cves

Published vulnerabilities from my security research.

Additional findings are moving through coordinated disclosure.

published
34
projects
11
critical
14

Payload CMS10

Headless content management system

  1. Remote code execution in Payload Form Builder

    critical10.0

    A crafted form submission could execute arbitrary code on a server using the Payload Form Builder plugin.

    CVSS 3.1 · 10.0 CVE ID not assigned
  2. Unauthorized update to collection documents

    critical9.8

    The reorder endpoint could update arbitrary collection fields without enforcing collection or field-level access controls.

    CVSS 3.1 · 9.8 CVE ID not assigned
  3. Reserved-claim collision in authentication tokens

    critical9.2

    A custom field mapped to a reserved authentication claim could inject unintended values into the token issued at login.

    CVSS 4.0 · 9.2 CVE ID not assigned
  4. Field access-control bypass through document duplication

    critical9.3

    The duplicate operation could copy protected fields from an auth-collection document despite hidden, read, create, or duplication controls.

    CVSS 4.0 · 9.3 CVE ID not assigned
  5. Remote code execution through first registration

    high8.1

    The initial account-registration flow could allow remote code execution on affected Payload CMS deployments.

    CVSS 3.1 · 8.1 CVE ID not assigned
  6. Stored cross-site scripting through XML uploads

    high8.6

    Uploaded XML files could execute JavaScript in the application's origin when opened, exposing users to stored cross-site scripting.

    CVSS 4.0 · 8.6 CVE ID not assigned
  7. Sanitization bypass for uploaded SVG files

    high8.7

    An SVG upload could bypass sanitization and execute JavaScript when the stored file was opened.

    CVSS 3.1 · 8.7 CVE ID not assigned
  8. API-key disclosure through document reads

    high7.7

    Ordinary document reads could expose API keys that should remain restricted.

    CVSS 4.0 · 7.7 CVE ID not assigned
  9. Restricted-field disclosure during token refresh

    high7.1

    Token-refresh and password-reset responses could expose protected user fields despite field-level read restrictions.

    CVSS 4.0 · 7.1 CVE ID not assigned
  10. Arbitrary file deletion through upload metadata

    high8.1

    Insufficient validation of upload metadata could allow file cleanup to remove files outside the upload directory.

    CVSS 3.1 · 8.1 CVE ID not assigned

Mistral Vibe06

AI coding agent

  1. Arbitrary file read through quoted absolute paths

    critical9.2

    Quoted absolute paths in allowlisted shell commands could bypass workspace restrictions and read files outside the active workspace without approval.

    CVSS 4.0 · 9.2 CVE record
  2. Arbitrary file write through shell redirection

    critical9.3

    Shell redirection destinations were omitted from permission checks, allowing files outside the active workspace to be created or overwritten without approval.

    CVSS 4.0 · 9.3 CVE record
  3. Arbitrary code execution through ANSI-C quoting

    critical10.0

    ANSI-C quoted arguments were not properly inspected, allowing a crafted allowlisted command to bypass permission checks and execute arbitrary code without approval.

    CVSS 4.0 · 10.0 CVE record
  4. Arbitrary code execution through unparsed shell constructs

    critical10.0

    Shell constructs the parser could not interpret were omitted from permission checks, allowing embedded commands to execute without approval.

    CVSS 4.0 · 10.0 CVE record
  5. Arbitrary code execution through environment assignments

    critical10.0

    Environment variable assignments preceding allowlisted commands were excluded from inspection, enabling arbitrary code execution without approval.

    CVSS 4.0 · 10.0 CVE record
  6. Arbitrary file access through unconditionally allowed commands

    critical10.0

    Commands classified as unconditionally allowed lacked path validation, enabling access to files outside the active workspace without approval.

    CVSS 4.0 · 10.0 CVE record

MLflow01

Machine-learning lifecycle platform

  1. Arbitrary code execution through malicious model artifacts

    high8.6

    Loading a maliciously crafted model artifact could execute arbitrary code on an end user's system.

    CVSS 4.0 · 8.6 CVE record

Netron03

Neural-network model viewer

  1. DOM XSS through an unsanitized node name

    medium6.8

    A crafted model could inject HTML through a node name when its sidebar was opened, enabling local-network requests or a browser exploit chain in the desktop app.

    CVSS 4.0 · 6.8 CVE record
  2. DOM XSS through an unsanitized input description

    medium6.8

    A crafted model could inject HTML through an input description when its sidebar was opened, enabling local-network requests or a browser exploit chain in the desktop app.

    CVSS 4.0 · 6.8 CVE record
  3. DOM XSS through an unsanitized output description

    medium6.8

    A crafted model could inject HTML through an output description when its sidebar was opened, enabling local-network requests or a browser exploit chain in the desktop app.

    CVSS 4.0 · 6.8 CVE record

Style Dictionary01

Design-token build system

  1. Prototype Pollution via constructor.prototype Bypasses CVE-2026-54639 Patch

    high8.4

    An attacker could exploit maliciously crafted token data to pollute object prototypes, potentially altering application behavior or data.

    CVSS 3.1 · 8.4 ID pending

Anubis01

Web AI firewall

  1. Policy bypass via a client-controlled X-Original-URI header

    medium5.8

    A client-controlled header was trusted before the request path, allowing matching ALLOW rules to bypass the Anubis challenge.

    CVSS 3.1 · 5.8 CVE record

ChromaDB06

AI-native database

  1. Authenticated remote code execution

    critical9.4

    A user with collection-update permission could load a malicious model repository with trust_remote_code and execute code on the server.

    CVSS 4.0 · 9.4
  2. Cross-tenant authorization bypass in ChromaDB Rust

    high8.8

    Any authenticated user could read, write, update, or delete collections belonging to another tenant.

    CVSS 4.0 · 8.8
  3. Cross-tenant authorization bypass in ChromaDB Python

    high8.8

    Any authenticated user could read, write, update, or delete collections belonging to another tenant.

    CVSS 4.0 · 8.8
  4. SimpleRBAC cross-tenant authorization bypass

    high8.8

    The provider checked whether a user held a permission, but not which tenant, database, or collection that permission applied to.

    CVSS 4.0 · 8.8
  5. Authorization bypass through V1 collection endpoints

    high8.8

    The V1 endpoints passed no tenant or database to the authorization layer, allowing its controls to be bypassed.

    CVSS 4.0 · 8.8
  6. Pre-authentication remote code execution

    critical10.0

    An unauthenticated attacker could submit a malicious model repository with trust_remote_code enabled and execute code on the server.

    CVSS 4.0 · 10.0

Flair01

NLP framework

  1. Arbitrary code execution through model deserialization

    high8.4

    Loading a malicious language model could trigger unsafe deserialization and execute arbitrary code.

    CVSS 3.1 · 8.4

MISP01

Threat intelligence platform

  1. Path traversal in the EventReport image viewer

    medium4.1

    A site administrator could traverse outside the intended path when viewing an EventReport picture.

    CVSS 3.1 · 4.1

Keras01

Deep-learning framework

  1. Safe-mode bypass through TorchModuleWrapper

    critical9.8

    A malicious Keras file could execute arbitrary code when loaded, despite safe mode being enabled.

    CVSS 3.1 · 9.8

Backend.AI03

AI compute platform

  1. Missing authorization for interactive sessions

    high8.1

    An attacker could take over active sessions and access, steal, or alter data available inside them.

    CVSS 3.1 · 8.1
  2. Arbitrary account creation through missing access control

    critical9.8

    Unauthenticated users could create accounts and reach private data even when registration was disabled.

    CVSS 3.1 · 9.8
  3. Credential exposure leading to account takeover

    high8.0

    Sensitive data exposed through active sessions could reveal management-platform credentials.

    CVSS 3.1 · 8.0

duplicate findings

Independently discovered vulnerabilities where another report arrived first.

Redis 01

In-memory data store

Scores shown are published base scores from the linked vulnerability records.