Vulnerabilities in HKUDS

44 results
Vexday analysis

A HKUDS apresenta 29 vulnerabilidades catalogadas, com 16 publicadas nos últimos 90 dias, indicando atividade recorrente de descoberta. Embora nenhuma esteja sob ataque ativo documentado (KEV), 3 são classificadas como críticas e a fraqueza dominante é traversal de diretório (CWE-22), fator de risco significativo em produtos de acesso a dados. O ritmo recente de divulgações recomenda acompanhamento contínuo, especialmente se o fornecedor for crítico para a operação.

CVE-2026-61808CRITICALLightRAG: Missing Authentication for Critical API Functions in Default ConfigurationEPSS 2.5%CVE-2026-19243MEDIUMHKUDS nanobot Shell Allowlist shell.py ExecTool._spawn os command injectionEPSS 2.3%CVE-2026-40502HIGHOpenHarness Remote Administrative Command Injection via Gateway HandlerEPSS 2.1%CVE-2026-61736CRITICALLightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed RequestsEPSS 1.4%CVE-2026-7551HIGHHKUDS OpenHarness Remote Command Execution via /bridge Slash CommandEPSS 1.0%CVE-2026-86124CRITICALAutoAgent Unauthenticated Remote Code Execution via the Sandbox TCP Command ServerEPSS 1.0%CVE-2026-33654HIGHZero-Click Indirect Prompt Injection and Authentication Bypass via Email PollingEPSS 0.7%CVE-2026-2577CRITICALNanobot Unauthenticated WhatsApp Session Hijack via WebSocket BridgeEPSS 0.7%CVE-2026-49139HIGHNanobot < 0.2.1 SSRF via Microsoft Teams Channel serviceUrl PoisoningEPSS 0.7%CVE-2026-61740CRITICALLightRAG: Authentication bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protectionEPSS 0.7%CVE-2026-58168HIGHDeepTutor < 1.4.10 - Insecure Default Grants Unrestricted MCP Tool Access to Non-Admin UsersEPSS 0.6%CVE-2026-6823HIGHHKUDS OpenHarness Insecure Default Remote Channel AllowlistEPSS 0.6%CVE-2026-90809MEDIUMHKUDS nanobot ExecTool shell.py ExecTool._spawn argument injectionEPSS 0.6%CVE-2026-58170HIGHVibe-Trading < 0.1.10 - Path Traversal in Proposal Identifier Allows Forging Live Trading MandatesEPSS 0.6%CVE-2026-6819HIGHHKUDS OpenHarness Plugin Management Command ExposureEPSS 0.5%CVE-2026-49138MEDIUMNanobot < 0.2.1 SSRF via web_fetch Tool Redirect FollowingEPSS 0.5%CVE-2026-19244MEDIUMHKUDS nanobot MCP enabledTools Scope mcp.py connect_mcp_servers access controlEPSS 0.5%CVE-2026-49140MEDIUMNanobot < 0.2.1 Denial of Service via Matrix Media Download HandlerEPSS 0.5%CVE-2026-40503HIGHOpenHarness Path Traversal Information Disclosure via /memory showEPSS 0.5%CVE-2026-85030MEDIUMHKUDS AI-Trader selfRegister API Endpoint routes_agent.py logic errorEPSS 0.5%