24h | 7d | 30d

Overview

  • siyuan-note
  • siyuan

25 Jul 2026
Published
25 Jul 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
Pending

KEV

Description

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a file tool with list/read/write/delete/rename/copy actions across the entire workspace. When the Publish server is enabled in anonymous mode (Conf.Publish.Enable=true and Conf.Publish.Auth.Enable=false), the Publish reverse proxy attaches an anonymous RoleReader JWT to proxied requests, allowing a remote unauthenticated attacker to reach /mcp. The attacker can read conf/conf.json to extract accessAuthCode, api.token, and cookieKey in plaintext, write arbitrary files in the workspace, and plant a plugin into data/plugins/ that executes with nodeIntegration:true and no contextIsolation on the next desktop launch, leading to administrator takeover.

Statistics

  • 1 Post

Last activity: 10 hours ago

Fediverse

Profile picture fallback

CVE-2026-66012: CRITICAL flaw in siyuan-note siyuan (<3.7.2). Missing authorization on /mcp lets remote attackers read secrets & plant malicious plugins for admin takeover. Disable anonymous Publish mode & restrict /mcp access. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 10h ago

Overview

  • med-united
  • epa4all

24 Jul 2026
Published
25 Jul 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
0.12%

KEV

Description

In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traffic (patient consent decisions, medication data, document operations, authorization tokens, and entitlement queries) becomes readable and modifiable. The attacker can also inject arbitrary requests through the hijacked channel. This issue has been patched in version 2026-05-20.

Statistics

  • 1 Post

Last activity: 19 hours ago

Fediverse

Profile picture fallback

CVE-2026-48021 in med-united epa4all (<2026-05-20): CRITICAL TLS cert validation flaw lets attackers decrypt/modify patient records & tokens. Upgrade to 2026-05-20+ ASAP. Details: radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 19h ago

Overview

  • RRWO
  • Catalyst::View::Wkhtmltopdf
  • Catalyst-View-Wkhtmltopdf

25 Jul 2026
Published
25 Jul 2026
Updated

CVSS
Pending
EPSS
0.67%

KEV

Description

Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options. Options are passed directly to the wkhtmltopdf command without sanitization. Any web application that passes user-controlled options such as the page_size, orientation or margins without validation allows shell command injection. Version 0.6.0 was released with an incomplete fix for this issue. Note that the wkhtmltopdf project is no longer being developed, and users of this package should migrate to alternative solutions.

Statistics

  • 1 Post

Last activity: 13 hours ago

Fediverse

Profile picture fallback

CVE-2026-16766: CRITICAL OS command injection in Catalyst::View::Wkhtmltopdf (<0.6.1). Exploitable via unsanitized PDF options — remote code execution possible. No maintained patch; upgrade to 0.6.1+ or migrate. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Microsoft
  • Microsoft Bing Images

19 Mar 2026
Published
19 Jun 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.70%

KEV

Description

Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.

Statistics

  • 1 Post

Last activity: 16 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

Microsoft patched two critical RCE flaws in Bing Images (CVE-2026-32194, CVE-2026-32191) that allowed unauthenticated attackers to execute arbitrary commands as SYSTEM/root via malicious SVG files processed by ImageMagick. Exploit details were published publicly in July 2026. Anyone who uploaded im…

threatnoir.com/focus

  • 0
  • 0
  • 0
  • 16h ago

Overview

  • Microsoft
  • Microsoft Bing Images

19 Mar 2026
Published
19 Jun 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.56%

KEV

Description

Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.

Statistics

  • 1 Post

Last activity: 16 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

Microsoft patched two critical RCE flaws in Bing Images (CVE-2026-32194, CVE-2026-32191) that allowed unauthenticated attackers to execute arbitrary commands as SYSTEM/root via malicious SVG files processed by ImageMagick. Exploit details were published publicly in July 2026. Anyone who uploaded im…

threatnoir.com/focus

  • 0
  • 0
  • 0
  • 16h ago
Showing 31 to 35 of 35 CVEs