Vulnerabilidades em HKUDS
34 resultadosAnálise Vexday
A HKUDS apresenta 29 vulnerabilidades catalogadas, com 16 publicadas nos últimos 90 dias, indicando atividade recorrente de descoberta. Embora nenhuma esteja sob ataque ativo documentado (KEV), 3 são classificadas como críticas e a fraqueza dominante é traversal de diretório (CWE-22), fator de risco significativo em produtos de acesso a dados. O ritmo recente de divulgações recomenda acompanhamento contínuo, especialmente se o fornecedor for crítico para a operação.
CVE-2026-40502HIGHOpenHarness Remote Administrative Command Injection via Gateway HandlerEPSS 1.7%CVE-2026-19243MEDIUMHKUDS nanobot Shell Allowlist shell.py ExecTool._spawn os command injectionEPSS 1.6%CVE-2026-7551HIGHHKUDS OpenHarness Remote Command Execution via /bridge Slash CommandEPSS 0.6%CVE-2026-2577CRITICALNanobot Unauthenticated WhatsApp Session Hijack via WebSocket BridgeEPSS 0.6%CVE-2026-33654HIGHZero-Click Indirect Prompt Injection and Authentication Bypass via Email PollingEPSS 0.5%CVE-2026-48716HIGHnanobot: Path traversal via unsanitized WhatsApp document fileName enables arbitrary file writeEPSS 0.4%CVE-2026-58170HIGHVibe-Trading < 0.1.10 - Path Traversal in Proposal Identifier Allows Forging Live Trading MandatesEPSS 0.4%CVE-2026-40503HIGHOpenHarness Path Traversal Information Disclosure via /memory showEPSS 0.4%CVE-2026-58168HIGHDeepTutor < 1.4.10 - Insecure Default Grants Unrestricted MCP Tool Access to Non-Admin UsersEPSS 0.4%CVE-2026-12203MEDIUMHKUDS AI-Trader Research Export agents.csv information disclosureEPSS 0.4%CVE-2026-61740CRITICALLightRAG: Authentication bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protectionEPSS 0.4%CVE-2026-49139HIGHNanobot < 0.2.1 SSRF via Microsoft Teams Channel serviceUrl PoisoningEPSS 0.4%CVE-2026-32847HIGHDeepCode 1.2.0 Path Traversal via SPA Catch-All Route in main.pyEPSS 0.4%CVE-2026-61808CRITICALLightRAG: Missing Authentication for Critical API Functions in Default ConfigurationEPSS 0.3%CVE-2026-6823HIGHHKUDS OpenHarness Insecure Default Remote Channel AllowlistEPSS 0.3%CVE-2026-58173MEDIUMVibe-Trading < 0.1.10 - Path Traversal via Persistent Memory TypeEPSS 0.3%CVE-2026-61736CRITICALLightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed RequestsEPSS 0.3%CVE-2026-6819HIGHHKUDS OpenHarness Plugin Management Command ExposureEPSS 0.3%CVE-2026-49138MEDIUMNanobot < 0.2.1 SSRF via web_fetch Tool Redirect FollowingEPSS 0.3%CVE-2026-58169HIGHVibe-Trading < 0.1.10 - Loopback Trust and Missing Host Validation Enable DNS-Rebinding Authentication Bypass and Remote Code ExecutionEPSS 0.3%