSS) occurs when an application includes untrusted data in a web page without proper validation or encoding. This allows attackers to execute malicious scripts in the victim's browser, leading to session hijacking, unauthorized actions, and sensitive data exposure.

CWE-79
View research
criticalMay 15, 2026

LiteLLM Proxy SQL Injection (CVE-2026-42208)

A critical SQL injection vulnerability (CVE-2026-42208) in LiteLLM's proxy component allows attackers to bypass authentication or access sensitive database information by exploiting the API key verification process.

CVE-2026-42208GHSA-r75f-5x8p-qvmcCWE-89
View research
mediumMay 15, 2026

Security Risks of Vibe Coding: Auditing AI-Generated Code

The rise of 'vibe coding'—building applications primarily through rapid AI prompting—introduces risks such as hardcoded credentials and insecure code patterns. Because AI models may suggest code based on training data containing vulnerabilities, their output must be treated as untrusted and audited using automated scanning tools to prevent data exposure.

CWE-798CWE-200CWE-693
View research
highMay 15, 2026

JWT Security: Risks of Unsecured Tokens and Missing Claim Validation

JSON Web Tokens (JWTs) provide a standard for transferring claims, but security relies on rigorous validation. Failure to verify signatures, expiration times, or intended audiences allows attackers to bypass authentication or replay tokens.

CWE-347CWE-287CWE-613
View research
mediumMay 15, 2026

Securing Vercel Deployments: Protection and Header Best Practices

This research explores security configurations for Vercel-hosted applications, focusing on Deployment Protection and custom HTTP headers. It explains how these features protect preview environments and enforce browser-side security policies to prevent unauthorized access and common web attacks.

CWE-16CWE-693
View research
highCovered by FixVibeMay 14, 2026

Firebase Security Rules: Preventing Unauthorized Data Exposure

Firebase Security Rules are the primary defense for serverless applications using Firestore and Cloud Storage. When these rules are too permissive, such as allowing global read or write access in production, attackers can bypass intended application logic to steal or delete sensitive data. This research explores common misconfigurations, the risks of 'test mode' defaults, and how to implement identity-based access control.

CWE-284CWE-863
View research
highMay 13, 2026

CSRF Protection: Defending Against Unauthorized State Changes

Cross-Site Request Forgery (CSRF) remains a significant threat to web applications. This research explores how modern frameworks like Django implement protection and how browser-level attributes like SameSite provide defense-in-depth against unauthorized requests.

CWE-352
View research
mediumMay 13, 2026

API Security Checklist: 12 Things to Check Before Going Live

APIs are the backbone of modern web applications but often lack the security rigor of traditional frontends. This research article outlines an essential checklist for securing APIs, focusing on access control, rate limiting, and cross-origin resource sharing (CORS) to prevent data breaches and service abuse.

CWE-285CWE-799CWE-942
View research
highCovered by FixVibeMay 13, 2026

API Key Leakage: Risks and Remediation in Modern Web Apps

Hard-coded secrets in frontend code or repository history allow attackers to impersonate services, access private data, and incur costs. This article covers the risks of secret leakage and the necessary steps for cleanup and prevention.

CWE-798
View research
highMay 13, 2026

CORS Misconfiguration: Risks of Overly Permissive Policies

Cross-Origin Resource Sharing (CORS) is a browser mechanism designed to relax the Same-Origin Policy (SOP). While necessary for modern web apps, improper implementation—such as echoing the requester's Origin header or whitelisting the 'null' origin—can allow malicious sites to exfiltrate private user data.

CWE-942
View research
highMay 13, 2026

Securing the MVP: Preventing Data Leaks in AI-Generated SaaS Apps

Rapidly developed SaaS applications often suffer from critical security oversights. This research explores how leaked secrets and broken access controls, such as missing Row Level Security (RLS), create high-impact vulnerabilities in modern web stacks.

CWE-284CWE-798CWE-668
View research
highMay 13, 2026

Vulnerability Research: SSRF and Security Header Compliance

This research article examines Server-Side Request Forgery (SSRF) and the importance of HTTP security header compliance. Using insights from PortSwigger and Mozilla, we explore how automated scanning identifies these vulnerabilities and how FixVibe flags them.

CWE-918
View research
criticalMay 13, 2026

SQL Injection: Preventing Unauthorized Database Access

SQL injection (SQLi) is a critical vulnerability where attackers interfere with an application's database queries. By injecting malicious SQL syntax, attackers can bypass authentication, view sensitive data like passwords and credit card details, or even compromise the underlying server.

CWE-89
View research
mediumMay 13, 2026

Comparing Automated Security Scanners: Capabilities and Operational Risks

Automated security scanners are essential for identifying critical vulnerabilities such as SQL injection and XSS. However, they can inadvertently damage target systems through non-standard interactions. This research compares professional DAST tools with free security observatories and outlines best practices for safe automated testing.

CWE-79CWE-89CWE-352
View research
highMay 12, 2026

Supabase Security Checklist: RLS, API Keys, and Storage

This research article outlines critical security configurations for Supabase projects. It focuses on the proper implementation of Row Level Security (RLS) to protect database rows, secure handling of anon and service_role API keys, and enforcing access control for storage buckets to mitigate risks of data exposure and unauthorized access.

CWE-284CWE-668
View research
highMay 12, 2026

OWASP Top 10 Checklist for 2026: Web App Risk Review

This research article provides a structured checklist for reviewing common web application security risks. By synthesizing the CWE Top 25 most dangerous software weaknesses with industry-standard access control and browser security guidelines, it identifies critical failure modes such as injection, broken authorization, and weak transport security that remain prevalent in modern development environments.

CWE-79CWE-89CWE-285
View research
mediumCovered by FixVibeMay 12, 2026

HTTP Security Headers: Implementing CSP and HSTS for Browser-Side Defense

This research explores the critical role of HTTP security headers, specifically Content Security Policy (CSP) and HTTP Strict Transport Security (HSTS), in protecting web applications from common vulnerabilities like Cross-Site Scripting (XSS) and protocol downgrade attacks.

CWE-1021CWE-79CWE-319
View research
criticalMay 12, 2026

CVE-2025-29927: Next.js Middleware Authorization Bypass

A critical vulnerability in Next.js allows attackers to bypass authorization checks implemented in middleware. By spoofing internal headers, external requests can masquerade as authorized sub-requests, leading to unauthorized access to protected routes and data.

CVE-2025-29927GHSA-F82V-JWR5-MFFWCWE-863
View research