VulnScope — package-centric CVE lookup- HIGH7.1CVE-2026-48099WsgiDAV encoded dot segments can escape filesystem share roots
- HIGH8.1CVE-2026-48060Litestar has HTML Injection Through its CSRF Token
- HIGH8.3praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR
- HIGH7.3Apache Airflow: Arbitrary import in custom deadline-reference deserialization
- HIGH8.8Apache Airflow: Authenticated RCE via XCom PATCH endpoint — XComUpdateBody missing FORBIDDEN_XCOM_KEYS validator
- HIGH7.5Apache Airflow: API authorization bypass: bulk TaskInstances allows cross-DAG mutation
- HIGH8.6Docling Core: Unsafe remote filename resolution
- HIGH8.1Docling Core: Insufficient validation of image reference URIs
- HIGH7.1Docling: Unsafe URI and Path Handling in HTML Backend
- HIGH7.5Docling: Unsafe XML Entity Expansion in USPTO Patent Backend
- HIGH8.2Docling: Unsafe Playwright-based HTML Rendering
- HIGH7.5Docling: Unsafe Zip Extraction in EasyOCR Model Download
- HIGH7.5AIOHTTP is vulnerable to cross-origin redirect with per-request cookies
- HIGH8.1praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}
- HIGH8.3praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR
- HIGH8.1praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR
- HIGH8.1praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR
- HIGH8.1praisonai-platform: Missing authorization on member removal enables full workspace takeover by any user regardless of role
- HIGH7.6praisonai-platform: Label endpoints' unchecked label_id/issue_id enable cross-workspace label IDOR (edit, delete, link)
- HIGH8.1praisonai-platform: IDOR in dependency endpoints allows cross-workspace issue linking, reading, and deletion due to missing ownership checks
- HIGH8.8PraisonAI Platform: Missing role checks let any workspace member become owner and control workspace membership
- HIGH8.8PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object ID
- HIGH8.8PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API
- HIGH8.1PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334
- HIGH8.8Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows