CVEs we hold for Hkuds
Records whose assigning authority named Hkuds as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-86124AutoAgent Unauthenticated Remote Code Execution via the Sandbox TCP Command ServerHKUDS AutoAgent
CVE-2026-61808LightRAG: Missing Authentication for Critical API Functions in Default ConfigurationHKUDS LightRAG
CVE-2026-61740LightRAG: Authentication bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY…HKUDS LightRAG
CVE-2026-61736LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed RequestsHKUDS LightRAG
CVE-2026-58170Vibe-Trading < 0.1.10 - Path Traversal in Proposal Identifier Allows Forging Live Trading MandatesHKUDS Vibe-Trading
CVE-2026-58169Vibe-Trading < 0.1.10 - Loopback Trust and Missing Host Validation Enable DNS-Rebinding Authentication Bypass and…HKUDS Vibe-Trading
CVE-2026-58168DeepTutor < 1.4.10 - Insecure Default Grants Unrestricted MCP Tool Access to Non-Admin UsersHKUDS DeepTutor
CVE-2026-56696OpenHarness - Prompt Injection via /issue and /pr_comments Slash CommandsHKUDS OpenHarness
CVE-2026-56695OpenHarness - Cross-Session Disclosure via /resume and /summary CommandsHKUDS OpenHarness
CVE-2026-48716nanobot: Path traversal via unsanitized WhatsApp document fileName enables arbitrary file writeHKUDS nanobot
CVE-2026-40502OpenHarness Remote Administrative Command Injection via Gateway HandlerHKUDS OpenHarness
CVE-2026-35589nanobot: Cross-Site WebSocket Hijacking in WhatsApp Bridge (CVE-2026-2577 Fix Update)HKUDS nanobot
CVE-2026-33654Zero-Click Indirect Prompt Injection and Authentication Bypass via Email PollingHKUDS nanobot
CVE-2026-19246HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url server-side request forgeryHKUDS nanobot
CVE-2026-19245HKUDS nanobot Login-shell Environment shell.py ExecTool._prepare_command information disclosureHKUDS nanobot
CVE-2026-19244HKUDS nanobot MCP enabledTools Scope mcp.py connect_mcp_servers access controlHKUDS nanobot
CVE-2026-19243HKUDS nanobot Shell Allowlist shell.py ExecTool._spawn os command injectionHKUDS nanobot
CVE-2025-6773HKUDS LightRAG File Upload document_routes.py upload_to_input_dir path traversalHKUDS LightRAG
39 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.