These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,130 reserved CVEs with public mentions, ranked by all-time mention count.
Page 44 of 46
CVE-2026-57144 is a sandbox enforcement flaw in PraisonAI SandlockSandbox in which the native sandbox can fail open when Linux Landlock support is unavailable or unusable. Instead of refusing execution when the required isolation mechanism cannot be applied, the component permits subprocess execution in a degraded state without the intended filesystem and network restrictions. As a result, code that is expected to run inside a constrained sandbox may execute with the ambient privileges of the hosting user or process, bypassing configured path restrictions and network controls.
CVE-2026-57144First seen Jul 21, 2026
CVE-2026-57146 is an authentication flaw in PraisonAI A2U affecting deployments started with the documented `praisonai serve a2u` command. An incomplete prior fix leaves A2U subscription and event-related routes unauthenticated by default unless the `A2U_AUTH_TOKEN` environment variable is explicitly configured. As a result, a reachable A2U server may permit unauthenticated access to A2U information and event-stream functionality. The issue stems from missing authentication enforcement on exposed A2U routes rather than a credential bypass after successful login.
CVE-2026-57146First seen Jul 21, 2026
CVE-2026-56837 is an authentication flaw in PraisonAI LinearBot in which webhook requests are processed without signature verification when the LINEAR_WEBHOOK_SECRET configuration is absent. In affected deployments, forged Linear webhook events can be accepted and dispatched into the agent workflow instead of being rejected. The vulnerability stems from failing open on missing webhook authentication material, allowing untrusted network input to be treated as authentic webhook traffic.
CVE-2026-56837First seen Jul 21, 2026
CVE-2026-57113 is a path traversal vulnerability in PraisonAI's handling of GitHub template cache paths. Crafted GitHub template reference components are incorporated into filesystem paths without sufficient validation or confinement to the intended cache root. As a result, attacker-controlled template owner, repository, path, or ref values can cause path resolution outside the template cache directory. The flaw allows writing cache metadata outside the cache boundary and, when a normal cache entry already exists for the same owner/repository/template prefix, can also trigger deletion of an attacker-selected directory reachable by the PraisonAI process. The vulnerability affects workflows that load attacker-supplied or otherwise untrusted GitHub template URIs.
CVE-2026-57113First seen Jul 21, 2026
CVE-2026-56832 is an authorization flaw in PraisonAI's DiscordApproval backend in which unrelated subsequent channel messages, including simple affirmative responses such as "yes," can be accepted as approval for a pending dangerous tool invocation. The approval logic does not sufficiently bind an approval response to the specific request that initiated it and does not adequately enforce that the approving message originates from an authorized approver for that request. As a result, approval of sensitive actions can be inferred from unrelated channel activity rather than from an authenticated, request-specific authorization event.
CVE-2026-56832First seen Jul 21, 2026
CVE-2026-57143 is a server-side request forgery vulnerability in the PraisonAI praisonaiagents package. The issue affects the SearxNG/search_web tooling by allowing attacker-controlled input for the searxng_url parameter, causing the application to issue server-side requests to arbitrary destinations. Because the response is returned to the agent, the flaw can be used not only to reach unintended internal resources but also to retrieve data from reachable internal HTTP-based services, including JSON APIs and cloud metadata services where accessible.
CVE-2026-57143First seen Jul 21, 2026
CVE-2026-56835 is an authorization bypass vulnerability in the PraisonAI Slack integration’s app_mention event handler. The flaw allows Slack app mention events to invoke the configured agent without enforcing the same authorization controls applied elsewhere, specifically bypassing configured allowed user restrictions, allowed channel restrictions, and unknown-user deny policy handling. As a result, prompt text supplied through an app_mention event can reach the agent even when the deployment is intended to restrict access to trusted users or channels only.
CVE-2026-56835First seen Jul 21, 2026
CVE-2026-57142 is a policy enforcement bypass in PraisonAI recipe workflows. An attacker can declare tools and corresponding approval entries in workflow YAML outside the expected TEMPLATE.yaml policy boundary, allowing a recipe to self-authorize use of tools that are intended to be denied by default. In particular, the flaw allows bypass of dangerous-tool restrictions and enables use of high-risk functionality such as shell command execution without requiring the expected dangerous-tools setting to be enabled. The issue stems from insufficient normalization and validation of the effective workflow tool graph during policy checks, causing workflow-level declarations and approvals to evade recipe-level enforcement.
CVE-2026-57142First seen Jul 21, 2026
CVE-2026-56836 is an authentication bypass in PraisonAI affecting the deprecated `recipe serve` Typer command. The vulnerable command path can bind the Recipe HTTP server to a non-localhost interface without enabling authentication, bypassing the intended safeguard that should prevent unauthenticated exposure when listening on non-local interfaces. As a result, deployments started through this deprecated handler may expose recipe API functionality remotely without access controls that operators would reasonably expect to be enforced.
CVE-2026-56836First seen Jul 21, 2026
CVE-2026-56833 is a path traversal vulnerability in PraisonAI Dynamic Context history and terminal tooling. The affected functionality uses caller-controlled identifiers such as run_id and agent_id in filesystem path construction for history and terminal read, search, and export operations. Insufficient validation and containment enforcement allows an attacker to supply absolute paths or traversal sequences that resolve outside the configured storage base directory. As a result, the vulnerable code can access reachable .jsonl and .log files beyond the intended storage scope, including files associated with conversation history and terminal activity.
CVE-2026-56833First seen Jul 21, 2026
CVE-2026-57117 is a shell command injection vulnerability in PraisonAI compute-bridged file tooling. The issue affects file operations exposed through read_file, list_files, and write_file when used by LocalManagedAgent or SandboxedAgent with an attached compute provider. Attacker-controlled path arguments are incorporated into shell command execution during compute-bridged file handling, allowing untrusted input to alter the intended command. In the case of write_file, content handling may also be unsafe if treated as shell source rather than inert data. The flaw stems from constructing shell command strings from user-influenced arguments instead of using provider-native file APIs or structured argument passing. Successful exploitation can result in arbitrary command execution in local compute environments or within Docker-backed compute containers.
CVE-2026-57117First seen Jul 21, 2026
CVE-2026-57209 is a header injection vulnerability in Heimdall when operating in proxy mode. The flaw is caused by unsanitized use of the incoming Host header while constructing the outbound Forwarded header for upstream services. By supplying a crafted Host header, an attacker can inject additional parameters into the generated Forwarded header, causing upstream applications or intermediaries to consume attacker-controlled forwarding metadata. This can undermine trust assumptions about client origin information propagated through Heimdall.
CVE-2026-57209First seen Jul 21, 2026
CVE-2026-56840 is a cross-site scripting vulnerability in the PraisonAI HTTPApproval dashboard. The dashboard renders tool arguments and related approval-page fields as raw HTML without sufficient output encoding, allowing attacker-controlled content to be interpreted as active script in a reviewer’s browser. If an attacker can influence agent task or prompt content such that malicious payloads are embedded into tool arguments or other rendered approval metadata, opening the approval page triggers script execution in the dashboard’s origin. This undermines the intended human-in-the-loop approval workflow by allowing injected JavaScript to interact with the approval interface directly.
CVE-2026-56840First seen Jul 21, 2026
CVE-2026-57114 is a server-side request forgery vulnerability in PraisonAI affecting the Jobs webhook feature. The issue arises from insufficient validation of attacker-supplied webhook_url values: destination checks can be bypassed at send time through DNS rebinding, allowing a hostname that initially appears benign to resolve to prohibited internal destinations when the outbound request is actually made. As a result, PraisonAI can be induced to send POST requests to loopback, private-network, or cloud metadata endpoints. The flaw is specifically a protection-bypass condition in SSRF defenses rather than a generic outbound request feature misuse.
CVE-2026-57114First seen Jul 21, 2026
CVE-2026-52883 is an authorization validation flaw in MantisBT affecting the SOAP mc_issue_update endpoint and a related REST API path. The vulnerability allows a user with UPDATER access to add note types that should be subject to stronger authorization controls, specifically TIME_TRACKING notes and, through SOAP, REMINDER notes. The issue stems from insufficient server-side authorization validation when processing issue update requests, enabling an authenticated user to submit note data that is accepted as privileged note content despite lacking the intended permissions for that note type.
CVE-2026-52883First seen Jul 16, 2026
CVE-2026-47142 is a SQL injection vulnerability in MantisBT affecting core/history_api.php. The flaw arises from insufficient neutralization of attacker-controlled SQL syntax in the history_order configuration value, which is incorporated into an ORDER BY clause. An administrator can set a crafted value that is later processed when users view issues containing history entries, causing the application to execute unintended SQL against the bug tracker database.
CVE-2026-47142First seen Jul 16, 2026
CVE-2026-62944 is a stored cross-site scripting vulnerability in MantisBT affecting the HTML export functionality implemented in print_all_bug_page_word.php. The flaw is caused by missing output encoding of attacker-controlled image attachment filenames before they are inserted into an IMG alt attribute. By supplying a crafted attachment filename, an authenticated user can persist malicious HTML or script-bearing content that is later rendered when another user accesses the affected export page. The vulnerability arises from improper neutralization of input during web page generation, enabling stored client-side code injection in a privileged application context.
CVE-2026-62944First seen Jul 16, 2026
CVE-2026-52882 is an authorization flaw in MantisBT affecting REST and SOAP API issue update handling. The vulnerability allows users whose privileges are below the configured report_issues_for_unreleased_versions_threshold to assign unreleased product versions when updating issues through the API. The issue stems from improper authorization or validation in the API path, enabling behavior that should be restricted by the product's version-release permission model.
CVE-2026-52882First seen Jul 16, 2026
CVE-2026-49280 is an authorization flaw in MantisBT affecting issue status changes performed through the REST and SOAP APIs. A user who has permission to update an issue can modify that issue's status through these API interfaces even when the configured status-change threshold is intended to restrict such transitions to users with higher privileges. The vulnerability results from improper enforcement of authorization checks on API-driven workflow changes, allowing the API path to bypass the configured privilege threshold for status transitions.
CVE-2026-49280First seen Jul 16, 2026
CVE-2026-45693 is an unauthenticated path traversal vulnerability in FacturaScripts static file controllers. The flaw allows attacker-supplied path traversal sequences to influence file resolution for requests to static asset routes, causing the application to serve files outside the intended public asset locations. The vulnerable logic appears to rely on raw URL prefix or route-based checks rather than canonicalized filesystem path validation. As a result, a crafted request can traverse into other allow-listed locations within the FacturaScripts installation directory and expose non-public files. The issue is mitigated only partially by file-type restrictions, as executable PHP files are reportedly not included in the allow-list, but sensitive business documents and stored data remain exposed.
CVE-2026-45693First seen Jul 15, 2026
CVE-2026-45263 is a CSV formula injection vulnerability in the FacturaScripts CSVExport functionality. The flaw allows an authenticated low-privileged user to place spreadsheet formula payloads into application data that is later exported to CSV. When the exported file is opened in a spreadsheet application, cells beginning with formula-interpreted characters can be evaluated as active formulas rather than inert text. This indicates insufficient neutralization of formula-leading characters during CSV generation, enabling attacker-controlled content in exported fields, and potentially in headers or other spreadsheet-loadable export outputs, to trigger client-side execution or data access in the context of the user opening the file.
CVE-2026-45263First seen Jul 15, 2026
CVE-2026-55372 is a pre-authentication server-side request forgery vulnerability in NukeViet. The issue arises from insufficient validation of client-supplied forwarded headers, specifically X-Forwarded-Host and X-Forwarded-Proto, which are consumed by server_info_update() when constructing an outbound cURL request. Because these values are not properly normalized and constrained before use, an unauthenticated attacker can influence the destination of a server-initiated request. The vulnerable behavior permits blind SSRF against attacker-selected internal or external targets. Available details indicate the request behavior is constrained by a fixed request path, use of the HEAD method, and absence of reflected response content, which limits exploitability beyond network reachability and limited side effects such as cached header poisoning.
CVE-2026-55372First seen Jul 14, 2026
CVE-2026-48118 is an unauthenticated reflected cross-site scripting vulnerability in the NukeViet Comment module. The issue is exposed through the status_comment parameter, whose decoded content can be reflected into the rendered page without sufficient output encoding. The vulnerability is compounded by an anti-forgery mechanism that derives the comment checkss token from a session-independent value rather than a per-user session value, allowing crafted links to be generated in a way that can be delivered across users. As a result, an attacker can cause arbitrary HTML or JavaScript to execute in a victim’s browser within the security context of the affected NukeViet site.
CVE-2026-48118First seen Jul 14, 2026
CVE-2026-54064 is a stored cross-site scripting vulnerability in NukeViet affecting the News module. The issue stems from multiple anti-XSS filter bypasses involving weaknesses in the Request::filterAttr() and Request::unhtmlentities() routines. These weaknesses allow crafted input to evade attribute and javascript: scheme filtering, including through handling flaws involving ASCII control characters and HTML entity decoding. An authenticated low-privileged user with permission to post news content can inject malicious script into stored content, which is then rendered and executed in the browsers of users who view the affected pages, including administrative users.
CVE-2026-54064First seen Jul 14, 2026
CVE-2026-54065 is a path traversal vulnerability in the NukeViet Edit Comment administrative function. The flaw arises from insufficient validation of the attach parameter, allowing a crafted path to traverse directories and reference files outside the intended uploads location but still within the application root. An authenticated administrator can abuse this behavior to delete arbitrary files accessible through the vulnerable code path. Deletion of critical application files can break core functionality and render the installation unusable.
CVE-2026-54065First seen Jul 14, 2026