Vulnerabilities in HKUDS
44 resultsVexday analysis
A HKUDS apresenta 29 vulnerabilidades catalogadas, com 16 publicadas nos últimos 90 dias, indicando atividade recorrente de descoberta. Embora nenhuma esteja sob ataque ativo documentado (KEV), 3 são classificadas como críticas e a fraqueza dominante é traversal de diretório (CWE-22), fator de risco significativo em produtos de acesso a dados. O ritmo recente de divulgações recomenda acompanhamento contínuo, especialmente se o fornecedor for crítico para a operação.
CVE-2026-58173MEDIUMVibe-Trading < 0.1.10 - Path Traversal via Persistent Memory TypeEPSS 0.4%CVE-2026-92576CRITICALHKUDS nanobot before 0.3.0 Server-Side Request Forgery via WebFetchToolEPSS 0.4%CVE-2026-32847HIGHDeepCode 1.2.0 Path Traversal via SPA Catch-All Route in main.pyEPSS 0.4%CVE-2026-48716HIGHnanobot: Path traversal via unsanitized WhatsApp document fileName enables arbitrary file writeEPSS 0.4%CVE-2026-58169HIGHVibe-Trading < 0.1.10 - Loopback Trust and Missing Host Validation Enable DNS-Rebinding Authentication Bypass and Remote Code ExecutionEPSS 0.4%CVE-2026-90808MEDIUMHKUDS nanobot ExecTool shell.py ExecTool._spawn incomplete blacklistEPSS 0.4%CVE-2026-12203MEDIUMHKUDS AI-Trader Research Export agents.csv information disclosureEPSS 0.4%CVE-2026-56695HIGHOpenHarness - Cross-Session Disclosure via /resume and /summary CommandsEPSS 0.4%CVE-2026-85709MEDIUMLightRAG: Sensitive Information Exposure Through Raw Exception Messages in API Error ResponsesEPSS 0.4%CVE-2026-56696MEDIUMOpenHarness - Prompt Injection via /issue and /pr_comments Slash CommandsEPSS 0.4%CVE-2026-19246MEDIUMHKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url server-side request forgeryEPSS 0.4%CVE-2026-40515HIGHOpenHarness Permission Bypass via grep and glob root argumentEPSS 0.4%CVE-2026-85725MEDIUMLightRAG: Plaintext Passwords Compared Without Constant-Time FunctionEPSS 0.4%CVE-2026-85734CRITICALLightRAG: No Rate Limiting on /login Endpoint Allows Brute-Force AttacksEPSS 0.4%CVE-2026-6729MEDIUMHKUDS OpenHarness Session Key Collision Privilege EscalationEPSS 0.3%CVE-2026-58171LOWVibe-Trading < 0.1.10 - Path Traversal via Swarm Run IdentifierEPSS 0.3%CVE-2026-40516HIGHOpenHarness SSRF via web_fetch and web_searchEPSS 0.3%CVE-2026-86062MEDIUMLightRAG: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested contentEPSS 0.2%CVE-2026-85740HIGHLightRAG: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guardEPSS 0.2%CVE-2026-39413MEDIUMLightRAG has a JWT Algorithm Confusion Vulnerability in LightRAG APIEPSS 0.2%