vciy

CVEs we hold for Hkuds

Records whose assigning authority named Hkuds as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-92576HKUDS nanobot before 0.3.0 Server-Side Request Forgery via WebFetchToolHKUDS nanobot
CVE-2026-90809HKUDS nanobot ExecTool shell.py ExecTool._spawn argument injectionHKUDS nanobot
CVE-2026-90808HKUDS nanobot ExecTool shell.py ExecTool._spawn incomplete blacklistHKUDS nanobot
CVE-2026-86124AutoAgent Unauthenticated Remote Code Execution via the Sandbox TCP Command ServerHKUDS AutoAgent
CVE-2026-85030HKUDS AI-Trader selfRegister API Endpoint routes_agent.py logic errorHKUDS AI-Trader
CVE-2026-7551HKUDS OpenHarness Remote Command Execution via /bridge Slash CommandHKUDS OpenHarness
CVE-2026-6823HKUDS OpenHarness Insecure Default Remote Channel AllowlistHKUDS OpenHarness
CVE-2026-6819HKUDS OpenHarness Plugin Management Command ExposureHKUDS OpenHarness
CVE-2026-6729HKUDS OpenHarness Session Key Collision Privilege EscalationHKUDS OpenHarness
CVE-2026-61808LightRAG: Missing Authentication for Critical API Functions in Default ConfigurationHKUDS LightRAG
CVE-2026-61740LightRAG: Authentication bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY…HKUDS LightRAG
CVE-2026-61736LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed RequestsHKUDS LightRAG
CVE-2026-58173Vibe-Trading < 0.1.10 - Path Traversal via Persistent Memory TypeHKUDS Vibe-Trading
CVE-2026-58171Vibe-Trading < 0.1.10 - Path Traversal via Swarm Run IdentifierHKUDS Vibe-Trading
CVE-2026-58170Vibe-Trading < 0.1.10 - Path Traversal in Proposal Identifier Allows Forging Live Trading MandatesHKUDS Vibe-Trading
CVE-2026-58169Vibe-Trading < 0.1.10 - Loopback Trust and Missing Host Validation Enable DNS-Rebinding Authentication Bypass and…HKUDS Vibe-Trading
CVE-2026-58168DeepTutor < 1.4.10 - Insecure Default Grants Unrestricted MCP Tool Access to Non-Admin UsersHKUDS DeepTutor
CVE-2026-56696OpenHarness - Prompt Injection via /issue and /pr_comments Slash CommandsHKUDS OpenHarness
CVE-2026-56695OpenHarness - Cross-Session Disclosure via /resume and /summary CommandsHKUDS OpenHarness
CVE-2026-49140Nanobot < 0.2.1 Denial of Service via Matrix Media Download HandlerHKUDS nanobot
CVE-2026-49139Nanobot < 0.2.1 SSRF via Microsoft Teams Channel serviceUrl PoisoningHKUDS nanobot
CVE-2026-49138Nanobot < 0.2.1 SSRF via web_fetch Tool Redirect FollowingHKUDS nanobot
CVE-2026-48716nanobot: Path traversal via unsanitized WhatsApp document fileName enables arbitrary file writeHKUDS nanobot
CVE-2026-40516OpenHarness SSRF via web_fetch and web_searchHKUDS OpenHarness
CVE-2026-40515OpenHarness Permission Bypass via grep and glob root argumentHKUDS OpenHarness
CVE-2026-40503OpenHarness Path Traversal Information Disclosure via /memory showHKUDS OpenHarness
CVE-2026-40502OpenHarness Remote Administrative Command Injection via Gateway HandlerHKUDS OpenHarness
CVE-2026-39413LightRAG has a JWT Algorithm Confusion Vulnerability in LightRAG APIHKUDS LightRAG
CVE-2026-35589nanobot: Cross-Site WebSocket Hijacking in WhatsApp Bridge (CVE-2026-2577 Fix Update)HKUDS nanobot
CVE-2026-33654Zero-Click Indirect Prompt Injection and Authentication Bypass via Email PollingHKUDS nanobot
CVE-2026-32847DeepCode 1.2.0 Path Traversal via SPA Catch-All Route in main.pyHKUDS DeepCode
CVE-2026-2577Nanobot Unauthenticated WhatsApp Session Hijack via WebSocket BridgeHKUDS nanobot
CVE-2026-22682OpenHarness Improper Access Control via File ToolsHKUDS OpenHarness
CVE-2026-19246HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url server-side request forgeryHKUDS nanobot
CVE-2026-19245HKUDS nanobot Login-shell Environment shell.py ExecTool._prepare_command information disclosureHKUDS nanobot
CVE-2026-19244HKUDS nanobot MCP enabledTools Scope mcp.py connect_mcp_servers access controlHKUDS nanobot
CVE-2026-19243HKUDS nanobot Shell Allowlist shell.py ExecTool._spawn os command injectionHKUDS nanobot
CVE-2026-12203HKUDS AI-Trader Research Export agents.csv information disclosureHKUDS AI-Trader
CVE-2025-6773HKUDS LightRAG File Upload document_routes.py upload_to_input_dir path traversalHKUDS LightRAG

39 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.