CVE-2026-92576HKUDS nanobot before 0.3.0 Server-Side Request Forgery via WebFetchTool Exploitation status Public exploit Fix YesAffected product N nanobot Published 09/16/2026 Severity Critical CVE-2026-90809HKUDS nanobot ExecTool shell.py ExecTool._spawn argument injection Exploitation status Not known exploited Fix YesAffected product N nanobot Published 09/14/2026 Severity Medium CVE-2026-90808HKUDS nanobot ExecTool shell.py ExecTool._spawn incomplete blacklist Exploitation status Public exploit Fix YesAffected product N nanobot Published 09/14/2026 Severity Medium CVE-2026-86124AutoAgent Unauthenticated Remote Code Execution via the Sandbox TCP Command Server Exploitation status Not known exploited Fix YesAffected product A AutoAgent Published 09/05/2026 Severity Critical CVE-2026-85030HKUDS AI-Trader selfRegister API Endpoint routes_agent.py logic error Exploitation status Public exploit Fix Not confirmed Affected product A AI-Trader Published 09/03/2026 Severity Medium CVE-2026-19246HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url server-side request forgery Exploitation status Public exploit Fix YesAffected product N nanobot Published 08/07/2026 Severity Medium CVE-2026-19245HKUDS nanobot Login-shell Environment shell.py ExecTool._prepare_command information disclosure Exploitation status Public exploit Fix YesAffected product N nanobot Published 08/07/2026 Severity Medium CVE-2026-19244HKUDS nanobot MCP enabledTools Scope mcp.py connect_mcp_servers access control Exploitation status Public exploit Fix YesAffected product N nanobot Published 08/07/2026 Severity Medium CVE-2026-61808LightRAG: Missing Authentication for Critical API Functions in Default Configuration Exploitation status Public exploit Fix Not confirmed Affected product L LightRAG Published 08/07/2026 Severity Critical CVE-2026-19243HKUDS nanobot Shell Allowlist shell.py ExecTool._spawn os command injection Exploitation status Public exploit Fix YesAffected product N nanobot Published 08/07/2026 Severity Medium CVE-2026-61740LightRAG: Authentication bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection Exploitation status Public exploit Fix YesAffected product L LightRAG Published 07/15/2026 Severity Critical CVE-2026-61736LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests Exploitation status Not known exploited Fix YesAffected product L LightRAG Published 07/15/2026 Severity Critical CVE-2026-58173Vibe-Trading < 0.1.10 - Path Traversal via Persistent Memory Type Exploitation status Public exploit Fix YesAffected product V Vibe-Trading Published 06/30/2026 Severity Medium CVE-2026-58171Vibe-Trading < 0.1.10 - Path Traversal via Swarm Run Identifier Exploitation status Not known exploited Fix YesAffected product V Vibe-Trading Published 06/30/2026 Severity Low CVE-2026-58170Vibe-Trading < 0.1.10 - Path Traversal in Proposal Identifier Allows Forging Live Trading Mandates Exploitation status Public exploit Fix YesAffected product V Vibe-Trading Published 06/30/2026 Severity High CVE-2026-58169Vibe-Trading < 0.1.10 - Loopback Trust and Missing Host Validation Enable DNS-Rebinding Authentication Bypass and Remote Code Execution Exploitation status Not known exploited Fix YesAffected product V Vibe-Trading Published 06/30/2026 Severity High CVE-2026-58168DeepTutor < 1.4.10 - Insecure Default Grants Unrestricted MCP Tool Access to Non-Admin Users Exploitation status Public exploit Fix YesAffected product D DeepTutor Published 06/30/2026 Severity High CVE-2026-56696OpenHarness - Prompt Injection via /issue and /pr_comments Slash Commands Exploitation status Public exploit Fix YesAffected product O OpenHarness Published 06/23/2026 Severity Medium CVE-2026-56695OpenHarness - Cross-Session Disclosure via /resume and /summary Commands Exploitation status Public exploit Fix YesAffected product O OpenHarness Published 06/23/2026 Severity High CVE-2026-48716nanobot: Path traversal via unsanitized WhatsApp document fileName enables arbitrary file write Exploitation status Public exploit Fix Not confirmed Affected product N nanobot Published 06/18/2026 Severity High CVE-2026-12203HKUDS AI-Trader Research Export agents.csv information disclosure Exploitation status Public exploit Fix YesAffected product A AI-Trader Published 06/15/2026 Severity Medium CVE-2026-49140Nanobot < 0.2.1 Denial of Service via Matrix Media Download Handler Exploitation status Public exploit Fix YesAffected product N nanobot Published 06/01/2026 Severity Medium CVE-2026-49139Nanobot < 0.2.1 SSRF via Microsoft Teams Channel serviceUrl Poisoning Exploitation status Not known exploited Fix YesAffected product N nanobot Published 06/01/2026 Severity High CVE-2026-49138Nanobot < 0.2.1 SSRF via web_fetch Tool Redirect Following Exploitation status Public exploit Fix YesAffected product N nanobot Published 06/01/2026 Severity Medium CVE-2026-32847DeepCode 1.2.0 Path Traversal via SPA Catch-All Route in main.py Exploitation status Public exploit Fix Not confirmed Affected product D DeepCode Published 05/28/2026 Severity High CVE-2026-7551HKUDS OpenHarness Remote Command Execution via /bridge Slash Command Exploitation status Not known exploited Fix YesAffected product O OpenHarness Published 04/30/2026 Severity High CVE-2026-6823HKUDS OpenHarness Insecure Default Remote Channel Allowlist Exploitation status Public exploit Fix YesAffected product O OpenHarness Published 04/21/2026 Severity High CVE-2026-6819HKUDS OpenHarness Plugin Management Command Exposure Exploitation status Not known exploited Fix YesAffected product O OpenHarness Published 04/21/2026 Severity High CVE-2026-6729HKUDS OpenHarness Session Key Collision Privilege Escalation Exploitation status Not known exploited Fix YesAffected product O OpenHarness Published 04/20/2026 Severity Medium CVE-2026-40516OpenHarness SSRF via web_fetch and web_search Exploitation status Public exploit Fix YesAffected product O OpenHarness Published 04/17/2026 Severity High CVE-2026-40515OpenHarness Permission Bypass via grep and glob root argument Exploitation status Not known exploited Fix YesAffected product O OpenHarness Published 04/17/2026 Severity High CVE-2026-40502OpenHarness Remote Administrative Command Injection via Gateway Handler Exploitation status Not known exploited Fix YesAffected product O OpenHarness Published 04/16/2026 Severity High CVE-2026-40503OpenHarness Path Traversal Information Disclosure via /memory show Exploitation status Not known exploited Fix YesAffected product O OpenHarness Published 04/16/2026 Severity High CVE-2026-35589nanobot: Cross-Site WebSocket Hijacking in WhatsApp Bridge (CVE-2026-2577 Fix Update) Exploitation status Public exploit Fix YesAffected product N nanobot Published 04/14/2026 Severity High CVE-2026-39413LightRAG has a JWT Algorithm Confusion Vulnerability in LightRAG API Exploitation status Public exploit Fix YesAffected product L LightRAG Published 04/08/2026 Severity Medium CVE-2026-22682OpenHarness Improper Access Control via File Tools Exploitation status Public exploit Fix YesAffected product O OpenHarness Published 04/07/2026 Severity High CVE-2026-33654Zero-Click Indirect Prompt Injection and Authentication Bypass via Email Polling Exploitation status Public exploit Fix Not confirmed Affected product N nanobot Published 03/27/2026 Severity High CVE-2026-2577Nanobot Unauthenticated WhatsApp Session Hijack via WebSocket Bridge Exploitation status Not known exploited Fix YesAffected product N nanobot Published 02/16/2026 Severity Critical CVE-2025-6773HKUDS LightRAG File Upload document_routes.py upload_to_input_dir path traversal Exploitation status Public exploit Fix YesAffected product L LightRAG Published 06/27/2025 Severity Medium