Real-time vulnerability trends from news, Mastodon, and Bluesky
Real-time vulnerability trends from news, Mastodon, and Bluesky
5,406
Tracked CVEs
144
News Articles
1,588
Mastodon Posts
6,114
Bluesky Posts
Vulnerability: CVE-2026-21962 is an easily exploitable vulnerability in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in (versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0) that allows unauthenticated attackers with network access via HTTP to compromise the affected systems and gain unauthorized access to critical data or perform unauthorized modifications.
Trending: The vulnerability is trending due to its inclusion in the US CISA catalog of known exploited vulnerabilities, indicating active exploitation in the wild, and federal government departments have been mandated to patch the vulnerability by a specific deadline.
Vulnerability: A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. An unauthenticated attacker can send specially crafted SMTP requests that exploit improper sanitization of untrusted input to execute arbitrary operating system commands as the Zimbra user.
Trending: The vulnerability is receiving attention across social media platforms including Bluesky and Mastodon, with security researchers and news outlets highlighting its high severity rating (8.9) and sharing details about the affected Zimbra Collaboration versions.
Vulnerability: An unauthenticated privilege escalation vulnerability exists in SAML SP Single Sign On plugin versions 5.4.3 and earlier, affecting the miniOrange SAML 2.0 SSO WordPress plugin. The vulnerability allows attackers to forge SAML responses and gain unauthorized access to WordPress administrator accounts.
Trending: This vulnerability is trending due to active exploitation in the wild, with public proof-of-concept code available. Multiple security news outlets and social media platforms are reporting on coordinated attacks targeting WordPress sites using this authentication bypass flaw.
Vulnerability: The SAML Single Sign On – SSO Login plugin for WordPress (versions up to 5.4.4) contains an authentication bypass vulnerability in the mo_saml_validate_signature() function. A loose boolean check on the openssl_verify() return value allows unauthenticated attackers to log in as any WordPress user, including administrators, by submitting a crafted SAMLResponse with a malformed signature that triggers an OpenSSL error.
Trending: The vulnerability is gaining attention on social media platforms like Bluesky, where security researchers are highlighting it as a serious risk due to its ability to allow attackers to bypass password authentication entirely and gain administrative access to WordPress installations.
Vulnerability: CVE-2026-60004 is a critical remote code execution (RCE) vulnerability in Gitea that allows repository writers to execute shell commands through a diffpatch Git hook. The vulnerability affects Gitea versions prior to 1.27.1.
Trending: The vulnerability is trending due to the availability of public proof-of-concept exploits and active discussion across security communities. Multiple security accounts are urging immediate updates to Gitea 1.27.1, with the high CVSS 9.8 rating and RCE capability driving widespread attention in DevOps and cybersecurity circles.
Vulnerability: A double free vulnerability in OpenSSL's QUIC server implementation occurs when channel creation fails for an initial packet, causing the QRX (QUIC record layer RX) object to be freed twice. This heap corruption typically results in denial of service through termination of the QUIC server process, with no evidence of remote code execution exploitability.
Trending: The vulnerability is trending due to its inclusion in the August 2026 OpenSSL security update that addresses nine flaws, with security researchers and organizations emphasizing the need to patch immediately given the denial of service impact and the relative ease of triggering the failure through malformed INITIAL packets with invalid destination connection IDs.
Vulnerability: CVE-2026-39975 affects Combodo iTop, a web-based IT service management tool. Prior to version 3.2.3, unauthenticated users could delete the .readonly file on iTop instances, leading to remote code execution by bypassing write protections established during setup.
Trending: This vulnerability is trending due to its critical CVSS 9.4 severity rating and the fact that it requires no authentication to exploit, allowing remote attackers to potentially take control of affected servers. Multiple cybersecurity accounts on Bluesky and Mastodon have highlighted the vulnerability's severity and ease of exploitation.
Vulnerability: CVE-2026-77635 is a SQL injection vulnerability in CakePHP's FunctionsBuilder::jsonValue() function when used with PostgresDriver, affecting versions prior to 5.1.10, 5.2.15, and 5.3.7. The vulnerability occurs when user-controlled data is supplied to the jsonPath parameter.
Trending: This vulnerability is receiving attention across security-focused social media platforms with a CVSS 9.2 critical severity rating, with multiple cybersecurity accounts sharing alerts and technical details about the SQL injection risk in CakePHP's PostgreSQL JSON handling functionality.
Vulnerability: An unauthenticated privilege escalation vulnerability exists in TranslatePress WordPress plugin versions 3.3.2 and earlier, allowing attackers to escalate privileges without authentication.
Trending: The vulnerability is receiving significant attention across social media platforms including Bluesky and Mastodon, with multiple security accounts sharing alerts about its critical 9.8 severity rating following its recent publication on August 24, 2026.
Vulnerability: Vocos through version 0.1.0 contains an arbitrary code execution vulnerability in its model loading mechanism. The instantiate_class function in vocos/pretrained.py fails to restrict which classes can be instantiated from configuration files, allowing attackers to execute arbitrary code by specifying malicious class paths in config.yaml files downloaded from Hugging Face repositories.
Trending: CVE-2026-79784 is receiving attention across security-focused social media platforms including Bluesky and Mastodon, with multiple posts from security news aggregators highlighting the high severity rating (8.8) and the risk posed by loading models from untrusted repositories.
Vulnerability: CVE-2026-76070 is a critical stack-based buffer overflow vulnerability in Netis NC63 firmware through V3.0.0.3327 that allows unauthenticated remote attackers to achieve remote code execution with root privileges by submitting an oversized Base64-encoded password to the login handler in /bin/netis.cgi.
Trending: The vulnerability is trending across multiple social media platforms including Bluesky and Mastodon, with security researchers and infosec accounts actively sharing details about the critical 9.8-rated flaw shortly after its public disclosure on August 24, 2026.
Vulnerability: CVE-2026-76071 is a stack-based buffer overflow vulnerability in Netis NC63 firmware through version V3.0.0.3327 that allows unauthenticated remote attackers to achieve remote code execution as root by supplying an oversized destHost parameter to the ipFilterList=mod action in netis.cgi.
Trending: The vulnerability is trending due to its critical severity rating (9.8) and active discussion across multiple social media platforms including Bluesky and Mastodon, with security researchers and infosec communities highlighting the unauthenticated remote code execution capability that requires no user interaction.
Vulnerability: CVE-2026-28165 is an unauthenticated privilege escalation vulnerability affecting Digits versions 9.2 and earlier, including the Digits WordPress plugin, which allows unauthenticated users to gain administrator privileges.
Trending: The vulnerability is receiving attention across social media platforms with a CVSS 9.8 critical severity rating, with multiple cybersecurity accounts sharing alerts and details about the flaw affecting WordPress sites using the Digits feature.
Vulnerability: An unauthenticated privilege escalation vulnerability exists in Affiliate Pro - Affiliate Program for WooCommerce & WordPress in versions 8.9.1 and earlier, allowing unauthenticated attackers to gain elevated privileges.
Trending: The vulnerability is receiving attention across social media platforms with a CVSS 9.8 critical severity rating, with multiple cybersecurity accounts highlighting the unauthenticated nature of the exploit and its potential for full system compromise.
Vulnerability: Multiple vulnerabilities in affected versions of Zscaler Client Connector allow remote code execution, enabling unauthenticated, unprivileged users to execute arbitrary code in the ZCC context. The vulnerability affects Zscaler Client Connector deployments.
Trending: CVE-2026-59568 is receiving significant attention across social media platforms with a CVSS 9.1 critical severity rating. The vulnerability is being actively discussed in cybersecurity communities on Bluesky and Mastodon, with mentions highlighting the critical nature of the remote code execution risk and the potential for attackers to take control of affected connectors.
Vulnerability: An authorization bypass vulnerability in the supplier API of Roskus Prospero Flow CRM versions 4.0.0 through 5.3.1 allows any authenticated user to read, modify, and reassign another company's supplier records to their own company through a PUT request to /api/supplier/{id} by controlling the company_id parameter.
Trending: The vulnerability is receiving attention across social media platforms due to its critical CVSS 9.3 severity rating and the ease of exploitation, requiring only an authenticated user account and a simple API request to compromise other organizations' supplier data.
Vulnerability: CVE-2026-78370 is an authorization flaw in RansomLook's legacy database export functionality that allows unauthenticated remote users to access the /export/<database> endpoint and retrieve private information including ransomware intelligence, victim data, and internal tracking records that should remain restricted to authorized users.
Trending: The vulnerability is receiving attention across social media platforms with a CVSS 9.2 critical severity rating, with multiple cybersecurity accounts highlighting the risk that attackers can exploit the unauthenticated export endpoint to access sensitive data from RansomLook instances.
Vulnerability: CVE-2026-78372 is an authorization bypass vulnerability in RansomLook that fails to consistently enforce access controls on private groups, markets, and ransom notes. An unauthenticated remote attacker can access restricted information including private entity names, ransom-note content, metadata, post counts, and uptime statistics through multiple web views and API endpoints.
Trending: The vulnerability is receiving attention across security-focused social media platforms due to its critical CVSS 9.2 severity rating and the ease of exploitation, requiring no authentication or user interaction. Multiple cybersecurity accounts are actively sharing alerts about the disclosure of private ransom group information and market details that were explicitly intended to be restricted.
Vulnerability: CVE-2026-78387 is an authorization weakness in RansomLook's web-based configuration editor at the /admin/config endpoint that allows authenticated low-privileged users to modify security-sensitive application settings, LDAP, SMTP, and notification configurations by writing directly to the config/generic.json file. Successful exploitation could enable attackers to alter authentication configuration, disrupt services, or render the RansomLook installation unavailable.
Trending: The vulnerability is receiving attention across social media platforms due to its critical CVSS 9.4 severity rating and the significant privilege escalation risk it poses, with security researchers highlighting that administrative functionality is accessible to any logged-in user regardless of privilege level.
Vulnerability: A critical flaw in the reset-credentials flow of the keycloak-services component in Red Hat Build of Keycloak allows unauthenticated attackers to force password resets for any user without email verification, enabling full account takeover by setting new credentials.
Trending: The vulnerability is receiving attention across social media platforms due to its critical CVSS 9.1 severity rating and the high-impact nature of the flaw, which affects identity and access management systems used by organizations.
Vulnerability: A stack buffer overflow exists in the OCPP 1.6 client's parse_getconfig_msg() function in subsys/net/lib/ocpp/ocpp_j.c, where an unbounded strcpy() copies attacker-controlled JSON "key" strings into a fixed 50-byte stack buffer. An attacker controlling the central system endpoint or performing a man-in-the-middle attack can send a malicious GetConfiguration request to trigger a stack overflow, potentially causing denial of service or remote code execution.
Trending: The vulnerability is receiving attention on social media platforms including Bluesky and Mastodon due to its critical CVSS 9.8 severity rating and the straightforward nature of the exploitation vector over WebSocket connections used by OCPP charge points.
Vulnerability: An unrestricted file upload vulnerability with dangerous file type handling in TRtek Technological Products' Software Repository Management allows attackers to upload web shells to web servers. The vulnerability affects Software Repository Management versions before 2fb4acee.
Trending: The vulnerability is receiving attention across social media platforms due to its critical CVSS 9.8 severity rating, with security researchers and cybersecurity accounts actively sharing alerts and details about the flaw.
Vulnerability: A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Trending: The vulnerability is receiving attention across social media platforms including Bluesky and Mastodon, with security researchers and infosec communities sharing alerts about the high-severity CVE (7.8 rating) and its potential for arbitrary code execution.
Vulnerability: A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability that allows a malicious actor to execute arbitrary code in the context of the current process.
Trending: The vulnerability is receiving attention across social media platforms including Bluesky and Mastodon, with security researchers and infosec communities sharing alerts about this high-severity (7.8) CVE affecting Autodesk 3ds Max users.
Vulnerability: An unauthenticated Cross Site Scripting (XSS) vulnerability exists in Boost versions 2.0.4 and earlier, allowing attackers to inject malicious scripts without requiring authentication.
Trending: The vulnerability is gaining attention across security communities on Mastodon and Bluesky due to its high CVSS score of 7.1 and the fact that it remains unpatched, with security researchers urging immediate system audits and risk mitigation measures.
Vulnerability: PraisonAI versions prior to 4.6.58 contain an authentication bypass vulnerability where the _create_agents_app() function fails to authenticate POST requests to /agents and /agents/{agent_name} endpoints, allowing requests with missing or incorrect bearer and X-API-Key values to reach agent execution.
Trending: The vulnerability is receiving attention across social media platforms with security researchers highlighting the authentication bypass and its CVSS 7.3 severity rating, with recommendations for immediate updates to version 4.6.58.
Vulnerability: Crater Invoice through version 6.0.6 contains a path traversal vulnerability in the self-update API that allows authenticated company owners to write arbitrary files outside the intended extraction directory using crafted ZIP archives with ../ sequences, enabling remote code execution by writing malicious PHP files to the web-accessible public directory.
Trending: The vulnerability is receiving attention across security-focused social media platforms including Bluesky and Mastodon, with security news outlets highlighting its high severity rating (8.8) and sharing details about the exploitation mechanism involving unsanitized ZIP entry names.
Vulnerability: Dell ThinOS 10 versions prior to 2605_10.2518 contain an Improper Access Control vulnerability that allows a low privileged attacker with local access to gain unauthorized access to affected systems.
Trending: The vulnerability is receiving attention across social media platforms including Bluesky and Mastodon, where it is being shared by security news outlets with a CVSS score of 7.8 (High severity), indicating active awareness and discussion within the infosec community.
Vulnerability: A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Trending: The vulnerability is receiving attention across social media platforms including Bluesky and Mastodon, with security researchers and infosec communities sharing alerts about the high-severity issue (CVSS 7.8) and its potential for arbitrary code execution.
Vulnerability: Mistune versions 3.3.0 through 3.3.2, a Python Markdown parser with renderers and plugins, are vulnerable to denial of service through deeply nested tokens. Crafted Markdown with consecutive asterisk characters can create deeply nested emphasis tokens that exceed Python's recursion limit, causing RecursionError and crashing the parsing process.
Trending: The vulnerability is receiving attention across security-focused social media platforms including Bluesky and Mastodon, with posts highlighting its high severity rating (7.5) and sharing details about the affected versions and fix available in version 3.3.3.
Vulnerability: A Powermail extension vulnerability allows unauthenticated users to submit Fluid template syntax through a form field configured as "sender_name," which is passed unsanitized directly into a Fluid View for rendering. This can lead to arbitrary Fluid ViewHelper execution, enabling disclosure of server configuration, environment variables, application source code, and potentially remote code execution.
Trending: The vulnerability is receiving significant attention due to its critical CVSS 9.5 severity rating and confirmed active exploitation in the wild, with minimal barriers to exploitation requiring only a standard form submission to a commonly-configured default field.
Vulnerability: A TYPO3 extension fails to safely process untrusted client input from attacker-controlled cookies, passing them directly to PHP's unserialize() function. A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server.
Trending: The vulnerability is receiving attention across social media platforms due to its critical CVSS 9.3 severity rating and the ease of exploitation, requiring only unauthenticated remote access with no user interaction needed.
Vulnerability: Filament, a collection of full-stack components for accelerated Laravel development, contains an authentication bypass vulnerability in versions prior to 4.12.0 and 5.7.0. Incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when recovery codes are enabled, though email-based multi-factor authentication is not affected.
Trending: The vulnerability is receiving attention across social media platforms including Bluesky and Mastodon, with security news outlets highlighting its high severity rating of 8.1 and sharing information about the affected versions and available patches.
Vulnerability: CVE-2026-77998 is an unauthenticated authentication bypass vulnerability in miniOrange SAML SSO extensions for Joomla (versions < 11.0.2, < 6.4, and < 6.4 respectively) caused by improper boolean validation of OpenSSL signature verification results. Attackers can exploit this flaw by submitting a crafted SAMLResponse with a malformed signature to log in as any Joomla user, including administrators.
Trending: This vulnerability is receiving significant attention on social media platforms with a CVSS 10 critical severity rating, indicating widespread concern about its potential impact on Joomla installations using miniOrange SAML authentication extensions.
Vulnerability: An unauthenticated PHP Object Injection vulnerability affects The Events Calendar plugin in versions 6.17.2 and earlier, allowing attackers to exploit the flaw without requiring authentication.
Trending: The vulnerability is receiving attention across social media platforms including Bluesky and Mastodon due to its critical severity rating of 9.8, with security researchers and news outlets actively sharing information about the flaw and directing users to vulnerability tracking resources.
Vulnerability: CVE-2026-78284 is an unauthenticated arbitrary file deletion vulnerability affecting MasterStudy LMS versions 3.7.42 and earlier. The vulnerability allows attackers to delete files without authentication.
Trending: The vulnerability is receiving attention across social media platforms including Bluesky and Mastodon, where it has been shared by security news outlets with a CVSS score of 8.6 (High severity), indicating significant concern within the infosec community.
Vulnerability: CVE-2026-78555 is an API key disclosure vulnerability in RansomLook's authenticated /admin/apikeys administration page, where complete API keys were embedded in hidden form fields despite only shortened representations being displayed to users. An attacker obtaining these exposed credentials could authenticate with the privileges assigned to the compromised key, potentially accessing private data.
Trending: The vulnerability is trending on social media platforms including Bluesky, where multiple security accounts have shared information about the disclosure shortly after its publication on August 24, 2026. The exposure mechanism—full API keys visible in HTML source code and page DOM—has generated attention within the infosec community due to the risk of unintentional credential exposure through browser caches, debugging proxies, and monitoring systems.
Vulnerability: The Total Donations plugin for WordPress versions up to and including 2.0.5 contains a privilege escalation vulnerability that allows unauthenticated attackers to elevate their privileges to administrator level.
Trending: The vulnerability is trending due to its critical severity (CVSS 9.8) and the fact that no patch is currently available, with security researchers recommending immediate plugin removal or disablement as a mitigation measure.
Vulnerability: NLTK before version 3.10.0 (affected versions ≤3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method that allows arbitrary code execution when loading attacker-crafted model files. The vulnerability affects applications using NLTK's transition parser functionality.
Trending: The vulnerability is receiving attention on security-focused social media platforms, with multiple posts highlighting the remote code execution risk and emphasizing that any application loading a specially crafted NLTK model file could execute arbitrary code with user privileges.
Vulnerability: NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft malicious pickle payloads invoking dangerous in-namespace functions like ReppTokenizer._execute and numpy.f2py.crackfortran.myeval through pickle REDUCE to execute arbitrary commands during model or tokenizer artifact loading.
Trending: The vulnerability is receiving attention across social media platforms with a CVSS 9.3 critical severity rating, with security researchers and cybersecurity accounts actively sharing alerts and technical details about the flaw.
Vulnerability: Ech0 before version 4.7.3 contains a critical flaw in access token revocation for tokens created with the never-expire option, allowing attackers to maintain perpetual authenticated access after token theft. Three independent revocation mechanisms fail: logout panics on nil ExpiresAt field, RevokeToken skips when remainTTL is zero, and admin delete does not blacklist the JTI, leaving stolen tokens cryptographically valid until JWT secret rotation.
Trending: This vulnerability is trending due to its critical CVSS 9.1 severity rating and active discussion across multiple social media platforms including Bluesky and Mastodon, with security researchers highlighting the serious implications of perpetual token validity for systems using Ech0.
Vulnerability: NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags like -agentpath, -javaagent, or @argfile to achieve arbitrary code execution through Stanford wrapper classes.
Trending: The vulnerability is receiving attention across social media platforms including Bluesky and Mastodon, with security researchers and infosec communities sharing alerts about its critical 9.8 severity rating and the need for updates to NLTK versions 3.10.3 and later.
Vulnerability: Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\Twig\SecurityPolicy that allows authenticated backend users with template-editing permissions to bypass sandbox restrictions. Attackers can exploit method forwarding through Eloquent models and query builders to read and modify arbitrary database records, execute arbitrary SQL, and achieve remote code execution by injecting PHP into template code sections.
Trending: The vulnerability is receiving attention across infosec communities on social media platforms including Bluesky and Mastodon, with security researchers and news outlets highlighting its high severity rating of 8.4 and the critical nature of the sandbox escape flaw affecting Winter CMS deployments.
Vulnerability: Nokogiri before 1.13.2 contains vulnerable vendored versions of libxml2 2.9.12 and libxslt 1.1.34, which expose applications to denial-of-service attacks, memory disclosure, and potential code execution when processing untrusted XML documents or XSL stylesheets. The vulnerability affects CRuby installations using packaged libraries.
Trending: CVE-2022-51000 is receiving attention across social media platforms with a CVSS 9.3 critical severity rating, with security researchers and cybersecurity accounts actively sharing alerts and details about the vulnerability.
Vulnerability: CVE-2024-34459 is a buffer over-read vulnerability in xmllint (from libxml2) before versions 2.11.8 and 2.12.7 that can be triggered when formatting error messages with the --htmlout option in the xmlHTMLPrintFileContext function.
Trending: The vulnerability is gaining attention due to its inclusion in Nokogiri versions before 1.16.5, which bundle the affected libxml2 2.12.6. While security researchers are highlighting the critical CVSS 9.3 rating of the related CVE-2024-58377, Nokogiri maintainers have noted that Nokogiri users are not impacted because the library does not expose the vulnerable xmllint functionality.
Vulnerability: Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which is affected by CVE-2024-34459 in libxml2's xmllint tool. Nokogiri 1.16.5 upgrades the bundled libxml2 to 2.12.7 to address this vulnerability, though maintainers note there is no impact to Nokogiri users since Nokogiri does not expose the xmllint tool where the issue occurs.
Trending: The vulnerability is receiving attention on social media platforms including Bluesky and Mastodon, where it is being highlighted with a CVSS 9.3 critical severity rating and shared across cybersecurity and information security communities.
Vulnerability: Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby with packaged libxml2) is affected by a use-after-free vulnerability in libxml2's xmlTextReader module. Processing a crafted XML document with DTD validation and XInclude expansion enabled can lead to an xmlValidatePopElement use-after-free.
Trending: The vulnerability is receiving attention due to its critical CVSS 9.3 severity rating and active discussion across security-focused social media platforms including Bluesky and Mastodon, with cybersecurity communities sharing details and awareness posts about the affected versions.
Vulnerability: Nokogiri before 1.18.3 contains a stack buffer overflow vulnerability in libxml2 when reporting DTD validation errors with long QName prefixes, and a use-after-free vulnerability during validation against untrusted XML Schemas. Attackers can trigger these vulnerabilities by providing malicious DTD content or untrusted XSD files to cause denial of service or potential code execution.
Trending: This vulnerability is receiving attention across social media platforms with a CVSS 9.3 critical severity rating, generating cybersecurity community awareness and information sharing about the Nokogiri library flaw.
Vulnerability: PraisonAI versions prior to 4.6.58 contain an authentication bypass vulnerability in the Browser Server's _handle_connection() function, where improper validation of Chrome extension origins using an unanchored regex pattern allows attackers to bypass origin checks and execute unauthorized browser automation commands.
Trending: The vulnerability is receiving attention across social media platforms due to its critical CVSS 9.1 severity rating and the potential for unauthorized browser automation exploitation in multi-agent AI systems.
Vulnerability: CVE-2026-55540 is a path traversal vulnerability in PraisonAI versions prior to 4.6.58 that allows arbitrary file read access. The flaw exists in the is_path_within_directory() function, which uses os.path.abspath() instead of os.path.realpath(), enabling symlinks within the workspace to point outside configured boundaries and bypass security checks for file access tools.
Trending: The vulnerability is receiving attention on social media platforms with security researchers highlighting the arbitrary file read capability via symlink path traversal and recommending immediate updates to version 4.6.58, with a CVSS score of 7.1 indicating moderate-to-high severity.