Vulnerabilidades em Jovancoding
11 resultadosAnálise Vexday
Jovancoding apresenta 11 vulnerabilidades na base, todas publicadas nos últimos 90 dias, com 3 classificadas como críticas e predominância de falhas de path traversal (CWE-22). Apesar do volume recente e da severidade, nenhuma vulnerabilidade está sob exploração ativa conhecida (KEV), sugerindo risco elevado em potencial mas sem evidência de campanha coordenada no momento.
CVE-2026-42856HIGHNetwork-AI: Missing authentication on MCP HTTP endpoint allows unauthenticated privileged tool callsEPSS 0.5%CVE-2026-64622CRITICALNetwork-AI 5.12.2 through 5.13.3 Missing Authorization via ApprovalInboxEPSS 0.4%CVE-2026-54051CRITICALNetwork-AI has an an OS Command Injection issueEPSS 0.4%CVE-2026-48814CRITICALNetwork-AI: Empty default secret still authorizes all requests (Incomplete fix for CVE-2026-46701)EPSS 0.3%CVE-2026-64623HIGHNetwork-AI before 5.13.4 Cryptographic Signature Verification BypassEPSS 0.2%CVE-2026-46701HIGHNetwork-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default SecretEPSS 0.2%CVE-2026-58484HIGHNetwork-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruningEPSS 0.1%CVE-2026-58482MEDIUMNetwork-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actionsEPSS 0.1%CVE-2026-58481MEDIUMNetwork-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directoryEPSS 0.1%CVE-2026-58413MEDIUMEnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment dataEPSS 0.1%CVE-2026-58414MEDIUMNetwork-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backupsEPSS 0.1%