VulnScope — 以套件為主體的 CVE 查詢工具- MEDIUM4.4CVE-2026-55650Outerbase Studio: Stored XSS in Text Widget Leads to Authentication Token Exposure
- CRITICAL9.6Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
- MEDIUM6.1Langflow: Logout button does not clear session
- CRITICAL9.9Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
- MEDIUM6.8dbt MCP Server: Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens
- MEDIUM6.5UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()
- CRITICAL9.9Network-AI: Improper Neutralization of Special Elements used in an OS Command
- CRITICAL9.1Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests
- MEDIUM5.3ts-deepmerge: Prototype Method Override leads to DoS
- MEDIUM5.8Signal K Server: Server-Side Request Forgery via Remote Connection Endpoints
- CRITICAL9.8gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)
- MEDIUM5.4OpenClaw: Empty-scope device re-pairing could confuse caller scope containment
- MEDIUM4.2OpenClaw: BlueBubbles sender policy could match mutable conversation identifiers
- MEDIUM6.5OpenClaw: memory-wiki shared search could miss session visibility checks
- MEDIUM5.5OpenClaw: Config recovery could restore openclaw.json with broad file permissions
- MEDIUM4.3OpenClaw: Skill-command dispatch could skip before-tool-call hooks
- MEDIUM6.1OpenClaw: Exported session HTML could keep unsafe markdown links
- MEDIUM5.3OpenClaw: Slack reaction events could ignore reaction notification settings
- MEDIUM4.2OpenClaw: Bootstrap token replay could widen pending pairing scopes
- MEDIUM6.5OpenClaw: Hostname checks could treat trailing-dot hosts inconsistently
- MEDIUM4.3OpenClaw: Exec allowlist could miss side effects from transparent command wrappers
- LOW2.2BBOT: Symlink-Following Arbitrary Write via github_workflows Module
- MEDIUM6.5BBOT: Arbitrary File Write in postman_download Module
- LOW3.1BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing
- MEDIUM5.3BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284