FixVibe

// vulnerability research

Vulnerability research for AI-built websites and apps.

Source-grounded notes on vulnerabilities that matter to AI-generated web apps, BaaS stacks, frontend bundles, auth, and dependency security.

Research articles summarize public vulnerability trends. Scan coverage is described only when a FixVibe check is already available.
255
published
197
live checks
255
matches
Latest researchResearch notehigh

Anthropic's Fever Dream: Claude's Package That Stole Real Keys

Recent security research highlights risks in AI-assisted development and software supply chains, where dependency confusion or malicious package injections can lead to the exfiltration of sensitive credentials [S1].

Read article

All research

255 articles

Research notemediumAug 3, 2026

Stored XSS in osTicket Installation Script (CVE-2019-14750)

A stored cross-site scripting (XSS) vulnerability was identified in osTicket versions prior to 1.10.7 and 1.12.x before 1.12.1. The flaw exists in the setup/install.php script due to a lack of input sanitization in the firstname and lastname fields. Attackers can exploit this to inject malicious scripts that execute in the context of other users' browsers.

CVE-2019-14750CWE-79
View research
Research notecriticalAug 3, 2026

Remote Code Execution in Sourcecodester Doctor's Appointment System 1.0 (CVE-2022-28568)

Sourcecodester Doctor's Appointment System 1.0 contains a critical vulnerability (CVE-2022-28568) that allows authenticated administrators to upload malicious files via the image upload feature, leading to Remote Code Execution (RCE).

CVE-2022-28568CWE-434
View research
Research notecriticalAug 3, 2026

9router Missing Authorization and OS Command Injection (CVE-2026-59800)

9router versions prior to 0.4.44 are affected by a critical security flaw combining missing authorization (CWE-862) and OS command injection (CWE-78). This allows unauthenticated remote attackers to execute arbitrary system commands on the host, potentially leading to full system compromise.

CVE-2026-59800GHSA-g6g7-pvmx-m74pCWE-78
View research
Covered by FixVibehighJul 25, 2026

runc Container Breakout via File Descriptor Leak (CVE-2024-21626)

CVE-2024-21626 is a high-severity runc file-descriptor leak that can let malicious images or container processes reach the host filesystem. FixVibe repo scans now flag container working-directory configuration associated with the breakout condition while clearly separating source evidence from deployed-runtime exploitability.

CVE-2024-21626GHSA-xr7r-f8xq-vfvvCWE-200
View research
Not automatically checkedhighJul 25, 2026

TP-Link AX10v1 HTTP Response Misconfiguration (CVE-2021-41451)

CVE-2021-41451 reports that specially formed HTTP requests can cause unexpected HTTP/0.9-style responses from some TP-Link AX10v1 firmware before V1_211117, with possible cache-related or availability impact. The current source record is sparse, and observing an unusual origin response would not prove cache poisoning. FixVibe will not send malformed raw HTTP traffic to router management interfaces for this research item.

CVE-2021-41451CWE-444
View research
Covered by FixVibecriticalJul 25, 2026

Authentication Bypass in MLflow Job Endpoints (CVE-2026-0545)

CVE-2026-0545 is an MLflow authentication-boundary flaw affecting FastAPI job routes when Basic Auth and job execution are enabled. FixVibe now covers this exposure with a verified, read-only active check that confirms the missing authentication boundary without listing, reading, submitting, executing, searching, or cancelling jobs.

CVE-2026-0545CWE-306
View research
Not automatically checkedhighJul 25, 2026

Ubiquiti EdgeRouter X Command Injection (CVE-2023-2375)

CVE-2023-2375 describes a reported post-authentication command-injection condition in the Ubiquiti EdgeRouter X Web Management Interface through firmware 2.0.9-hotfix.6. The current CVE record says the condition remains uncertain and records the vendor position that post-authentication issues are not accepted as vulnerabilities. FixVibe will not attempt command execution against router management interfaces.

CVE-2023-2375CWE-74CWE-77
View research
Not automatically checkedmediumJul 25, 2026

CVE-2021-40905: Disputed Checkmk MKP Execution Report

CVE-2021-40905 is a disputed report about administrator-controlled Checkmk extension packages. Checkmk states that administrators are intentionally able to install executable extensions, so a public version string does not establish a vulnerable condition and FixVibe does not report one.

CVE-2021-40905CWE-434
View research
Covered by FixVibecriticalJul 25, 2026

NocoBase Sandbox Escape and Remote Code Execution (CVE-2026-34156)

NocoBase @nocobase/plugin-workflow-javascript versions through 2.0.27 are affected by CVE-2026-34156. An authenticated user who can run a Workflow Script Node may escape its sandbox and execute code on the host. FixVibe repo scans now report exact affected dependency evidence; that evidence is a patch signal, not proof of reachability or exploitation.

CVE-2026-34156CWE-913
View research
Covered by FixVibecriticalJul 25, 2026

Microsoft Kiota Command Injection via Malicious OpenAPI Metadata (CVE-2026-59865)

Microsoft Kiota releases before 1.32.5 could trust dependency-install guidance supplied by an OpenAPI description. Exploitation requires an untrusted or compromised description and a developer or integration that follows the supplied install action. Kiota 1.32.5 removes support for description-supplied dependency install commands, and FixVibe now reports affected repository-managed Kiota versions as a version-based advisory.

CVE-2026-59865GHSA-hq9q-27g5-qwpjCWE-94
View research
Not automatically checkedmediumJul 25, 2026

CVE-2023-2378: Disputed EdgeRouter X Command-Injection Report

CVE-2023-2378 is a disputed report of authenticated command injection in the EdgeRouter X web management interface through firmware 2.0.9-hotfix.6. Safe automatic confirmation would require sending crafted input with administrator credentials, so FixVibe does not scan for it.

CVE-2023-2378CWE-77CWE-74
View research
Covered by FixVibehighJul 25, 2026

CVE-2025-56005: Disputed Unsafe Deserialization Risk in PLY

PLY parser construction can opt into loading parser tables through Python pickle. That becomes a code-execution risk only when a less-trusted actor can influence the existing pickle file or its path. CVE-2025-56005 is disputed, so FixVibe reports explicit repository configuration as a likely issue rather than treating the original critical RCE claim as proven.

CVE-2025-56005GHSA-qc6m-pwr3-g72pCWE-502
View research
Not automatically checkedhighJul 25, 2026

Ubiquiti EdgeRouter X Command Injection (CVE-2023-2376)

CVE-2023-2376 describes a reported post-authentication command-injection condition in the Ubiquiti EdgeRouter X Web Management Interface through firmware 2.0.9-hotfix.6. The current CVE record says the condition remains uncertain and records the vendor position that post-authentication issues are not accepted as vulnerabilities. FixVibe will not attempt command execution against router management interfaces.

CVE-2023-2376CWE-77
View research
Covered by FixVibecriticalJul 25, 2026

Remote Code Execution in verot/class.upload.php (CVE-2019-19576)

CVE-2019-19576 affects dangerous-file handling in verot/class.upload.php releases before 1.0.3 and from 2.0.0 through 2.0.3. FixVibe GitHub repo scans identify affected Composer dependency evidence as a version-based advisory; a match does not by itself confirm a reachable upload path or remote code execution.

CVE-2019-19576GHSA-r5gm-4p5w-pq2pCWE-434
View research
Not automatically checkedhighJul 25, 2026

Ubiquiti EdgeRouter X Command Injection (CVE-2023-2374)

CVE-2023-2374 describes a reported post-authentication command-injection condition in the Ubiquiti EdgeRouter X Web Management Interface through firmware 2.0.9-hotfix.6. The current CVE record says the condition remains uncertain and records the vendor position that post-authentication issues are not accepted as vulnerabilities. FixVibe will not attempt command execution against router management interfaces.

CVE-2023-2374CWE-74CWE-77
View research
Not automatically checkedcriticalJul 25, 2026

Authentication Bypass and RCE in Tenda AC Series Routers

CVE-2021-44971 is a critical authentication flaw reported in specific Tenda AC15 and AC5 firmware builds. Public research demonstrates protected data exposure and describes remote code execution as a possible chained impact, but safe automatic verification would require crossing the router's authentication boundary, so FixVibe does not scan for it.

CVE-2021-44971CWE-697
View research
Covered by FixVibecriticalJul 25, 2026

LobeHub Unauthenticated SSRF in /webapi/proxy (CVE-2026-54157)

LobeHub versions through 2.1.56 expose an unauthenticated server-side proxy route. FixVibe can confirm the exposed external-fetch behavior with a benign callback on verified targets without probing private networks or internal services.

CVE-2026-54157GHSA-xmwj-c75x-6346CWE-918
View research
Covered by FixVibehighJul 20, 2026

Next.js WebSocket SSRF Vulnerability (CVE-2026-44578)

CVE-2026-44578 is a high-severity server-side request forgery vulnerability affecting self-hosted applications that use the built-in Next.js server. Vercel-hosted deployments are not affected. FixVibe now reports affected dependency evidence in authorized GitHub repository scans as a version-based advisory, not proof of live exploitation.

CVE-2026-44578GHSA-c4j6-fc7j-m34rGHSA-c4j6-fc7j-m34r
View research
Covered by FixVibehighJul 20, 2026

Apache ActiveMQ Artemis resource-consumption denial of service (CVE-2022-23913)

CVE-2022-23913 is a high-severity Apache ActiveMQ Artemis availability issue involving uncontrolled memory consumption. FixVibe now reports affected org.apache.activemq:artemis-core-client dependency evidence in authorized repository scans without connecting to brokers or attempting denial of service.

CVE-2022-23913GHSA-pr38-qpxm-g88xGHSA-pr38-qpxm-g88x
View research