FixVibe

// 취약점 리서치

AI 기반 웹사이트 및 앱을 위한 취약점 리서치.

AI 생성 웹 앱, BaaS 스택, 프론트엔드 번들, 인증, 종속성 보안과 관련된 취약점에 대한 출처 기반 노트.

연구 기사에는 대중의 취약성 추세가 요약되어 있습니다. 스캔 범위는 FixVibe 확인이 이미 사용 가능한 경우에만 설명됩니다.
60
게시됨
60
라이브 체크
60
일치
최신 리서치FixVibe에서 담당high

파일 설명자 누출을 통한 runc 컨테이너 브레이크아웃(CVE-2024-21626)

CVE-2024-21626는 악성 이미지나 컨테이너 프로세스가 호스트 파일 시스템에 도달할 수 있는 심각도가 높은 runc 파일 설명자 누출입니다. FixVibe 리포지토리 스캔은 이제 배포된 런타임 악용 가능성에서 소스 증거를 명확하게 분리하면서 브레이크아웃 조건과 관련된 컨테이너 작업 디렉터리 구성에 플래그를 지정합니다.

글 읽기

전체 리서치

60개 글

FixVibe에서 담당criticalJul 25, 2026

MLflow 작업 엔드포인트의 인증 우회(CVE-2026-0545)

CVE-2026-0545는 기본 인증 및 작업 실행이 활성화된 경우 FastAPI 작업 경로에 영향을 미치는 MLflow 인증 경계 결함입니다. 이제 FixVibe는 작업 나열, 읽기, 제출, 실행, 검색 또는 취소 없이 누락된 인증 경계를 확인하는 검증된 읽기 전용 활성 검사를 통해 이러한 노출을 처리합니다.

CVE-2026-0545CWE-306
리서치 보기
FixVibe에서 담당highJul 25, 2026

CVE-2025-56005: PLY의 안전하지 않은 역직렬화 위험 논란

PLY 파서 구성은 Python 피클을 통해 파서 테이블을 로드하도록 선택할 수 있습니다. 이는 신뢰도가 낮은 행위자가 기존 피클 파일이나 해당 경로에 영향을 미칠 수 있는 경우에만 코드 실행 위험이 됩니다. CVE-2025-56005는 논쟁의 여지가 있으므로 FixVibe는 원래의 중요한 RCE 주장을 입증된 것으로 처리하지 않고 명시적인 저장소 구성을 가능한 문제로 보고합니다.

CVE-2025-56005GHSA-qc6m-pwr3-g72pCWE-502
리서치 보기
FixVibe에서 담당highJul 20, 2026

Next.js WebSocket SSRF 취약점 (CVE-2026-44578)

CVE-2026-44578 내장된 기능을 사용하는 자체 호스팅 애플리케이션에 영향을 미치는 심각도가 높은 서버 측 요청 위조 취약점입니다. Next.js 서버. Vercel-hosted 배포는 영향을 받지 않습니다. FixVibe 이제 승인된 항목에서 영향을 받은 종속성 증거를 보고합니다. GitHub 실시간 악용 증거가 아닌 버전 기반 권고로 저장소를 검사합니다.

CVE-2026-44578GHSA-c4j6-fc7j-m34rGHSA-c4j6-fc7j-m34r
리서치 보기
FixVibe에서 담당highJul 20, 2026

Apache ActiveMQ Artemis 자원 소비 서비스 거부(CVE-2022-23913)

CVE-2022-23913 심각도가 높음 Apache ActiveMQ Artemis 통제되지 않은 메모리 소비와 관련된 가용성 문제. FixVibe 이제 영향을 받는 것으로 보고됩니다 org.apache.activemq:artemis-core-client 브로커에 연결하거나 서비스 거부를 시도하지 않고 승인된 저장소 스캔의 종속성 증거.

CVE-2022-23913GHSA-pr38-qpxm-g88xGHSA-pr38-qpxm-g88x
리서치 보기
FixVibe에서 담당highJul 20, 2026

조건부 NGINX HTTP/2 및 gRPC 프록시 버퍼 오버플로(CVE-2026-42055)

CVE-2026-42055는 NGINX HTTP/2 및 gRPC 업스트림 프록시의 조건부 힙 기반 버퍼 오버플로입니다. F5는 CVSS v3.1에서 높음 8.1점을 얻었고, nginx.org에서는 중간으로 분류했습니다. 악용에는 대형 클라이언트 헤더 버퍼를 포함하여 몇 가지 일반적이지 않은 구성 전제 조건이 필요합니다. 작업자 다시 시작은 문서화된 직접적인 영향이며, 코드를 실행하려면 ASLR을 비활성화하거나 우회해야 합니다. FixVibe는 영향을 받은 공식 NGINX 오픈 소스 컨테이너 배포에 대한 보수적인 저장소 증거를 보고하고 위험한 활성 증명을 수행하지 않습니다.

CVE-2026-42055CWE-122CWE-787
리서치 보기
FixVibe에서 담당criticalJul 20, 2026

vLLM 비디오 처리 RCE 권고(CVE-2026-22778)

CVE-2026-22778는 배포가 비디오 지원 모델을 제공하고 공격자가 제어하는 비디오 입력을 처리할 때 vLLM 릴리스 0.8.3부터 0.14.0까지 영향을 미칩니다. vLLM 0.14.1에서는 문제가 해결되었습니다. FixVibe는 실시간 악용 확인이 아닌 안전한 저장소 종속성 증거를 보고합니다.

CVE-2026-22778GHSA-4r2x-xpjr-7cvvPYSEC-2026-565
리서치 보기
FixVibe에서 담당criticalJul 20, 2026

ChromaDB Python 백엔드 사전 인증 RCE(CVE-2026-45829)

CVE-2026-45829은 승인 전에 공격자가 제어하는 ​​포함 구성이 처리될 때 ChromaDB's optional Python FastAPI backend에 영향을 미칩니다. 기본 Rust 프런트엔드는 영향을 받지 않습니다.

CVE-2026-45829CWE-94CWE-502
리서치 보기
FixVibe에서 담당highJun 11, 2026

Mbed TLS Double-Free Vulnerability (CVE-2021-44732)

CVE-2021-44732 affects older Mbed TLS releases in a session-handling error path. FixVibe repo scans can now flag affected version evidence in source and build metadata, while making clear that the scan did not run Mbed TLS, force out-of-memory behavior, or prove exploitation.

CVE-2021-44732GHSA-7g56-f7p4-fmcqCWE-415
리서치 보기
FixVibe에서 담당criticalJun 10, 2026

Missing Authentication in Moxa NPort Series Devices (CVE-2016-9369)

Moxa NPort serial device servers before vendor fixed firmware releases are associated with CVE-2016-9369. FixVibe can flag strong HTTP model and firmware-version evidence as a version-based advisory during verified active scans without attempting firmware updates, unauthenticated administrative actions, or exploit confirmation.

CVE-2016-9369CWE-287CWE-306
리서치 보기
FixVibe에서 담당criticalJun 10, 2026

Schneider Electric Modicon M221 Authentication Replay Advisory (CVE-2018-7790)

FixVibe can flag public Modicon M221 HTTP product and firmware-version evidence associated with CVE-2018-7790 as a version-based advisory. The scan does not replay authentication, query industrial protocols, upload PLC programs, or prove unauthorized access.

CVE-2018-7790CWE-294
리서치 보기
FixVibe에서 담당criticalJun 10, 2026

Langflow CORS Misconfiguration Enables Account Takeover and RCE (CVE-2025-34291)

GitHub, NVD, and CISA describe CVE-2025-34291 as a critical Langflow CORS issue affecting versions 1.6.9 and earlier. FixVibe covers it with a verified-target check that combines Langflow version and fingerprint evidence with credentialed CORS header reflection, without authenticating, reading tokens, triggering refresh flows, or proving code execution.

CVE-2025-34291GHSA-577h-p2hh-v4mvCWE-346
리서치 보기
FixVibe에서 담당highJun 10, 2026

PickleScan ZIP Archive Scan Bypass (CVE-2025-10156)

FixVibe can flag repositories that declare PickleScan versions before 0.0.31, which public advisories associate with a ZIP archive scan-bypass issue. The scanner reports dependency evidence, affected range, fixed version, confidence, and what was not verified; it does not run PickleScan, create corrupted archives, load models, or prove code execution.

CVE-2025-10156GHSA-mjqp-26hc-grxgPYSEC-2025-152
리서치 보기
FixVibe에서 담당criticalJun 10, 2026

Malware in @tanstack/arktype-adapter Exfiltrates Credentials (CVE-2026-45321)

The TanStack npm supply-chain compromise included @tanstack/arktype-adapter versions 1.166.12 and 1.166.15. These package versions contained embedded malware; teams should remove them, rebuild cached install environments, and rotate credentials if either version was installed.

CVE-2026-45321GHSA-g7cv-rxg3-hmpxCWE-506
리서치 보기
FixVibe에서 담당criticalJun 9, 2026

Arbitrary Code Execution in NLTK via Zip Slip (CVE-2025-14009)

NLTK versions through 3.9.2 are associated with CVE-2025-14009, a downloader Zip Slip advisory that can lead to arbitrary code execution when malicious or compromised packages are extracted. Upgrade to 3.9.3 or newer.

CVE-2025-14009GHSA-7p94-766c-hgjpPYSEC-2026-96
리서치 보기
FixVibe에서 담당highJun 9, 2026

Apache Tomcat Sensitive Information Disclosure (CVE-2021-25122)

Apache Tomcat h2c request handling in affected 8.5.x, 9.0.x, and 10.0.x release lines can mix request headers and limited body data between users. Upgrade to 8.5.63, 9.0.43, 10.0.2, or newer for the release line in use.

CVE-2021-25122GHSA-j39c-c8hj-x4j3CWE-200
리서치 보기
FixVibe에서 담당highJun 4, 2026

Information Disclosure via Undocumented TRACK Method in Microsoft IIS 5.0

CVE-2003-1567 covers Microsoft IIS 5.0 TRACK behavior that can echo request content. FixVibe now reports this as a verified active-scan finding when target-specific, non-sensitive evidence shows legacy TRACK echo behavior, while clearly separating that evidence from proof of cookie theft or compromise.

CVE-2003-1567CWE-200
리서치 보기
FixVibe에서 담당criticalJun 4, 2026

Stack-Based Buffer Overflow in Orpak SiteOmat CGI Components (CVE-2017-14854)

FixVibe verified active scans can now identify strong Orpak SiteOmat BOS product and version evidence associated with CVE-2017-14854. Findings are reported as version-based advisories: FixVibe verifies the exposed SiteOmat version, not CGI crash behavior or code execution.

CVE-2017-14854CWE-119CWE-121
리서치 보기
FixVibe에서 담당highJun 4, 2026

Microsoft ATL COM Initialization Advisory (CVE-2009-2493)

Microsoft ATL components and controls built with affected ATL headers can be exposed to CVE-2009-2493 under COM initialization conditions. FixVibe now treats this as covered by its repo source/build advisory for legacy Visual C++ ATL projects, without claiming build-machine patch state, deployed ActiveX or COM exposure, or live code-execution proof.

CVE-2009-2493CWE-264CWE-94
리서치 보기
FixVibe에서 담당highJun 4, 2026

Apache Tomcat EncryptInterceptor Bypass (CVE-2026-34486)

FixVibe covers CVE-2026-34486 as a repo-scan version advisory for exact Apache Tomcat releases, while keeping clustering and plaintext-disclosure conditions explicit.

CVE-2026-34486GHSA-69r9-qgr7-g2wjCWE-311
리서치 보기