VulnScope — package-centric CVE lookup- LOW3.7CVE-2026-49854Tornado has out-of-bounds memory access via C extension
- HIGH7.1CVE-2026-48099WsgiDAV encoded dot segments can escape filesystem share roots
- HIGH8.1Litestar has HTML Injection Through its CSRF Token
- LOW3.1Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known
- LOW3.1Bugsink: Issue event views can show an event from another project if its UUID is known
- HIGH8.3praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR
- HIGH7.3Apache Airflow: Arbitrary import in custom deadline-reference deserialization
- HIGH8.8Apache Airflow: Authenticated RCE via XCom PATCH endpoint — XComUpdateBody missing FORBIDDEN_XCOM_KEYS validator
- HIGH7.5Apache Airflow: API authorization bypass: bulk TaskInstances allows cross-DAG mutation
- HIGH8.6Docling Core: Unsafe remote filename resolution
- HIGH8.1Docling Core: Insufficient validation of image reference URIs
- HIGH7.1Docling: Unsafe URI and Path Handling in HTML Backend
- HIGH7.5Docling: Unsafe XML Entity Expansion in USPTO Patent Backend
- HIGH8.2Docling: Unsafe Playwright-based HTML Rendering
- HIGH7.5Docling: Unsafe Zip Extraction in EasyOCR Model Download
- HIGH7.5AIOHTTP is vulnerable to cross-origin redirect with per-request cookies
- HIGH8.1praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}
- HIGH8.3praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR
- HIGH8.1praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR
- HIGH8.1praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR
- LOW3.1EPSS 0.04%Apache Airflow: Log server JWT authorization bypass via Python lstrip() character stripping allows cross-Dag log access
- HIGH8.1praisonai-platform: Missing authorization on member removal enables full workspace takeover by any user regardless of role
- HIGH7.6praisonai-platform: Label endpoints' unchecked label_id/issue_id enable cross-workspace label IDOR (edit, delete, link)
- HIGH8.1praisonai-platform: IDOR in dependency endpoints allows cross-workspace issue linking, reading, and deletion due to missing ownership checks
- HIGH8.8PraisonAI Platform: Missing role checks let any workspace member become owner and control workspace membership