<!doctype html><html lang="en"><head><meta charset="utf-8">
<meta name="viewport" content="width=device-width,initial-scale=1">
<title>Vuln Signal Radar | CVE, KEV &amp; EPSS Signals for Defenders</title><meta name="description" content="Track public-safe CVE, KEV, EPSS, and vendor-advisory signals for defender triage with source, freshness, and safety context."><meta name="robots" content="index,follow"><link rel="canonical" href="https://vuln.signal-radar.com/"><meta property="og:type" content="website"><meta property="og:site_name" content="Signal-Radar.com"><meta property="og:title" content="Vuln Signal Radar | CVE, KEV &amp; EPSS Signals for Defenders"><meta property="og:description" content="Track public-safe CVE, KEV, EPSS, and vendor-advisory signals for defender triage with source, freshness, and safety context."><meta property="og:url" content="https://vuln.signal-radar.com/"><meta property="og:image" content="https://vuln.signal-radar.com/assets/vuln/hero-vulnerability-intelligence.webp"><meta name="twitter:card" content="summary_large_image"><meta name="twitter:title" content="Vuln Signal Radar | CVE, KEV &amp; EPSS Signals for Defenders"><meta name="twitter:description" content="Track public-safe CVE, KEV, EPSS, and vendor-advisory signals for defender triage with source, freshness, and safety context."><meta name="twitter:image" content="https://vuln.signal-radar.com/assets/vuln/hero-vulnerability-intelligence.webp"><link rel="icon" href="/assets/vuln/favicon.webp" type="image/webp"><link rel="icon" href="/assets/vuln/favicon-32.png" type="image/png" sizes="32x32"><link rel="apple-touch-icon" href="/assets/vuln/apple-touch-icon.png"><link rel="agent" href="/agent.json" type="application/json"><link rel="alternate" type="application/ld+json" href="/data/v1/graph/latest.jsonld"><link rel="stylesheet" href="/assets/vuln/dashboard.css?v=20260718-vuln-treemap-1"><link rel="stylesheet" href="/assets/preview.css?v=20260718-vuln-treemap-1"><link rel="stylesheet" href="/assets/vuln/vuln-treemap.css?v=20260718-vuln-treemap-1"></head><body>
<a class="skip-link" href="#signals" data-skip-live-feed>Live feedへ移動</a>
<div class="app-shell public-dashboard" data-public-dashboard="true">
<header class="vsr-topnav">
<a class="console-roll-link brand" href="#dashboard" data-console-roll-link data-view-link="dashboard"><span class="console-roll-link__wash" aria-hidden="true"></span><span class="console-roll-link__bracket console-roll-link__bracket--left" aria-hidden="true">[</span><span class="console-roll-link__clip"><span class="console-roll-link__label" data-scramble-text>Vuln Signal Radar</span></span><span class="console-roll-link__bracket console-roll-link__bracket--right" aria-hidden="true">]</span></a>
<nav class="top-tabs" aria-label="Primary"><a class="console-roll-link active" href="#dashboard" data-console-roll-link data-view-link="dashboard" aria-current="page"><span class="console-roll-link__wash" aria-hidden="true"></span><span class="console-roll-link__bracket console-roll-link__bracket--left" aria-hidden="true">[</span><span class="console-roll-link__clip"><span class="console-roll-link__label" data-scramble-text>Dashboard</span></span><span class="console-roll-link__bracket console-roll-link__bracket--right" aria-hidden="true">]</span></a><a class="console-roll-link" href="#signals" data-console-roll-link data-view-link="signals"><span class="console-roll-link__wash" aria-hidden="true"></span><span class="console-roll-link__bracket console-roll-link__bracket--left" aria-hidden="true">[</span><span class="console-roll-link__clip"><span class="console-roll-link__label" data-scramble-text>Signals</span></span><span class="console-roll-link__bracket console-roll-link__bracket--right" aria-hidden="true">]</span></a><a class="console-roll-link" href="#sources" data-console-roll-link data-view-link="sources"><span class="console-roll-link__wash" aria-hidden="true"></span><span class="console-roll-link__bracket console-roll-link__bracket--left" aria-hidden="true">[</span><span class="console-roll-link__clip"><span class="console-roll-link__label" data-scramble-text>Sources</span></span><span class="console-roll-link__bracket console-roll-link__bracket--right" aria-hidden="true">]</span></a><a class="console-roll-link" href="#watchlist" data-console-roll-link data-view-link="watchlist"><span class="console-roll-link__wash" aria-hidden="true"></span><span class="console-roll-link__bracket console-roll-link__bracket--left" aria-hidden="true">[</span><span class="console-roll-link__clip"><span class="console-roll-link__label" data-scramble-text>Watchlist</span></span><span class="console-roll-link__bracket console-roll-link__bracket--right" aria-hidden="true">]</span></a><a class="console-roll-link" href="#reports" data-console-roll-link data-view-link="reports"><span class="console-roll-link__wash" aria-hidden="true"></span><span class="console-roll-link__bracket console-roll-link__bracket--left" aria-hidden="true">[</span><span class="console-roll-link__clip"><span class="console-roll-link__label" data-scramble-text>Reports</span></span><span class="console-roll-link__bracket console-roll-link__bracket--right" aria-hidden="true">]</span></a><a class="console-roll-link" href="/about/" data-console-roll-link><span class="console-roll-link__wash" aria-hidden="true"></span><span class="console-roll-link__bracket console-roll-link__bracket--left" aria-hidden="true">[</span><span class="console-roll-link__clip"><span class="console-roll-link__label" data-scramble-text>About</span></span><span class="console-roll-link__bracket console-roll-link__bracket--right" aria-hidden="true">]</span></a></nav>
<section class="vsr-radar-pulse" data-vsr-radar-pulse data-status="fresh" data-mode="snapshot" data-source-state="healthy" aria-label="Defensive Priority Capsule. Snapshot freshness: FRESH. Defensive priority 98 out of 100. Deterministic snapshot ranking, not a probability of exploitation or compromise. Driver: Critical CVSS severity, 4 items. Source health: 3 of 3 sources available; state healthy. Triage Intercept is a 15-second defensive prioritization simulation. PERFECT describes game performance only, not vulnerability remediation status."><button type="button" class="vsr-pulse-freshness" data-view-link="dashboard" data-vsr-pulse-freshness title="Snapshot freshness: FRESH. Open Dashboard view."><i aria-hidden="true"></i><span>FRESH</span></button><button type="button" class="vsr-pulse-priority" data-view-link="signals" data-vsr-pulse-priority aria-label="Defensive priority 98 out of 100. Deterministic snapshot ranking, not a probability of exploitation or compromise. Open Signals view." title="Defensive priority 98 out of 100. Deterministic snapshot ranking, not a probability of exploitation or compromise. Open Signals view."><small class="vsr-pulse-priority-label"><span class="vsr-pulse-priority-label-full">PRIORITY</span><span class="vsr-pulse-priority-label-short" aria-hidden="true">PRI</span></small><strong>98</strong></button><span class="vsr-pulse-driver" data-vsr-pulse-driver title="CRIT 4">CRIT 4</span><div class="vsr-pulse-tracks" data-vsr-pulse-tracks aria-hidden="true"><span class="vsr-pulse-axis"><b>OBSERVED</b><b>REVIEW</b></span><i class="vsr-pulse-node lane-critical shape-diamond urgency-3 confidence-medium delay-2 speed-4"></i><i class="vsr-pulse-node lane-critical shape-diamond urgency-3 confidence-medium delay-1 speed-5"></i><i class="vsr-pulse-node lane-critical shape-diamond urgency-3 confidence-medium delay-5 speed-3"></i><i class="vsr-pulse-node lane-critical shape-diamond urgency-2 confidence-medium delay-1 speed-4"></i><i class="vsr-pulse-node lane-elevated shape-hexagon urgency-2 confidence-medium delay-1 speed-5"></i><i class="vsr-pulse-node lane-elevated shape-hexagon urgency-2 confidence-high delay-4 speed-1 has-remediation"></i></div><button type="button" class="vsr-pulse-sources" data-view-link="sources" data-vsr-pulse-sources aria-label="Source health: 3 of 3 available; healthy. Open Sources view." title="Source health: 3 of 3 available; healthy. Open Sources view.">3/3</button><button type="button" class="vsr-pulse-game-trigger" data-vsr-pulse-game-trigger aria-label="Start 15-second Triage Intercept simulation. PERFECT describes game performance only, not vulnerability remediation status." title="Start 15-second Triage Intercept simulation. PERFECT describes game performance only, not vulnerability remediation status." aria-pressed="false"><span aria-hidden="true">◇</span></button><div class="vsr-triage-shell" data-vsr-triage-shell hidden><div class="vsr-triage-meta"><strong data-vsr-triage-state>TRIAGE</strong><small aria-hidden="true">SIM</small><span data-vsr-triage-time>15.0s</span></div><div class="vsr-triage-stage" data-vsr-triage-stage tabindex="-1" aria-label="Triage Intercept simulation area"></div><div class="vsr-triage-scoreboard"><span class="sr-only" data-vsr-triage-score-label>SCORE</span><b data-vsr-triage-score>0000</b><span data-vsr-triage-combo>x1</span></div></div><template data-vsr-triage-sequence><button type="button" class="vsr-triage-object kind-target lane-3 shape-hexagon delay-5 speed-1" data-vsr-triage-object data-kind="target" data-order="0" tabindex="-1" aria-label="Defensive review target"><span class="sr-only">Defensive review target</span></button><button type="button" class="vsr-triage-object kind-noise lane-2 shape-square delay-2 speed-4" data-vsr-triage-object data-kind="noise" data-order="1" tabindex="-1" aria-label="Simulation noise"><span class="sr-only">Simulation noise</span></button><button type="button" class="vsr-triage-object kind-noise lane-3 shape-hollow_circle delay-4 speed-3" data-vsr-triage-object data-kind="noise" data-order="2" tabindex="-1" aria-label="Simulation noise"><span class="sr-only">Simulation noise</span></button><button type="button" class="vsr-triage-object kind-target lane-1 shape-diamond delay-5 speed-5" data-vsr-triage-object data-kind="target" data-order="3" tabindex="-1" aria-label="Defensive review target"><span class="sr-only">Defensive review target</span></button><button type="button" class="vsr-triage-object kind-noise lane-3 shape-circle delay-3 speed-1" data-vsr-triage-object data-kind="noise" data-order="4" tabindex="-1" aria-label="Simulation noise"><span class="sr-only">Simulation noise</span></button><button type="button" class="vsr-triage-object kind-target lane-2 shape-hexagon delay-2 speed-5" data-vsr-triage-object data-kind="target" data-order="5" tabindex="-1" aria-label="Defensive review target"><span class="sr-only">Defensive review target</span></button><button type="button" class="vsr-triage-object kind-target lane-1 shape-diamond delay-1 speed-4" data-vsr-triage-object data-kind="target" data-order="6" tabindex="-1" aria-label="Defensive review target"><span class="sr-only">Defensive review target</span></button><button type="button" class="vsr-triage-object kind-target lane-1 shape-hexagon delay-5 speed-5" data-vsr-triage-object data-kind="target" data-order="7" tabindex="-1" aria-label="Defensive review target"><span class="sr-only">Defensive review target</span></button><button type="button" class="vsr-triage-object kind-noise lane-1 shape-square delay-4 speed-1" data-vsr-triage-object data-kind="noise" data-order="8" tabindex="-1" aria-label="Simulation noise"><span class="sr-only">Simulation noise</span></button><button type="button" class="vsr-triage-object kind-target lane-1 shape-diamond delay-4 speed-3" data-vsr-triage-object data-kind="target" data-order="9" tabindex="-1" aria-label="Defensive review target"><span class="sr-only">Defensive review target</span></button><button type="button" class="vsr-triage-object kind-noise lane-1 shape-square delay-1 speed-5" data-vsr-triage-object data-kind="noise" data-order="10" tabindex="-1" aria-label="Simulation noise"><span class="sr-only">Simulation noise</span></button><button type="button" class="vsr-triage-object kind-target lane-3 shape-diamond delay-5 speed-5" data-vsr-triage-object data-kind="target" data-order="11" tabindex="-1" aria-label="Defensive review target"><span class="sr-only">Defensive review target</span></button><button type="button" class="vsr-triage-object kind-target lane-2 shape-diamond delay-4 speed-1" data-vsr-triage-object data-kind="target" data-order="12" tabindex="-1" aria-label="Defensive review target"><span class="sr-only">Defensive review target</span></button><button type="button" class="vsr-triage-object kind-target lane-1 shape-diamond delay-1 speed-1" data-vsr-triage-object data-kind="target" data-order="13" tabindex="-1" aria-label="Defensive review target"><span class="sr-only">Defensive review target</span></button></template><span class="sr-only" aria-live="polite" aria-atomic="true" data-vsr-pulse-announcer></span></section>
</header>
<div class="dashboard-shell">
<aside class="vsr-sidebar">
<nav class="side-nav" aria-label="Dashboard sections"><a class="active" href="#dashboard" data-view-link="dashboard">▦ Overview</a><a href="#signals" data-view-link="signals">⌁ Live Feed <span id="side-feed-count">20</span></a><a href="#dashboard" data-view-link="dashboard" data-filter-shortcut="risk">♢ Risk Explorer</a><a href="#reports" data-view-link="reports">⌬ Defensive Paths</a><a href="#signals" data-view-link="signals" data-filter-shortcut="kev">⬡ KEV Tracker</a><a href="#dashboard" data-view-link="dashboard" data-filter-shortcut="epss">✣ EPSS Heatmap</a><a href="#sources" data-view-link="sources">⚭ Integrations</a><a href="#saved" data-view-link="saved">▱ Saved Views</a></nav>
<div class="side-meta" aria-label="Operational status">
<section class="side-card freshness"><h2>Data Freshness</h2><p><span class="live-dot"></span>Read-only public-safe data</p><div class="fresh-row generated-row"><span>Generated</span><div id="last-updated" class="compact-timestamp" title="Last generated 2026-08-12 19:39 JST / 2026-08-12 10:39 UTC" aria-label="Last generated 2026-08-12 19:39 JST / 2026-08-12 10:39 UTC"><strong>19:39 JST</strong><span>2026-08-12</span><small>UTC 10:39</small></div></div><div class="fresh-row"><span>Source health</span><strong>healthy</strong></div><div class="fresh-row"><span>Deploy mode</span><strong>fresh fetch</strong></div><div class="freshness-bars" id="age-histogram" aria-label="Age histogram"><div><span>0-24h</span><strong><i class="bar-fill bar-w-0"></i></strong><em>0</em></div><div><span>2-7d</span><strong><i class="bar-fill bar-w-100"></i></strong><em>20</em></div><div><span>8-30d</span><strong><i class="bar-fill bar-w-0"></i></strong><em>0</em></div><div><span>&gt;30d</span><strong><i class="bar-fill bar-w-0"></i></strong><em>0</em></div><div><span>unknown</span><strong><i class="bar-fill bar-w-0"></i></strong><em>0</em></div></div></section>
<section class="side-card archive-card"><h2>Archive</h2><p><span class="live-dot"></span>Static public-safe history surface</p><div class="fresh-row"><span>Latest run</span><strong id="archive-run-id">20260812T103932Z</strong></div><div class="fresh-row"><span>Archived CVEs</span><strong id="archive-count">2357</strong></div><div class="fresh-row"><span>Timelines</span><strong>2357</strong></div><div class="archive-links"><a href="https://vuln.signal-radar.com/archive/">Human archive</a><a href="https://vuln.signal-radar.com/data/vuln/archive/index.json" target="_blank" rel="noopener noreferrer">Archive index JSON</a><a href="https://vuln.signal-radar.com/data/vuln/archive/latest.json" target="_blank" rel="noopener noreferrer">Latest run JSON</a></div></section>
<section class="side-card"><h2>Safety Guardrails</h2><p><span class="live-dot"></span>Read-only public-safe controls are active</p><a class="inline-data-link" href="#settings" data-view-link="settings">View guardrails →</a></section>
</div>
</aside>
<main class="dashboard-main">
<section class="hero-panel view-panel" id="dashboard" data-view="dashboard">
<div class="hero-copy"><div class="demo-pill">public radar</div><h1>Prioritized Vulnerability Signals for Defenders</h1><p>Track CVE, KEV, EPSS, and vendor-advisory changes in one read-only radar—so teams can see what changed, why it matters, and what to verify next.</p></div>
<div class="radar-globe" aria-hidden="true"><span></span><span></span><span></span><i></i></div>
<div class="live-signal-map" data-live-signal-map data-node-count="7"><div class="live-signal-map-visual"><div class="live-map-heading"><span>LIVE SIGNAL MAP</span><strong>DEFENSIVE PRIORITY CIRCUIT</strong><small>LATEST STATIC SNAPSHOT</small></div><span class="live-map-disclaimer">PRIORITY ORDER · NOT AN ATTACK PATH</span><svg class="live-signal-map-svg" viewBox="0 0 780 230" aria-hidden="true" focusable="false"><defs><linearGradient id="live-map-line-gradient" x1="0" y1="0" x2="1" y2="0"><stop offset="0" stop-color="#26d9ee"/><stop offset=".56" stop-color="#6da7ff"/><stop offset="1" stop-color="#9b7cff"/></linearGradient><radialGradient id="live-map-critical-core"><stop offset="0" stop-color="#ffffff"/><stop offset=".7" stop-color="#eef8ff"/><stop offset="1" stop-color="#ff6d74"/></radialGradient></defs><text class="live-map-endpoint-label" x="8" y="207">OBSERVED</text><text class="live-map-endpoint-label" x="772" y="207" text-anchor="end">REVIEW</text><path class="live-map-echo live-map-echo-one" d="M 42 132 L 148 68 L 258 154 L 376 52 L 494 130 L 612 76 L 730 150" transform="translate(0 -6)"/><path class="live-map-echo live-map-echo-two" d="M 42 132 L 148 68 L 258 154 L 376 52 L 494 130 L 612 76 L 730 150" transform="translate(0 6)"/><path class="live-map-main-line" d="M 42 132 L 148 68 L 258 154 L 376 52 L 494 130 L 612 76 L 730 150" pathLength="1"/><g class="live-map-node severity-critical recency-new_disclosure remediation-reference_unknown live-map-slot-0 is-top-urgency label-priority-1" data-slot="0"><polygon class="live-map-core" points="42,120 54,132 42,144 30,132"/><path class="live-map-terminal-branch" d="M 54 132 L 65 132 L 65 105 L 75 105"/><path class="live-map-terminal-marker open" d="M 76 101 L 82 105 L 76 109"/><text class="live-map-terminal-label" x="85" y="108">REF UNKNOWN</text><g class="live-map-evidence-pin source-nvd"><rect x="31" y="109" width="4" height="4"/></g><text class="live-map-node-label" x="42" y="83" text-anchor="middle"><tspan class="vendor" x="42">UNSPECIFIED</tspan><tspan class="product" x="42" dy="-11">CVE-2026-66747</tspan><tspan class="meta" x="42" dy="-11">CVE ×1 · EPSS P45</tspan><tspan class="state" x="42" dy="-11">NEW DISCLOSURE</tspan></text></g><g class="live-map-node severity-critical recency-new_disclosure remediation-reference_unknown live-map-slot-1 label-priority-3" data-slot="1"><polygon class="live-map-core" points="148,56 160,68 148,80 136,68"/><path class="live-map-terminal-branch" d="M 160 68 L 171 68 L 171 95 L 181 95"/><path class="live-map-terminal-marker open" d="M 182 91 L 188 95 L 182 99"/><text class="live-map-terminal-label" x="191" y="98">REF UNKNOWN</text><g class="live-map-evidence-pin source-nvd"><rect x="137" y="45" width="4" height="4"/></g><text class="live-map-node-label" x="148" y="113" text-anchor="middle"><tspan class="vendor" x="148">UNSPECIFIED</tspan><tspan class="product" x="148" dy="11">CVE-2026-71237</tspan><tspan class="meta" x="148" dy="11">CVE ×1 · EPSS P35</tspan><tspan class="state" x="148" dy="11">NEW DISCLOSURE</tspan></text></g><g class="live-map-node severity-critical recency-new_disclosure remediation-reference_unknown live-map-slot-2 label-priority-4" data-slot="2"><polygon class="live-map-core" points="258,142 270,154 258,166 246,154"/><path class="live-map-terminal-branch" d="M 270 154 L 281 154 L 281 127 L 291 127"/><path class="live-map-terminal-marker open" d="M 292 123 L 298 127 L 292 131"/><text class="live-map-terminal-label" x="301" y="130">REF UNKNOWN</text><g class="live-map-evidence-pin source-nvd"><rect x="247" y="131" width="4" height="4"/></g><text class="live-map-node-label" x="258" y="105" text-anchor="middle"><tspan class="vendor" x="258">UNSPECIFIED</tspan><tspan class="product" x="258" dy="-11">CVE-2026-71231</tspan><tspan class="meta" x="258" dy="-11">CVE ×1 · EPSS P29</tspan><tspan class="state" x="258" dy="-11">NEW DISCLOSURE</tspan></text></g><g class="live-map-node severity-critical recency-new_disclosure remediation-reference_unknown live-map-slot-3 label-priority-5" data-slot="3"><polygon class="live-map-core" points="376,40 388,52 376,64 364,52"/><path class="live-map-terminal-branch" d="M 388 52 L 399 52 L 399 79 L 409 79"/><path class="live-map-terminal-marker open" d="M 410 75 L 416 79 L 410 83"/><text class="live-map-terminal-label" x="419" y="82">REF UNKNOWN</text><g class="live-map-evidence-pin source-nvd"><rect x="365" y="29" width="4" height="4"/></g><text class="live-map-node-label" x="376" y="97" text-anchor="middle"><tspan class="vendor" x="376">UNSPECIFIED</tspan><tspan class="product" x="376" dy="11">CVE-2026-71238</tspan><tspan class="meta" x="376" dy="11">CVE ×1 · EPSS P24</tspan><tspan class="state" x="376" dy="11">NEW DISCLOSURE</tspan></text></g><g class="live-map-node severity-high recency-new_disclosure remediation-reference_unknown live-map-slot-4" data-slot="4"><polygon class="live-map-core" points="487,118 501,118 506,130 501,142 487,142 482,130"/><path class="live-map-terminal-branch" d="M 506 130 L 517 130 L 517 103 L 527 103"/><path class="live-map-terminal-marker open" d="M 528 99 L 534 103 L 528 107"/><text class="live-map-terminal-label" x="537" y="106">REF UNKNOWN</text><g class="live-map-evidence-pin source-nvd"><rect x="483" y="107" width="4" height="4"/></g></g><g class="live-map-node severity-high recency-new_disclosure remediation-reference_present live-map-slot-5 label-priority-2" data-slot="5"><polygon class="live-map-core" points="606,65 618,65 623,76 618,87 606,87 601,76"/><path class="live-map-terminal-branch" d="M 623 76 L 635 76 L 635 103 L 645 103"/><rect class="live-map-terminal-marker closed" x="645" y="100" width="7" height="7"/><text class="live-map-terminal-label" x="655" y="106">REMEDIATION REF</text><path class="live-map-cluster-branch" d="M 601 76 L 589 76 L 589 89"/><circle class="live-map-cluster-dot dot-1" cx="589" cy="89" r="1.8"/><circle class="live-map-cluster-dot dot-2" cx="582" cy="89" r="1.8"/><circle class="live-map-cluster-dot dot-3" cx="575" cy="89" r="1.8"/><text class="live-map-cluster-label" x="589" y="103" text-anchor="end">CVE ×3</text><g class="live-map-evidence-pin source-nvd"><rect x="601" y="54" width="4" height="4"/></g><g class="live-map-evidence-pin source-osv"><path d="M 612 60 L 617 55"/></g><g class="live-map-evidence-pin source-vendor-advisory"><rect x="619" y="54" width="4" height="4"/></g><text class="live-map-node-label" x="612" y="121" text-anchor="middle"><tspan class="vendor" x="612">eclipse</tspan><tspan class="product" x="612" dy="11">theia</tspan><tspan class="meta" x="612" dy="11">CVE ×3 · EPSS P34</tspan><tspan class="state" x="612" dy="11">NEW DISCLOSURE</tspan></text></g><g class="live-map-node severity-medium recency-new_disclosure remediation-reference_unknown live-map-slot-6" data-slot="6"><circle class="live-map-core" cx="730" cy="150" r="11"/><path class="live-map-terminal-branch" d="M 741 150 L 753 150 L 753 123 L 763 123"/><path class="live-map-terminal-marker open" d="M 764 119 L 770 123 L 764 127"/><text class="live-map-terminal-label" x="772" y="116" text-anchor="end">REF UNKNOWN</text><g class="live-map-evidence-pin source-nvd"><rect x="719" y="128" width="4" height="4"/></g></g></svg></div><p class="sr-only">Latest static defensive priority circuit. This is a review-priority visualization, not an attack path. 7 product clusters are shown. The highest urgency cluster is CVE-2026-66747, with 1 CVE, 0 KEV-listed records, EPSS percentile 45, and remediation reference unknown. 0 displayed clusters contain KEV-listed records. The highest displayed EPSS percentile is 45. 4 critical clusters have unknown remediation references. The largest displayed cluster is eclipse theia, with 3 CVEs. Additional affected products are present in the underlying record.</p></div>
</section>
<section class="status-strip view-panel" id="status-strip" data-view="dashboard"><span class="status-chip on">indexable public surface</span><span class="status-chip on">read-only dataset</span><span class="status-chip on">public-safe sources</span><span class="status-chip on">external execution disabled</span><span class="status-chip on">auto remediation disabled</span></section>
<section class="private-stat-grid view-panel" id="private-stat-grid" data-view="dashboard"><article class="stat-card "><span class="stat-icon"><img src="/assets/vuln/kpi-new-cves.webp" alt="" aria-hidden="true" loading="lazy" decoding="async"></span><div><small>Tracked CVEs</small><strong>20</strong><em>20 new in 7d</em></div></article><article class="stat-card critical"><span class="stat-icon"><img src="/assets/vuln/kpi-critical.webp" alt="" aria-hidden="true" loading="lazy" decoding="async"></span><div><small>Critical</small><strong>4</strong><em>canonical CVSS</em></div></article><article class="stat-card kev"><span class="stat-icon"><img src="/assets/vuln/kpi-kev.webp" alt="" aria-hidden="true" loading="lazy" decoding="async"></span><div><small>Known Exploited</small><strong>0</strong><em>KEV observed</em></div></article><article class="stat-card epss"><span class="stat-icon"><img src="/assets/vuln/kpi-high-epss.webp" alt="" aria-hidden="true" loading="lazy" decoding="async"></span><div><small>High EPSS percentile (≥70)</small><strong>0</strong><em>EPSS percentile observed</em></div></article><article class="stat-card "><span class="stat-icon"><img src="/assets/vuln/kpi-monitored-vendors.webp" alt="" aria-hidden="true" loading="lazy" decoding="async"></span><div><small>Monitored Vendors</small><strong>2</strong><em>from current data</em></div></article></section>
<section class="filter-toolbar view-panel" data-view="dashboard signals reports" aria-label="Signal filters">
<div class="filter-group search-group"><label class="feed-search" for="feed-search"><span aria-hidden="true">⌕</span><input id="feed-search" type="search" autocomplete="off" aria-label="Search live feed" placeholder="Search in live feed..."><kbd aria-hidden="true">⌘K</kbd></label></div>
<div class="filter-group chip-group" role="group" aria-label="Quick filters"><button class="filter-chip critical" data-severity-chip="CRITICAL" type="button" aria-label="Filter Critical severity">Critical</button><button class="filter-chip high" data-severity-chip="HIGH" type="button" aria-label="Filter High severity">High</button><button class="filter-chip kev" id="kev-chip" type="button" aria-label="Filter KEV listed">KEV</button><button class="filter-chip epss" id="epss-chip" type="button" aria-label="Filter EPSS percentile 70 or higher">EPSS ≥70</button></div>
<div class="filter-group action-group"><button class="clear-button" id="filter-reset" type="button">Clear all</button><button class="icon-button" data-save-view type="button" aria-label="Save view">⚙</button></div>
<div class="filter-group select-group" role="group" aria-label="Structured filters"><select id="severity-filter" aria-label="Severity filter"><option value="all">Severity All</option><option value="CRITICAL">Critical</option><option value="HIGH">High</option><option value="MEDIUM">Medium</option><option value="LOW">Low</option><option value="NONE">None</option><option value="UNKNOWN">Unknown</option></select>
<select id="kev-filter" aria-label="KEV filter"><option value="all">KEV All</option><option value="yes">KEV listed</option><option value="no">Not listed</option></select>
<select id="source-filter" aria-label="Source filter"><option value="all">Source All</option><option value="NVD">NVD</option><option value="OSV">OSV</option><option value="CISA KEV">CISA KEV</option><option value="Vendor Advisory">Vendor Advisory</option></select>
<select id="vendor-filter" aria-label="Vendor filter"><option value="all">Vendor</option></select><select id="product-filter" aria-label="Product filter"><option value="all">Product</option></select><select id="time-filter" aria-label="Time range"><option value="all">Any time</option><option value="today">Today</option><option value="week">This week</option></select><select id="sort-select" aria-label="Sort"><option value="priority">Sort Priority</option><option value="updated">Observed</option><option value="epss">EPSS percentile</option><option value="cvss">CVSS Severity</option></select></div>
</section>
<section class="panel vuln-treemap-panel view-panel" data-view="dashboard signals" data-vuln-treemap-root data-menu-open="false" aria-labelledby="vuln-treemap-title"><header class="vuln-treemap-head"><div class="vuln-treemap-title"><span class="vuln-treemap-kicker"><i aria-hidden="true"></i>VULNERABILITY TREEMAP</span><h2 id="vuln-treemap-title">DEFENSIVE PRIORITY SURFACE</h2><p>Stable CVE grouping for defensive triage. Area changes by display mode; severity remains encoded by color.</p></div><div class="vuln-treemap-status" role="status" aria-live="polite"><span><i aria-hidden="true"></i>LATEST STATIC SNAPSHOT</span><small data-vuln-treemap-status-detail>2026-08-12 10:39 UTC / 2026-08-12 19:39 JST</small></div><button type="button" class="vuln-treemap-menu-trigger" data-vuln-treemap-toggle aria-expanded="false" aria-controls="vuln-treemap-content" aria-label="Open defensive priority surface"><span class="vuln-treemap-menu-trigger__copy" aria-hidden="true"><small>VULN MAP</small><strong data-vuln-treemap-menu-state>OPEN</strong></span><span class="vuln-treemap-menu-trigger__icon" aria-hidden="true"><i data-menu-line="top"></i><i data-menu-line="middle"></i><i data-menu-line="bottom"></i></span></button></header><div id="vuln-treemap-content" class="vuln-treemap-content" data-vuln-treemap-content aria-hidden="true" inert><div class="vuln-treemap-content__inner" data-vuln-treemap-inner><div class="vuln-treemap-command-bar" data-surface-reveal><div><span>DISPLAY MODE</span><small data-vuln-treemap-mode-label>DEFENSIVE PRIORITY</small></div><div class="vuln-treemap-mode-switch" role="group" aria-label="Vulnerability treemap mode"><button type="button" data-vuln-treemap-mode="priority" aria-pressed="true">Priority <kbd>P</kbd></button><button type="button" data-vuln-treemap-mode="pressure" aria-pressed="false">Pressure <kbd>E</kbd></button></div></div><div class="vuln-treemap-body" data-surface-reveal><div class="vuln-treemap-viewport" data-vuln-treemap-viewport role="group" aria-label="Defensive priority CVE treemap. Use Tab or arrow keys to navigate tiles."><div class="vuln-treemap-grid" aria-hidden="true"></div><div data-vuln-treemap-groups aria-hidden="true"></div><div data-vuln-treemap-tiles></div><div class="vuln-treemap-tooltip" data-vuln-treemap-tooltip id="vuln-treemap-tooltip" role="tooltip" hidden></div><div class="vuln-treemap-empty" data-vuln-treemap-empty role="status" hidden><strong>No vulnerability tiles match the active filters</strong><p>The feed, priority queue, and dashboard remain available.</p><button type="button" data-vuln-treemap-clear>Clear filters</button></div></div></div><footer class="vuln-treemap-foot" data-surface-reveal><div class="vuln-treemap-legend" aria-label="Vulnerability treemap legend"><span class="is-critical"><i></i>Critical</span><span class="is-high"><i></i>High</span><span class="is-medium"><i></i>Medium</span><span class="is-low"><i></i>Low</span><span class="is-unknown"><i></i>Unknown</span><span class="is-kev"><i></i>KEV marker</span><span class="is-epss"><i></i>EPSS glow</span><span class="is-confidence"><i></i>Edge = evidence confidence</span></div><p>Area shows defensive priority or exploit-signal pressure. This is a public-safe static snapshot, not an inventory or exposure measurement.</p><span class="vuln-treemap-keyboard-note">Tab / Arrows navigate · Enter opens · Esc closes · P / E mode</span></footer></div></div></section>
<section class="dashboard-grid-mvp view-panel" id="signals" data-view="dashboard signals">
<div class="panel live-feed-panel view-panel" data-view="dashboard signals"><div class="panel-head"><h2 id="live-feed-heading" tabindex="-1">Live Vulnerability Feed <span class="live-label">READ-ONLY</span></h2><div class="feed-status"><span id="feed-result-count" role="status" aria-live="polite" aria-atomic="true">20 signals</span><a href="#signals" data-view-link="signals">View all signals →</a></div></div><div id="live-feed" class="live-feed"><article class="feed-row" data-signal-id="CVE-2026-71237"><span class="observed">2026-08-12</span><span class="live-dot"></span><div class="feed-title"><button class="linklike signal-focus-target" type="button" data-open-detail="CVE-2026-71237" data-signal-id="CVE-2026-71237" data-focus-role="primary" data-signal-focus-target aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="CVE-2026-71237, CRITICAL, -, open vulnerability detail">CVE-2026-71237</button><strong>defensive priority signal</strong></div><span class="severity-pill critical">CRITICAL</span><span class="epss-cell">EPSS <strong>0.0042 (35)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">-</span><span class="summary-cell">NVD: Miantang/IoT-PHP&#x27;s index.php implements a POST /userlogin route that reads the password directly from [&#x27;pwd&#x27;] with no sanitization and… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71237.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" type="button" data-bookmark="CVE-2026-71237" data-signal-id="CVE-2026-71237" data-focus-role="bookmark" aria-pressed="false" aria-label="Save CVE-2026-71237 to local watchlist">♡</button><button class="kebab" type="button" data-open-detail="CVE-2026-71237" data-signal-id="CVE-2026-71237" data-focus-role="more" aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="Open detail for CVE-2026-71237">⋮</button></article><article class="feed-row" data-signal-id="CVE-2026-71231"><span class="observed">2026-08-12</span><span class="live-dot"></span><div class="feed-title"><button class="linklike signal-focus-target" type="button" data-open-detail="CVE-2026-71231" data-signal-id="CVE-2026-71231" data-focus-role="primary" data-signal-focus-target aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="CVE-2026-71231, CRITICAL, -, open vulnerability detail">CVE-2026-71231</button><strong>defensive priority signal</strong></div><span class="severity-pill critical">CRITICAL</span><span class="epss-cell">EPSS <strong>0.0036 (29)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">-</span><span class="summary-cell">NVD: IOTSmartHome&#x27;s gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID=&#x27;&lt;decoded lastLogin c… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71231.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" type="button" data-bookmark="CVE-2026-71231" data-signal-id="CVE-2026-71231" data-focus-role="bookmark" aria-pressed="false" aria-label="Save CVE-2026-71231 to local watchlist">♡</button><button class="kebab" type="button" data-open-detail="CVE-2026-71231" data-signal-id="CVE-2026-71231" data-focus-role="more" aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="Open detail for CVE-2026-71231">⋮</button></article><article class="feed-row" data-signal-id="CVE-2026-66747"><span class="observed">2026-08-12</span><span class="live-dot"></span><div class="feed-title"><button class="linklike signal-focus-target" type="button" data-open-detail="CVE-2026-66747" data-signal-id="CVE-2026-66747" data-focus-role="primary" data-signal-focus-target aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="CVE-2026-66747, CRITICAL, -, open vulnerability detail">CVE-2026-66747</button><strong>defensive priority signal</strong></div><span class="severity-pill critical">CRITICAL</span><span class="epss-cell">EPSS <strong>0.0058 (45)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">-</span><span class="summary-cell">NVD: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product li… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-66747.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" type="button" data-bookmark="CVE-2026-66747" data-signal-id="CVE-2026-66747" data-focus-role="bookmark" aria-pressed="false" aria-label="Save CVE-2026-66747 to local watchlist">♡</button><button class="kebab" type="button" data-open-detail="CVE-2026-66747" data-signal-id="CVE-2026-66747" data-focus-role="more" aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="Open detail for CVE-2026-66747">⋮</button></article><article class="feed-row" data-signal-id="CVE-2026-71238"><span class="observed">2026-08-12</span><span class="live-dot"></span><div class="feed-title"><button class="linklike signal-focus-target" type="button" data-open-detail="CVE-2026-71238" data-signal-id="CVE-2026-71238" data-focus-role="primary" data-signal-focus-target aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="CVE-2026-71238, CRITICAL, -, open vulnerability detail">CVE-2026-71238</button><strong>defensive priority signal</strong></div><span class="severity-pill critical">CRITICAL</span><span class="epss-cell">EPSS <strong>0.0031 (24)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">-</span><span class="summary-cell">NVD: DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71238.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" type="button" data-bookmark="CVE-2026-71238" data-signal-id="CVE-2026-71238" data-focus-role="bookmark" aria-pressed="false" aria-label="Save CVE-2026-71238 to local watchlist">♡</button><button class="kebab" type="button" data-open-detail="CVE-2026-71238" data-signal-id="CVE-2026-71238" data-focus-role="more" aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="Open detail for CVE-2026-71238">⋮</button></article><article class="feed-row" data-signal-id="CVE-2026-60009"><span class="observed">2026-08-12</span><span class="live-dot"></span><div class="feed-title"><button class="linklike signal-focus-target" type="button" data-open-detail="CVE-2026-60009" data-signal-id="CVE-2026-60009" data-focus-role="primary" data-signal-focus-target aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="CVE-2026-60009, HIGH, eclipse, open vulnerability detail">CVE-2026-60009</button><strong>defensive priority signal</strong></div><span class="severity-pill high">HIGH</span><span class="epss-cell">EPSS <strong>0.0032 (25)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">eclipse / theia</span><span class="summary-cell">NVD: In Eclipse Theia versions up to and including 1.73.1, the @theia/filesystem backend binds POST /file-upload in every filesystem-enable… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-60009.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" type="button" data-bookmark="CVE-2026-60009" data-signal-id="CVE-2026-60009" data-focus-role="bookmark" aria-pressed="false" aria-label="Save CVE-2026-60009 to local watchlist">♡</button><button class="kebab" type="button" data-open-detail="CVE-2026-60009" data-signal-id="CVE-2026-60009" data-focus-role="more" aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="Open detail for CVE-2026-60009">⋮</button></article><article class="feed-row" data-signal-id="CVE-2026-71235"><span class="observed">2026-08-12</span><span class="live-dot"></span><div class="feed-title"><button class="linklike signal-focus-target" type="button" data-open-detail="CVE-2026-71235" data-signal-id="CVE-2026-71235" data-focus-role="primary" data-signal-focus-target aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="CVE-2026-71235, HIGH, -, open vulnerability detail">CVE-2026-71235</button><strong>defensive priority signal</strong></div><span class="severity-pill high">HIGH</span><span class="epss-cell">EPSS <strong>0.0029 (21)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">-</span><span class="summary-cell">NVD: Magistrala&#x27;s Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT mes… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71235.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" type="button" data-bookmark="CVE-2026-71235" data-signal-id="CVE-2026-71235" data-focus-role="bookmark" aria-pressed="false" aria-label="Save CVE-2026-71235 to local watchlist">♡</button><button class="kebab" type="button" data-open-detail="CVE-2026-71235" data-signal-id="CVE-2026-71235" data-focus-role="more" aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="Open detail for CVE-2026-71235">⋮</button></article><article class="feed-row" data-signal-id="CVE-2026-71243"><span class="observed">2026-08-12</span><span class="live-dot"></span><div class="feed-title"><button class="linklike signal-focus-target" type="button" data-open-detail="CVE-2026-71243" data-signal-id="CVE-2026-71243" data-focus-role="primary" data-signal-focus-target aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="CVE-2026-71243, HIGH, -, open vulnerability detail">CVE-2026-71243</button><strong>defensive priority signal</strong></div><span class="severity-pill high">HIGH</span><span class="epss-cell">EPSS <strong>0.0029 (21)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">-</span><span class="summary-cell">NVD: The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filte… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71243.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" type="button" data-bookmark="CVE-2026-71243" data-signal-id="CVE-2026-71243" data-focus-role="bookmark" aria-pressed="false" aria-label="Save CVE-2026-71243 to local watchlist">♡</button><button class="kebab" type="button" data-open-detail="CVE-2026-71243" data-signal-id="CVE-2026-71243" data-focus-role="more" aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="Open detail for CVE-2026-71243">⋮</button></article><article class="feed-row" data-signal-id="CVE-2026-71233"><span class="observed">2026-08-12</span><span class="live-dot"></span><div class="feed-title"><button class="linklike signal-focus-target" type="button" data-open-detail="CVE-2026-71233" data-signal-id="CVE-2026-71233" data-focus-role="primary" data-signal-focus-target aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="CVE-2026-71233, HIGH, -, open vulnerability detail">CVE-2026-71233</button><strong>defensive priority signal</strong></div><span class="severity-pill high">HIGH</span><span class="epss-cell">EPSS <strong>0.0020 (10)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">-</span><span class="summary-cell">NVD: InvoiceNinja v5-stable renders an invoice or quote&#x27;s &quot;terms&quot; field in the client portal using Laravel Blade&#x27;s raw output directive {!!… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71233.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" type="button" data-bookmark="CVE-2026-71233" data-signal-id="CVE-2026-71233" data-focus-role="bookmark" aria-pressed="false" aria-label="Save CVE-2026-71233 to local watchlist">♡</button><button class="kebab" type="button" data-open-detail="CVE-2026-71233" data-signal-id="CVE-2026-71233" data-focus-role="more" aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="Open detail for CVE-2026-71233">⋮</button></article><article class="feed-row" data-signal-id="CVE-2026-71236"><span class="observed">2026-08-12</span><span class="live-dot"></span><div class="feed-title"><button class="linklike signal-focus-target" type="button" data-open-detail="CVE-2026-71236" data-signal-id="CVE-2026-71236" data-focus-role="primary" data-signal-focus-target aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="CVE-2026-71236, HIGH, -, open vulnerability detail">CVE-2026-71236</button><strong>defensive priority signal</strong></div><span class="severity-pill high">HIGH</span><span class="epss-cell">EPSS <strong>0.0020 (10)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">-</span><span class="summary-cell">NVD: Grocy&#x27;s API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field value… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71236.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" type="button" data-bookmark="CVE-2026-71236" data-signal-id="CVE-2026-71236" data-focus-role="bookmark" aria-pressed="false" aria-label="Save CVE-2026-71236 to local watchlist">♡</button><button class="kebab" type="button" data-open-detail="CVE-2026-71236" data-signal-id="CVE-2026-71236" data-focus-role="more" aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="Open detail for CVE-2026-71236">⋮</button></article><article class="feed-row" data-signal-id="CVE-2026-71242"><span class="observed">2026-08-12</span><span class="live-dot"></span><div class="feed-title"><button class="linklike signal-focus-target" type="button" data-open-detail="CVE-2026-71242" data-signal-id="CVE-2026-71242" data-focus-role="primary" data-signal-focus-target aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="CVE-2026-71242, HIGH, -, open vulnerability detail">CVE-2026-71242</button><strong>defensive priority signal</strong></div><span class="severity-pill high">HIGH</span><span class="epss-cell">EPSS <strong>0.0022 (12)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">-</span><span class="summary-cell">NVD: Crater&#x27;s NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, un… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71242.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" type="button" data-bookmark="CVE-2026-71242" data-signal-id="CVE-2026-71242" data-focus-role="bookmark" aria-pressed="false" aria-label="Save CVE-2026-71242 to local watchlist">♡</button><button class="kebab" type="button" data-open-detail="CVE-2026-71242" data-signal-id="CVE-2026-71242" data-focus-role="more" aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="Open detail for CVE-2026-71242">⋮</button></article><article class="feed-row" data-signal-id="CVE-2026-71239"><span class="observed">2026-08-12</span><span class="live-dot"></span><div class="feed-title"><button class="linklike signal-focus-target" type="button" data-open-detail="CVE-2026-71239" data-signal-id="CVE-2026-71239" data-focus-role="primary" data-signal-focus-target aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="CVE-2026-71239, HIGH, -, open vulnerability detail">CVE-2026-71239</button><strong>defensive priority signal</strong></div><span class="severity-pill high">HIGH</span><span class="epss-cell">EPSS <strong>0.0022 (13)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">-</span><span class="summary-cell">NVD: DjangoCRM&#x27;s massmail module renders user-controlled EmlMessage fields (subject, content) through Django&#x27;s Template constructor with no… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71239.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" type="button" data-bookmark="CVE-2026-71239" data-signal-id="CVE-2026-71239" data-focus-role="bookmark" aria-pressed="false" aria-label="Save CVE-2026-71239 to local watchlist">♡</button><button class="kebab" type="button" data-open-detail="CVE-2026-71239" data-signal-id="CVE-2026-71239" data-focus-role="more" aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="Open detail for CVE-2026-71239">⋮</button></article><article class="feed-row" data-signal-id="CVE-2026-12609"><span class="observed">2026-08-12</span><span class="live-dot"></span><div class="feed-title"><button class="linklike signal-focus-target" type="button" data-open-detail="CVE-2026-12609" data-signal-id="CVE-2026-12609" data-focus-role="primary" data-signal-focus-target aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="CVE-2026-12609, HIGH, eclipse, open vulnerability detail">CVE-2026-12609</button><strong>defensive priority signal</strong></div><span class="severity-pill high">HIGH</span><span class="epss-cell">EPSS <strong>0.0041 (34)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">eclipse / theia</span><span class="summary-cell">NVD: In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the @theia/plugin-ext backend exposes the /hostedPlugin/:pluginId/:pat… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-12609.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" type="button" data-bookmark="CVE-2026-12609" data-signal-id="CVE-2026-12609" data-focus-role="bookmark" aria-pressed="false" aria-label="Save CVE-2026-12609 to local watchlist">♡</button><button class="kebab" type="button" data-open-detail="CVE-2026-12609" data-signal-id="CVE-2026-12609" data-focus-role="more" aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="Open detail for CVE-2026-12609">⋮</button></article><article class="feed-row" data-signal-id="CVE-2026-71241"><span class="observed">2026-08-12</span><span class="live-dot"></span><div class="feed-title"><button class="linklike signal-focus-target" type="button" data-open-detail="CVE-2026-71241" data-signal-id="CVE-2026-71241" data-focus-role="primary" data-signal-focus-target aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="CVE-2026-71241, HIGH, -, open vulnerability detail">CVE-2026-71241</button><strong>defensive priority signal</strong></div><span class="severity-pill high">HIGH</span><span class="epss-cell">EPSS <strong>0.0028 (20)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">-</span><span class="summary-cell">NVD: Book-Management-System&#x27;s Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @log… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71241.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" type="button" data-bookmark="CVE-2026-71241" data-signal-id="CVE-2026-71241" data-focus-role="bookmark" aria-pressed="false" aria-label="Save CVE-2026-71241 to local watchlist">♡</button><button class="kebab" type="button" data-open-detail="CVE-2026-71241" data-signal-id="CVE-2026-71241" data-focus-role="more" aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="Open detail for CVE-2026-71241">⋮</button></article><article class="feed-row" data-signal-id="CVE-2026-71234"><span class="observed">2026-08-12</span><span class="live-dot"></span><div class="feed-title"><button class="linklike signal-focus-target" type="button" data-open-detail="CVE-2026-71234" data-signal-id="CVE-2026-71234" data-focus-role="primary" data-signal-focus-target aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="CVE-2026-71234, HIGH, -, open vulnerability detail">CVE-2026-71234</button><strong>defensive priority signal</strong></div><span class="severity-pill high">HIGH</span><span class="epss-cell">EPSS <strong>0.0024 (16)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">-</span><span class="summary-cell">NVD: Documize Community&#x27;s attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no aut… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71234.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" type="button" data-bookmark="CVE-2026-71234" data-signal-id="CVE-2026-71234" data-focus-role="bookmark" aria-pressed="false" aria-label="Save CVE-2026-71234 to local watchlist">♡</button><button class="kebab" type="button" data-open-detail="CVE-2026-71234" data-signal-id="CVE-2026-71234" data-focus-role="more" aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="Open detail for CVE-2026-71234">⋮</button></article><article class="feed-row" data-signal-id="CVE-2026-71232"><span class="observed">2026-08-12</span><span class="live-dot"></span><div class="feed-title"><button class="linklike signal-focus-target" type="button" data-open-detail="CVE-2026-71232" data-signal-id="CVE-2026-71232" data-focus-role="primary" data-signal-focus-target aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="CVE-2026-71232, HIGH, -, open vulnerability detail">CVE-2026-71232</button><strong>defensive priority signal</strong></div><span class="severity-pill high">HIGH</span><span class="epss-cell">EPSS <strong>0.0030 (22)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">-</span><span class="summary-cell">NVD: MacCMS10&#x27;s admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71232.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" type="button" data-bookmark="CVE-2026-71232" data-signal-id="CVE-2026-71232" data-focus-role="bookmark" aria-pressed="false" aria-label="Save CVE-2026-71232 to local watchlist">♡</button><button class="kebab" type="button" data-open-detail="CVE-2026-71232" data-signal-id="CVE-2026-71232" data-focus-role="more" aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="Open detail for CVE-2026-71232">⋮</button></article><article class="feed-row" data-signal-id="CVE-2026-71244"><span class="observed">2026-08-12</span><span class="live-dot"></span><div class="feed-title"><button class="linklike signal-focus-target" type="button" data-open-detail="CVE-2026-71244" data-signal-id="CVE-2026-71244" data-focus-role="primary" data-signal-focus-target aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="CVE-2026-71244, MEDIUM, -, open vulnerability detail">CVE-2026-71244</button><strong>defensive priority signal</strong></div><span class="severity-pill medium">MEDIUM</span><span class="epss-cell">EPSS <strong>0.0020 (10)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">-</span><span class="summary-cell">NVD: Paperless-ngx&#x27;s MailAccountViewSet.test action, when called with an existing account&#x27;s ID and a masked password field, reuses the stor… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71244.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" type="button" data-bookmark="CVE-2026-71244" data-signal-id="CVE-2026-71244" data-focus-role="bookmark" aria-pressed="false" aria-label="Save CVE-2026-71244 to local watchlist">♡</button><button class="kebab" type="button" data-open-detail="CVE-2026-71244" data-signal-id="CVE-2026-71244" data-focus-role="more" aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="Open detail for CVE-2026-71244">⋮</button></article><article class="feed-row" data-signal-id="CVE-2026-14574"><span class="observed">2026-08-12</span><span class="live-dot"></span><div class="feed-title"><button class="linklike signal-focus-target" type="button" data-open-detail="CVE-2026-14574" data-signal-id="CVE-2026-14574" data-focus-role="primary" data-signal-focus-target aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="CVE-2026-14574, MEDIUM, eclipse, open vulnerability detail">CVE-2026-14574</button><strong>defensive priority signal</strong></div><span class="severity-pill medium">MEDIUM</span><span class="epss-cell">EPSS <strong>0.0028 (20)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">eclipse / theia</span><span class="summary-cell">NVD: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges pr… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14574.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" type="button" data-bookmark="CVE-2026-14574" data-signal-id="CVE-2026-14574" data-focus-role="bookmark" aria-pressed="false" aria-label="Save CVE-2026-14574 to local watchlist">♡</button><button class="kebab" type="button" data-open-detail="CVE-2026-14574" data-signal-id="CVE-2026-14574" data-focus-role="more" aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="Open detail for CVE-2026-14574">⋮</button></article><article class="feed-row" data-signal-id="CVE-2026-14304"><span class="observed">2026-08-12</span><span class="live-dot"></span><div class="feed-title"><button class="linklike signal-focus-target" type="button" data-open-detail="CVE-2026-14304" data-signal-id="CVE-2026-14304" data-focus-role="primary" data-signal-focus-target aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="CVE-2026-14304, MEDIUM, eclipse, open vulnerability detail">CVE-2026-14304</button><strong>defensive priority signal</strong></div><span class="severity-pill medium">MEDIUM</span><span class="epss-cell">EPSS <strong>0.0017 (7)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">eclipse / accessibility_tools_framework</span><span class="summary-cell">NVD: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based ap… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14304.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" type="button" data-bookmark="CVE-2026-14304" data-signal-id="CVE-2026-14304" data-focus-role="bookmark" aria-pressed="false" aria-label="Save CVE-2026-14304 to local watchlist">♡</button><button class="kebab" type="button" data-open-detail="CVE-2026-14304" data-signal-id="CVE-2026-14304" data-focus-role="more" aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="Open detail for CVE-2026-14304">⋮</button></article><article class="feed-row" data-signal-id="CVE-2026-71240"><span class="observed">2026-08-12</span><span class="live-dot"></span><div class="feed-title"><button class="linklike signal-focus-target" type="button" data-open-detail="CVE-2026-71240" data-signal-id="CVE-2026-71240" data-focus-role="primary" data-signal-focus-target aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="CVE-2026-71240, MEDIUM, -, open vulnerability detail">CVE-2026-71240</button><strong>defensive priority signal</strong></div><span class="severity-pill medium">MEDIUM</span><span class="epss-cell">EPSS <strong>0.0019 (9)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">-</span><span class="summary-cell">NVD: DjangoCRM&#x27;s toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or staff_member_requ… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71240.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" type="button" data-bookmark="CVE-2026-71240" data-signal-id="CVE-2026-71240" data-focus-role="bookmark" aria-pressed="false" aria-label="Save CVE-2026-71240 to local watchlist">♡</button><button class="kebab" type="button" data-open-detail="CVE-2026-71240" data-signal-id="CVE-2026-71240" data-focus-role="more" aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="Open detail for CVE-2026-71240">⋮</button></article><article class="feed-row" data-signal-id="CVE-2026-17578"><span class="observed">2026-08-12</span><span class="live-dot"></span><div class="feed-title"><button class="linklike signal-focus-target" type="button" data-open-detail="CVE-2026-17578" data-signal-id="CVE-2026-17578" data-focus-role="primary" data-signal-focus-target aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="CVE-2026-17578, LOW, -, open vulnerability detail">CVE-2026-17578</button><strong>defensive priority signal</strong></div><span class="severity-pill low">LOW</span><span class="epss-cell">EPSS <strong>0.0015 (5)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">-</span><span class="summary-cell">NVD: Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usag… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-17578.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" type="button" data-bookmark="CVE-2026-17578" data-signal-id="CVE-2026-17578" data-focus-role="bookmark" aria-pressed="false" aria-label="Save CVE-2026-17578 to local watchlist">♡</button><button class="kebab" type="button" data-open-detail="CVE-2026-17578" data-signal-id="CVE-2026-17578" data-focus-role="more" aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="Open detail for CVE-2026-17578">⋮</button></article></div><noscript><div class="noscript-feed"><h3>Public-safe defensive signals</h3><ul><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71237/" target="_blank" rel="noopener noreferrer">CVE-2026-71237</a> <span class="severity-pill critical">CRITICAL</span> <span>CVSS 9.8</span> <span>-</span><p>NVD: Miantang/IoT-PHP&#x27;s index.php implements a POST /userlogin route that reads the password directly from [&#x27;pwd&#x27;] with no sanitization and concatenates it into a raw SQL string: mysql_query(&quot;select * from userlists where username=&#x27;&#x27; and password=&#x27;&#x27; limit 1&quot;).</p><p>This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review; CVSS 9.8 (CRITICAL); EPSS percentile 35; sources: NVD.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71231/" target="_blank" rel="noopener noreferrer">CVE-2026-71231</a> <span class="severity-pill critical">CRITICAL</span> <span>CVSS 9.8</span> <span>-</span><p>NVD: IOTSmartHome&#x27;s gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID=&#x27;&lt;decoded lastLogin cookie&gt;&#x27; after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding...</p><p>This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review; CVSS 9.8 (CRITICAL); EPSS percentile 29; sources: NVD.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66747/" target="_blank" rel="noopener noreferrer">CVE-2026-66747</a> <span class="severity-pill critical">CRITICAL</span> <span>CVSS 9.3</span> <span>-</span><p>NVD: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. NVD: It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel&#x27;s [kworker/*] threads. NVD: It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds.</p><p>An attacker may gain root or administrative-level privileges on affected systems; CVSS 9.3 (CRITICAL); EPSS percentile 45; sources: NVD.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71238/" target="_blank" rel="noopener noreferrer">CVE-2026-71238</a> <span class="severity-pill critical">CRITICAL</span> <span>CVSS 9.1</span> <span>-</span><p>NVD: DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. NVD: Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens...</p><p>This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review; CVSS 9.1 (CRITICAL); EPSS percentile 24; sources: NVD.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60009/" target="_blank" rel="noopener noreferrer">CVE-2026-60009</a> <span class="severity-pill high">HIGH</span> <span>CVSS 8.8</span> <span>eclipse / theia</span><p>NVD: In Eclipse Theia versions up to and including 1.73.1, the @theia/filesystem backend binds POST /file-upload in every filesystem-enabled deployment. NVD: The handler takes an attacker-supplied absolute path from the multipart uri field and calls fs.move(tmp, target, { overwrite: true }) with no workspace confinement and no authentication. NVD: In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in @theia/core re-issues the cookie and calls next() without rejecting tokenless HTTP requests.</p><p>An attacker may be able to run code or commands on affected systems; CVSS 8.8 (HIGH); EPSS percentile 25; affected product context: eclipse / theia; sources: NVD, OSV, Vendor Advisory.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71235/" target="_blank" rel="noopener noreferrer">CVE-2026-71235</a> <span class="severity-pill high">HIGH</span> <span>CVSS 8.8</span> <span>-</span><p>NVD: Magistrala&#x27;s Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. NVD: The Lua script engine (re/lua.go) performs no input validation at all and preloads dangerous libraries: db (arbitrary database access), ioutil (file I/O), an HTTP client (SSRF), and filepath (traversal).</p><p>This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary; CVSS 8.8 (HIGH); EPSS percentile 21; sources: NVD.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71243/" target="_blank" rel="noopener noreferrer">CVE-2026-71243</a> <span class="severity-pill high">HIGH</span> <span>CVSS 8.8</span> <span>-</span><p>NVD: The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. NVD: cmd = &quot;mkdir -p &quot; + path.join(info.destination, info.name) + &quot;; &quot; - and executes the resulting string through a shell via ssh2-exec (locally via child_process, or remotely via SSH when an ssh handle is supplied), rather than using execFile/spawn with an... OSV: backmeup (npm) - OS Command Injection via Backup Option Values</p><p>An attacker may be able to run unintended system commands through the affected component; CVSS 8.8 (HIGH); EPSS percentile 21; sources: NVD, OSV.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71233/" target="_blank" rel="noopener noreferrer">CVE-2026-71233</a> <span class="severity-pill high">HIGH</span> <span>CVSS 8.7</span> <span>-</span><p>NVD: InvoiceNinja v5-stable renders an invoice or quote&#x27;s &quot;terms&quot; field in the client portal using Laravel Blade&#x27;s raw output directive {!! NVD: -&gt;terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization.</p><p>This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 8.7 (HIGH); EPSS percentile 10; sources: NVD.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71236/" target="_blank" rel="noopener noreferrer">CVE-2026-71236</a> <span class="severity-pill high">HIGH</span> <span>CVSS 8.7</span> <span>-</span><p>NVD: Grocy&#x27;s API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HTML-entity encoding of the resulting output by replacing &amp;amp;lt;, &amp;amp;gt;, and...</p><p>This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 8.7 (HIGH); EPSS percentile 10; sources: NVD.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71242/" target="_blank" rel="noopener noreferrer">CVE-2026-71242</a> <span class="severity-pill high">HIGH</span> <span>CVSS 8.3</span> <span>-</span><p>NVD: Crater&#x27;s NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify -&gt;hasCompany(-&gt;company_id). NVD: Any authenticated user of one company can read, edit, or delete another company&#x27;s notes by ID. OSV: Crater - Cross-Company IDOR on Notes via Missing Company-Ownership Check in NotePolicy</p><p>This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary; CVSS 8.3 (HIGH); EPSS percentile 12; sources: NVD, OSV.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71239/" target="_blank" rel="noopener noreferrer">CVE-2026-71239</a> <span class="severity-pill high">HIGH</span> <span>CVSS 8.1</span> <span>-</span><p>NVD: DjangoCRM&#x27;s massmail module renders user-controlled EmlMessage fields (subject, content) through Django&#x27;s Template constructor with no sanitization, in at least three locations: message_previews.py builds an f-string embedding message.subject/message.content...</p><p>This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 8.1 (HIGH); EPSS percentile 13; sources: NVD.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12609/" target="_blank" rel="noopener noreferrer">CVE-2026-12609</a> <span class="severity-pill high">HIGH</span> <span>CVSS 7.5</span> <span>eclipse / theia</span><p>NVD: In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the @theia/plugin-ext backend exposes the /hostedPlugin/:pluginId/:path(*) HTTP endpoint, which resolves the requested file path with path.resolve(localPath, filePath) without verifying that the... NVD: An unauthenticated network attacker can send percent-encoded ../ sequences (%2e%2e%2f) that decode into the path parameter and escape the plugin directory, allowing arbitrary files readable by the Theia backend process to be retrieved. NVD: Plugin IDs are derived deterministically from a plugin&#x27;s publisher and name, so built-in plugins serve as reliable anchors that require no prior knowledge of the target system.</p><p>This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure; CVSS 7.5 (HIGH); EPSS percentile 34; affected product context: eclipse / theia; sources: NVD, OSV, Vendor Advisory.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71241/" target="_blank" rel="noopener noreferrer">CVE-2026-71241</a> <span class="severity-pill high">HIGH</span> <span>CVSS 7.5</span> <span>-</span><p>NVD: Book-Management-System&#x27;s Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. NVD: Because card_id values are sequential integers, the entire student database can be enumerated without authentication.</p><p>This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 7.5 (HIGH); EPSS percentile 20; sources: NVD.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71234/" target="_blank" rel="noopener noreferrer">CVE-2026-71234</a> <span class="severity-pill high">HIGH</span> <span>CVSS 7.5</span> <span>-</span><p>NVD: Documize Community&#x27;s attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a query parameter and grants access whenever the parameter is simply non-empty (len(secureToken) &gt; 0)...</p><p>This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 7.5 (HIGH); EPSS percentile 16; sources: NVD.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71232/" target="_blank" rel="noopener noreferrer">CVE-2026-71232</a> <span class="severity-pill high">HIGH</span> <span>CVSS 7.2</span> <span>-</span><p>NVD: MacCMS10&#x27;s admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function... OSV: MacCMS10 - Incomplete Function Blacklist in Template Editor Enables Authenticated RCE OSV: MacCMS10&#x27;s admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function...</p><p>An attacker may be able to run code or commands on affected systems; CVSS 7.2 (HIGH); EPSS percentile 22; sources: NVD, OSV.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71244/" target="_blank" rel="noopener noreferrer">CVE-2026-71244</a> <span class="severity-pill medium">MEDIUM</span> <span>CVSS 6.5</span> <span>-</span><p>NVD: Paperless-ngx&#x27;s MailAccountViewSet.test action, when called with an existing account&#x27;s ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a...</p><p>This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 6.5 (MEDIUM); EPSS percentile 10; sources: NVD.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14574/" target="_blank" rel="noopener noreferrer">CVE-2026-14574</a> <span class="severity-pill medium">MEDIUM</span> <span>CVSS 5.7</span> <span>eclipse / theia</span><p>NVD: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype). NVD: Because this function is invoked by PreferenceServiceImpl.doResolve for every preference resolution across scopes (default, user, workspace, folder), a crafted preference value in a workspace settings file (.theia/settings.json or .vscode/settings.json) can... OSV: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype).</p><p>This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.7 (MEDIUM); EPSS percentile 20; affected product context: eclipse / theia; sources: NVD, OSV, Vendor Advisory.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14304/" target="_blank" rel="noopener noreferrer">CVE-2026-14304</a> <span class="severity-pill medium">MEDIUM</span> <span>CVSS 4.6</span> <span>eclipse / accessibility_tools_framework</span><p>NVD: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. NVD: If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker. OSV: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists.</p><p>An attacker may cross a privilege boundary and gain more access than intended; CVSS 4.6 (MEDIUM); EPSS percentile 7; affected product context: eclipse / accessibility_tools_framework; sources: NVD, OSV, Vendor Advisory.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71240/" target="_blank" rel="noopener noreferrer">CVE-2026-71240</a> <span class="severity-pill medium">MEDIUM</span> <span>CVSS 4.3</span> <span>-</span><p>NVD: DjangoCRM&#x27;s toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or staff_member_required, and it redirects to a caller-supplied next_url GET parameter after only checking secure_url(next_url), which merely...</p><p>This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 4.3 (MEDIUM); EPSS percentile 9; sources: NVD.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17578/" target="_blank" rel="noopener noreferrer">CVE-2026-17578</a> <span class="severity-pill low">LOW</span> <span>CVSS 2.3</span> <span>-</span><p>NVD: Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled. NVD: If a producer sends messages at a sustained high rate without key rotation, which only occurs on reboot of the Kong Event Gateway instance, the probability of a nonce collision becomes non-negligible. NVD: An authorized consumer who detects a nonce collision can recover parts of plaintext from the affected messages.</p><p>This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 2.3 (LOW); EPSS percentile 5; sources: NVD.</p></li></ul></div></noscript><div id="empty-state" class="empty-state" tabindex="-1" hidden></div><div class="feed-legend"><span class="severity-legend"><span class="critical-dot"></span>Critical <span class="high-dot"></span>High <span class="medium-dot"></span>Medium <span class="low-dot"></span>Low <span class="badge mini">KEV</span>Known Exploited <span class="badge mini blue">NEW</span>Newly Observed</span><span class="feed-shortcut-controls"><span class="keyboard-hint">J / K Move · ↑ / ↓ Move · Enter Open · Esc Close</span><button id="keyboard-shortcuts-toggle" class="keyboard-shortcuts-toggle" type="button" aria-pressed="true">Shortcuts ON</button></span></div></div>
<aside class="panel priority-panel view-panel" data-view="dashboard signals"><div class="panel-head"><h2>Top Risks <span>(Priority Queue)</span></h2><a href="#signals" data-view-link="signals">View all →</a></div><div id="priority-queue"><button class="risk-row" type="button" data-open-detail="CVE-2026-71237" data-signal-id="CVE-2026-71237" data-focus-role="priority" aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="Priority 1, CVE-2026-71237, CRITICAL, score 98, open detail"><span class="rank">1</span><span><strong>CVE-2026-71237</strong><small>-</small><small>CRITICAL CVSS · official reference present</small></span><span class="score-bar"><i class="bar-fill bar-w-98"></i><em>98</em></span></button><button class="risk-row" type="button" data-open-detail="CVE-2026-71231" data-signal-id="CVE-2026-71231" data-focus-role="priority" aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="Priority 2, CVE-2026-71231, CRITICAL, score 98, open detail"><span class="rank">2</span><span><strong>CVE-2026-71231</strong><small>-</small><small>CRITICAL CVSS · official reference present</small></span><span class="score-bar"><i class="bar-fill bar-w-98"></i><em>98</em></span></button><button class="risk-row" type="button" data-open-detail="CVE-2026-66747" data-signal-id="CVE-2026-66747" data-focus-role="priority" aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="Priority 3, CVE-2026-66747, CRITICAL, score 93, open detail"><span class="rank">3</span><span><strong>CVE-2026-66747</strong><small>-</small><small>CRITICAL CVSS · official reference present</small></span><span class="score-bar"><i class="bar-fill bar-w-93"></i><em>93</em></span></button><button class="risk-row" type="button" data-open-detail="CVE-2026-71238" data-signal-id="CVE-2026-71238" data-focus-role="priority" aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="Priority 4, CVE-2026-71238, CRITICAL, score 91, open detail"><span class="rank">4</span><span><strong>CVE-2026-71238</strong><small>-</small><small>CRITICAL CVSS · official reference present</small></span><span class="score-bar"><i class="bar-fill bar-w-91"></i><em>91</em></span></button><button class="risk-row" type="button" data-open-detail="CVE-2026-60009" data-signal-id="CVE-2026-60009" data-focus-role="priority" aria-haspopup="dialog" aria-controls="detail-drawer" aria-expanded="false" aria-label="Priority 5, CVE-2026-60009, HIGH, score 88, open detail"><span class="rank">5</span><span><strong>CVE-2026-60009</strong><small>eclipse / theia</small><small>HIGH CVSS · official reference present</small></span><span class="score-bar"><i class="bar-fill bar-w-88"></i><em>88</em></span></button></div></aside>
</section>
<section class="agent-surface-grid view-panel" data-view="dashboard sources"><article class="panel agent-panel"><div class="panel-head"><h2>Agent Access <span>Agent Data Surface</span></h2></div><p class="muted">Read-only static JSON for humans and AI agents. This is a data contract, not an execution surface.</p><div class="agent-link-grid"><a href="/archive/" target="_blank" rel="noopener noreferrer">Human Archive</a><a href="/data/v1/priority-queue.json" target="_blank" rel="noopener noreferrer">Priority Queue JSON</a><a href="/data/v1/diff/latest.json" target="_blank" rel="noopener noreferrer">Latest Diff Feed</a><a href="/data/v1/graph/latest.jsonld" target="_blank" rel="noopener noreferrer">Knowledge Graph</a><a href="/.well-known/rirastafab-trust.json" target="_blank" rel="noopener noreferrer">Trust Layer</a><a href="/data/v1/proof/latest.json" target="_blank" rel="noopener noreferrer">Proof Metadata</a><a href="/data/v1/proof/canonical-policy.json" target="_blank" rel="noopener noreferrer">Canonical Policy</a><a href="/data/v1/proof/canonical-envelope.json" target="_blank" rel="noopener noreferrer">Canonical Envelope</a><a href="/data/v1/proof/canonical-envelope-index.json" target="_blank" rel="noopener noreferrer">Envelope Index</a><a href="/data/v1/proof/eas-typed-payload.json" target="_blank" rel="noopener noreferrer">EAS Typed Payload</a><a href="/data/v1/attestations/vuln-signal-ledger.json" target="_blank" rel="noopener noreferrer">Attestation Ledger</a><a href="https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71237.json" target="_blank" rel="noopener noreferrer">Signal Item JSON</a><a href="/data/v1/remediation-handoff/index.json" target="_blank" rel="noopener noreferrer">Remediation Handoff</a><a href="/agent.json" target="_blank" rel="noopener noreferrer">Agent Manifest</a><a href="/.well-known/signal-radar.json" target="_blank" rel="noopener noreferrer">Static Manifest</a><a href="/data/v1/schema/signal-item.schema.json" target="_blank" rel="noopener noreferrer">Schema</a></div><div class="trust-card-grid"><span><strong>Knowledge Graph / JSON-LD</strong><em>links CVE signals, sources, affected products, and provenance</em></span><span><strong>Local-first Vault</strong><em>browser-only personal review context; import/export/clear supported</em></span><span><strong>RirastaFab Trust Layer</strong><em>hash-only integrity metadata, canonical envelopes, and proof endpoints</em></span><span><strong>Canonical Envelope</strong><em>attestation-ready preflight metadata without onchain submission</em></span></div><p class="muted compact-copy">Agents should start with /agent.json, validate the signal item schema, use the JSON-LD graph for provenance, and treat the Local Vault as private browser state that is never uploaded.</p><div class="agent-rule-grid"><span><strong>WebMCP read-only tools</strong>Enabled</span><span><strong>Runtime server endpoints</strong>None</span><span><strong>Static agent JSON</strong>Enabled</span></div><div class="agent-rule-row"><strong>Allowed</strong><span>search / list / get / summarize / prioritize</span></div><div class="agent-rule-row disabled"><strong>Disabled</strong><span>scan / patch / exploit / external execution / auto remediation</span></div><p class="timestamp-note">Last generated: 2026-08-12 10:39 UTC / 2026-08-12 19:39 JST. Observed dates are per-source signal timestamps.</p></article><article class="panel agent-panel agent-insight-panel" data-agent-insight-stack><section class="agent-insight-section diff-panel"><div class="panel-head"><h2>Latest Changes <span>Diff Feed</span></h2></div><div class="diff-mode"><strong>previous successful latest</strong><span>public snapshot comparison</span></div><p class="muted">40 public-safe changes since the previous successful snapshot.</p><div class="diff-count-grid" aria-label="Latest diff summary"><div><span>Added</span><strong>20</strong></div><div><span>Changed</span><strong>0</strong></div><div><span>Removed</span><strong>20</strong></div></div><div class="diff-change-notes" aria-label="What changed"><strong>What changed</strong><ul><li>CVE-2026-12609: newly added to the public-safe set.</li><li>CVE-2026-14304: newly added to the public-safe set.</li><li>CVE-2026-14574: newly added to the public-safe set.</li><li>37 more public-safe changes in the JSON feed.</li></ul></div><div class="fresh-row"><span>Previous snapshot</span><strong>2026-08-12 05:14 UTC / 2026-08-12 14:14 JST</strong></div><div class="fresh-row"><span>Items compared</span><strong>20 -> 20</strong></div><div class="fresh-row"><span>Feed generated</span><strong>2026-08-12 10:39 UTC / 2026-08-12 19:39 JST</strong></div><a class="inline-data-link" href="/data/v1/diff/latest.json" target="_blank" rel="noopener noreferrer">Open latest diff feed</a></section><section class="agent-insight-section enrichment-panel"><div class="panel-head"><h2>Enrichment Coverage <span>partial</span></h2></div><p class="muted">Coverage is shown from the current public dataset. CPE, PURL, and canonical vendor/product are partial and may be unknown.</p><div class="coverage-source-grid"><div><span>NVD</span><strong>20</strong></div><div><span>Vendor Advisory</span><strong>20</strong></div><div><span>OSV</span><strong>7</strong></div><div><span>CISA KEV</span><strong>0</strong></div></div><div class="coverage-partial-grid"><div><span>Affected products</span><strong>5</strong><em>partial</em></div><div><span>CPE</span><strong>5</strong><em>partial</em></div><div><span>PURL</span><strong>0</strong><em>partial</em></div><div><span>Canonical vendor/product</span><strong>5</strong><em>partial</em></div></div></section></article></section>
<section class="analytics-grid view-panel" data-view="dashboard"><div class="panel chart-panel"><h2>Observed Buckets <span>(current snapshot)</span></h2><div id="risk-trend"><p class="snapshot-note compact"><img src="/assets/vuln/empty-report.svg" alt="" aria-hidden="true">Current snapshot only. Historical trend appears after multiple generated runs.</p><div><span>2026-08-12</span><strong><i class="bar-fill bar-w-100"></i></strong><em>20</em></div></div></div><div class="panel chart-panel"><h2>Severity Distribution</h2><div id="severity-distribution"><div class="donut" data-label="Total 20"><svg viewBox="0 0 42 42" aria-hidden="true"><circle class="donut-bg" cx="21" cy="21" r="15.9155"></circle><circle class="donut-segment donut-critical" cx="21" cy="21" r="15.9155" pathLength="100" stroke-dasharray="20.00 80.00" stroke-dashoffset="-0.00"></circle><circle class="donut-segment donut-high" cx="21" cy="21" r="15.9155" pathLength="100" stroke-dasharray="55.00 45.00" stroke-dashoffset="-20.00"></circle><circle class="donut-segment donut-medium" cx="21" cy="21" r="15.9155" pathLength="100" stroke-dasharray="20.00 80.00" stroke-dashoffset="-75.00"></circle><circle class="donut-segment donut-low" cx="21" cy="21" r="15.9155" pathLength="100" stroke-dasharray="5.00 95.00" stroke-dashoffset="-95.00"></circle></svg></div><ul><li><span class="legend-dot critical"></span>CRITICAL <strong>4</strong></li><li><span class="legend-dot high"></span>HIGH <strong>11</strong></li><li><span class="legend-dot medium"></span>MEDIUM <strong>4</strong></li><li><span class="legend-dot low"></span>LOW <strong>1</strong></li><li><span class="legend-dot none"></span>NONE <strong>0</strong></li><li><span class="legend-dot unknown"></span>UNKNOWN <strong>0</strong></li></ul></div></div><div class="panel chart-panel signal-map"><h2>Source Distribution <span>(current snapshot)</span></h2><div id="activity-map"><div class="region-bars source-bars"><div><span>NVD</span><strong><i class="bar-fill bar-w-100"></i></strong><em>20</em></div><div><span>Vendor Advisory</span><strong><i class="bar-fill bar-w-100"></i></strong><em>20</em></div><div><span>OSV</span><strong><i class="bar-fill bar-w-35"></i></strong><em>7</em></div></div></div></div></section>
<section class="panel vendor-panel view-panel" data-view="dashboard sources"><div class="panel-head"><h2>Monitored Vendors</h2><a href="#sources" data-view-link="sources">View all vendors →</a></div><p class="muted vendor-note">Vendor distribution from the current public snapshot. Neutral badges are not official vendor logos.</p><div id="vendor-cards" class="vendor-cards"><button class="vendor-card" data-vendor="Unspecified vendor" type="button"><span class="vendor-logo"><img src="/assets/vuln/vendor-generic.svg" alt="" aria-hidden="true"></span><strong>Unspecified vendor</strong><small>16 CVEs</small><em>snapshot</em></button><button class="vendor-card" data-vendor="eclipse" type="button"><span class="vendor-logo"><img src="/assets/vuln/vendor-generic.svg" alt="" aria-hidden="true"></span><strong>eclipse</strong><small>4 CVEs</small><em>snapshot</em></button></div></section>
<section class="panel utility-view local-vault-panel view-panel" id="watchlist" data-view="watchlist"><h2 id="watchlist-heading" tabindex="-1">Local-first Personal Data Vault</h2><p class="muted">A browser-only vault for human review context. It stores vendor / product / package / CPE prefix / saved signals / muted signals / preferences in localStorage, supports import/export/clear, validates shape on import, and never uploads data.</p><div class="vault-form" aria-label="Local vault watch fields"><input id="vault-vendor" placeholder="Vendor" aria-label="Vault vendor"><input id="vault-product" placeholder="Product" aria-label="Vault product"><input id="vault-package" placeholder="Package" aria-label="Vault package"><input id="vault-cpe" placeholder="CPE prefix" aria-label="Vault CPE prefix"><button id="vault-add" type="button">Add</button></div><div class="vault-actions" role="group" aria-label="Local vault actions"><button id="vault-export" type="button">Export Vault JSON</button><label class="vault-import-label" for="vault-import">Import Vault JSON</label><input id="vault-import" type="file" accept="application/json,.json"><button id="vault-clear" type="button">Clear Vault</button></div><div id="vault-summary" class="vault-summary"></div><div id="watchlist-view"><p id="watchlist-empty" class="empty-copy" tabindex="-1"><img src="/assets/vuln/empty-watchlist.svg" alt="" aria-hidden="true">No watched signals yet. Use the heart control on a signal row to add one.</p></div></section>
<section class="panel utility-view view-panel" id="saved" data-view="saved"><h2 id="saved-views-heading" tabindex="-1">Saved Views</h2><p class="muted">Save and reapply local filter sets. Nothing is uploaded.</p><div class="save-view-row"><input id="saved-view-name" placeholder="View name" aria-label="Saved view name"><button data-save-view type="button">Save current view</button></div><div id="saved-views"><p id="saved-views-empty" class="empty-copy" tabindex="-1">No saved views. Enter a name and save the current filters.</p></div></section>
<section class="panel utility-view view-panel" id="reports" data-view="reports"><h2>Read-only Triage Report Preview</h2><p class="muted">Generated from the current filters. Defensive checklist only; no exploit or scanning detail.</p><div class="export-actions" role="group" aria-label="Export report"><button id="export-json" type="button">Export JSON</button><span class="button-gap" aria-hidden="true"></span><button id="export-csv" type="button">Export CSV</button></div><div id="report-summary" class="report-summary"><article><span>Filtered signals</span><strong>20</strong></article><article><span>Top priority candidate</span><strong>CVE-2026-71237</strong></article><article><span>Critical / High</span><strong>4 / 11</strong></article><article><span>Safety mode</span><strong>read-only, public indexable, public-safe</strong></article></div><details class="raw-json-details"><summary>Raw JSON details</summary><pre id="report-preview">{
  &quot;count&quot;: 20,
  &quot;defensive_checklist&quot;: [
    &quot;Confirm affected products&quot;,
    &quot;Review official source references&quot;,
    &quot;Prioritize KEV, critical CVSS, and high EPSS percentile items&quot;,
    &quot;Record human confirmation&quot;
  ],
  &quot;mode&quot;: &quot;read_only_public_beta_dashboard&quot;,
  &quot;safety&quot;: {
    &quot;procedural_detail&quot;: false,
    &quot;public_launch&quot;: true,
    &quot;scanner_execution&quot;: false
  },
  &quot;severity_distribution&quot;: {
    &quot;CRITICAL&quot;: 4,
    &quot;HIGH&quot;: 11,
    &quot;LOW&quot;: 1,
    &quot;MEDIUM&quot;: 4,
    &quot;NONE&quot;: 0,
    &quot;UNKNOWN&quot;: 0
  },
  &quot;top_risk&quot;: &quot;CVE-2026-71237&quot;
}</pre></details></section>
<section class="panel utility-view view-panel" id="sources" data-view="sources"><h2>Source Status</h2><div id="source-status" class="source-status-grid"><article><strong>NVD</strong><span>20 signals</span><small>Last observed: 2026-08-12</small><small>Status: healthy</small></article><article><strong>EPSS</strong><span>20 signals</span><small>Last observed: 2026-08-12</small><small>Status: healthy</small></article><article><strong>OSV</strong><span>7 signals</span><small>Last observed: 2026-08-12</small><small>Status: healthy</small></article><article><strong>CISA KEV</strong><span>0 signals</span><small>Last observed: 2026-08-12</small><small>Status: not observed</small></article><article><strong>Vendor Advisory</strong><span>20 signals</span><small>Last observed: 2026-08-12</small><small>Status: observed</small></article></div></section>
<section class="panel utility-view view-panel" id="settings" data-view="settings"><h2>Safety Guardrails</h2><div class="settings-grid"><div class="setting-card read-only"><i aria-hidden="true"></i><strong>Public indexing</strong><span>Enabled</span></div><div class="setting-card read-only"><i aria-hidden="true"></i><strong>Read-only surface</strong><span>Enabled</span></div><div class="setting-card locked"><i aria-hidden="true"></i><strong>Deploy controls</strong><span>Codex managed deploy only</span></div><div class="setting-card disabled"><i aria-hidden="true"></i><strong>External notification</strong><span>Disabled</span></div><div class="setting-card disabled"><i aria-hidden="true"></i><strong>Auto remediation</strong><span>Disabled</span></div><div class="setting-card read-only"><i aria-hidden="true"></i><strong>Runtime server endpoints</strong><span>None</span></div><div class="setting-card read-only"><i aria-hidden="true"></i><strong>WebMCP read-only tools</strong><span>Enabled</span></div><div class="setting-card read-only"><i aria-hidden="true"></i><strong>Static agent JSON</strong><span>Enabled</span></div></div></section>
</main>
</div>
<footer class="status-footer"><span class="status-footer__brand">© 2026 <a class="console-roll-link" href="https://signal-radar.com/" data-console-roll-link target="_blank" rel="noopener noreferrer"><span class="console-roll-link__wash" aria-hidden="true"></span><span class="console-roll-link__bracket console-roll-link__bracket--left" aria-hidden="true">[</span><span class="console-roll-link__clip"><span class="console-roll-link__label" data-scramble-text>Signal-Radar.com</span></span><span class="console-roll-link__bracket console-roll-link__bracket--right" aria-hidden="true">]</span></a></span><a class="console-roll-link" href="/about/" data-console-roll-link><span class="console-roll-link__wash" aria-hidden="true"></span><span class="console-roll-link__bracket console-roll-link__bracket--left" aria-hidden="true">[</span><span class="console-roll-link__clip"><span class="console-roll-link__label" data-scramble-text>About</span></span><span class="console-roll-link__bracket console-roll-link__bracket--right" aria-hidden="true">]</span></a><a class="console-roll-link" href="/about/#contact" data-console-roll-link><span class="console-roll-link__wash" aria-hidden="true"></span><span class="console-roll-link__bracket console-roll-link__bracket--left" aria-hidden="true">[</span><span class="console-roll-link__clip"><span class="console-roll-link__label" data-scramble-text>Contact</span></span><span class="console-roll-link__bracket console-roll-link__bracket--right" aria-hidden="true">]</span></a><a class="console-roll-link" href="/about/#data-policy" data-console-roll-link><span class="console-roll-link__wash" aria-hidden="true"></span><span class="console-roll-link__bracket console-roll-link__bracket--left" aria-hidden="true">[</span><span class="console-roll-link__clip"><span class="console-roll-link__label" data-scramble-text>Data Policy</span></span><span class="console-roll-link__bracket console-roll-link__bracket--right" aria-hidden="true">]</span></a><a class="console-roll-link" href="#sources" data-console-roll-link data-view-link="sources"><span class="console-roll-link__wash" aria-hidden="true"></span><span class="console-roll-link__bracket console-roll-link__bracket--left" aria-hidden="true">[</span><span class="console-roll-link__clip"><span class="console-roll-link__label" data-scramble-text>Data sources</span></span><span class="console-roll-link__bracket console-roll-link__bracket--right" aria-hidden="true">]</span></a><a class="console-roll-link" href="#reports" data-console-roll-link data-view-link="reports"><span class="console-roll-link__wash" aria-hidden="true"></span><span class="console-roll-link__bracket console-roll-link__bracket--left" aria-hidden="true">[</span><span class="console-roll-link__clip"><span class="console-roll-link__label" data-scramble-text>Report preview</span></span><span class="console-roll-link__bracket console-roll-link__bracket--right" aria-hidden="true">]</span></a><a class="console-roll-link" href="#settings" data-console-roll-link data-view-link="settings"><span class="console-roll-link__wash" aria-hidden="true"></span><span class="console-roll-link__bracket console-roll-link__bracket--left" aria-hidden="true">[</span><span class="console-roll-link__clip"><span class="console-roll-link__label" data-scramble-text>Guardrails</span></span><span class="console-roll-link__bracket console-roll-link__bracket--right" aria-hidden="true">]</span></a><span><span class="live-dot"></span>Data sources: <strong id="source-count">3</strong></span><span>Times: UTC / JST</span></footer>
<aside class="detail-drawer" id="detail-drawer" role="dialog" aria-modal="true" aria-hidden="true" aria-labelledby="detail-drawer-title"><div id="drawer-content"></div></aside>
</div>
<template id="vuln-fallback-data">{"index": {"archive": {"append_only": true, "archive_index_url": "https://vuln.signal-radar.com/data/vuln/archive/index.json", "archive_latest_url": "https://vuln.signal-radar.com/data/vuln/archive/latest.json", "archive_version": "v0.1", "archived_cve_count": 2357, "item_count": 20, "latest_run_id": "20260812T103932Z", "latest_run_index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/index.json", "latest_run_manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/manifest.json", "public_archive_cve_page_count": 2357, "public_archive_url": "https://vuln.signal-radar.com/archive/", "timeline_count": 2357, "webmcp_future_contract": {"annotations": {"readOnlyHint": true, "untrustedContentHint": true}, "api": "document.modelContext", "auto_remediation_allowed": false, "cross_origin_exposure_allowed": false, "deploy_allowed": false, "enabled": true, "endpoint": null, "exposed_to": [], "external_execution_allowed": false, "fallback_api": "navigator.modelContext", "fetch_allowed": false, "github_issue_creation_allowed": false, "mode": "browser_imperative_progressive_enhancement", "mutation_allowed": false, "notes": "Browser WebMCP tools are registered only when document.modelContext or navigator.modelContext is available. They read existing public-safe static JSON and perform no network fetch, deploy, scan, patch, or mutation.", "planned": false, "scan_allowed": false, "tool_output_max_items": 10, "tool_output_target_max_chars": 1500, "tools": ["vuln_signal_search", "vuln_signal_get_item", "vuln_signal_list_priority"]}}, "archive_index_url": "https://vuln.signal-radar.com/data/vuln/archive/index.json", "archive_latest_url": "https://vuln.signal-radar.com/data/vuln/archive/latest.json", "auto_remediation_allowed": false, "automated_public_launch_generation": true, "automated_publication_mode": true, "automated_publication_mode_deprecated": "public launch is complete; static generation remains read-only and safety-gated", "external_execution_allowed": false, "generated_at": "2026-08-12T10:39:32.977657+00:00", "human_review": {"required_for_external_action": true, "required_for_public_launch": false, "required_for_read_only_view": false, "required_for_signal_radar_integration": true}, "human_review_required": false, "indexing_allowed": true, "items": [{"affected_label": "eclipse / theia", "affected_products": [{"canonicalProduct": "theia", "canonicalVendor": "eclipse", "cpe": "cpe:2.3:a:eclipse:theia:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "theia", "purl": null, "vendor": "eclipse", "version": null}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12609/", "cvss_score": 7.5, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-12609.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.3374, "epss_score": 0.00409, "exposure_hint": "remote exposure", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.", "human_impact_label": "remote exposure", "human_risk_summary": "CVE-2026-12609 for eclipse / theia: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.", "id": "CVE-2026-12609", "impact_tags": ["remote exposure relevant"], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": "theia", "public_human_impact": "Source describes remote exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.", "public_human_summary": "NVD: In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the @theia/plugin-ext backend exposes the /hostedPlugin/:pluginId/:path(*) HTTP endpoint, which resolves the requested file path with path.resolve(localPath, filePath) without verifying that the... NVD: An unauthenticated network attacker can send percent-encoded ../ sequences (%2e%2e%2f) that decode into the path parameter and escape the plugin directory, allowing arbitrary files readable by the Theia backend process to be retrieved. NVD: Plugin IDs are derived deterministically from a plugin's publisher and name, so built-in plugins serve as reliable anchors that require no prior knowledge of the target system.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes remote exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.; CVSS 7.5 (HIGH); EPSS percentile 34; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV, Vendor Advisory.", "public_safe_summary": "NVD: In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the @theia/plugin-ext backend exposes the /hostedPlugin/:pluginId/:path(*) HTTP endpoint, which resolves the requested file path with path.resolve(localPath, filePath) without verifying that the... NVD: An unauthenticated network attacker can send percent-encoded ../ sequences (%2e%2e%2f) that decode into the path parameter and escape the plugin directory, allowing arbitrary files readable by the Theia backend process to be retrieved. NVD: Plugin IDs are derived deterministically from a plugin's publisher and name, so built-in plugins serve as reliable anchors that require no prior knowledge of the target system.", "public_status": "public_safe", "published_at": "2026-08-05T11:16:24.080", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-12609-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-12609.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-12609.md", "scan_allowed": false}, "remediation_urls": ["https://github.com/eclipse-theia/theia/security/advisories/GHSA-qmm6-p8q4-2g48", "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/133", "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/524"], "sort_priority": 75.3374, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "vendor/product: eclipse / theia", "source_published_description": "NVD: In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the @theia/plugin-ext backend exposes the /hostedPlugin/:pluginId/:path(*) HTTP endpoint, which resolves the requested file path with path.resolve(localPath, filePath) without verifying that the... NVD: An unauthenticated network attacker can send percent-encoded ../ sequences (%2e%2e%2f) that decode into the path parameter and escape the plugin directory, allowing arbitrary files readable by the Theia backend process to be retrieved. NVD: Plugin IDs are derived deterministically from a plugin's publisher and name, so built-in plugins serve as reliable anchors that require no prior knowledge of the target system.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/eclipse-theia/theia/security/advisories/GHSA-qmm6-p8q4-2g48"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/133"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/524"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12609"}, {"source": "Official Reference", "type": "reference", "url": "https://osv.dev/vulnerability/CVE-2026-12609"}], "source_published_impact": "Source describes remote exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the @theia/plugin-ext backend exposes the /hostedPlugin/:pluginId/:path(*) HTTP endpoint, which resolves the requested file path with path.resolve(localPath, filePath) without verifying that the... NVD: An unauthenticated network attacker can send percent-encoded ../ sequences (%2e%2e%2f) that decode into the path parameter and escape the plugin directory, allowing arbitrary files readable by the Theia backend process to be retrieved. NVD: Plugin IDs are derived deterministically from a plugin's publisher and name, so built-in plugins serve as reliable anchors that require no prior knowledge of the target system.", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2026-12609 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 7.5. EPSS score is 0.0041 with percentile 0.3374. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-12609 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 7.5, "disclosure_freshness": 0.9613, "epss_percentile": 0.3374, "epss_score": 0.00409, "evidence_confidence": 1.0, "fallbacks": [], "group_key": "canonical_vendor:eclipse", "group_label": "eclipse", "id": "cve:CVE-2026-12609", "kev": false, "kev_date_added": null, "last_modified": "2026-08-07T20:23:46.517000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 33.74, "priority_area": 75.3374, "published_at": "2026-08-05T11:16:24.080000Z", "remediation_reference_count": 3, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 6}, "updated_at": "2026-08-07T20:23:46.517", "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "eclipse", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure; CVSS 7.5 (HIGH); EPSS percentile 34; affected product context: eclipse / theia; sources: NVD, OSV, Vendor Advisory."}, {"affected_label": "eclipse / accessibility_tools_framework", "affected_products": [{"canonicalProduct": "accessibility_tools_framework", "canonicalVendor": "eclipse", "cpe": "cpe:2.3:a:eclipse:accessibility_tools_framework:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "accessibility_tools_framework", "purl": null, "vendor": "eclipse", "version": null}, {"canonicalProduct": "michecker", "canonicalVendor": "soumu", "cpe": "cpe:2.3:a:soumu:michecker:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "michecker", "purl": null, "vendor": "soumu", "version": null}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14304/", "cvss_score": 4.6, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-14304.json", "defensive_priority": "Routine monitoring candidate", "epss_percentile": 0.06863, "epss_score": 0.00172, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may cross a privilege boundary and gain more access than intended.", "human_impact_label": "privilege escalation risk", "human_risk_summary": "CVE-2026-14304 for eclipse / accessibility_tools_framework: An attacker may cross a privilege boundary and gain more access than intended.", "id": "CVE-2026-14304", "impact_tags": ["privilege boundary review"], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": "accessibility_tools_framework", "public_human_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.", "public_human_summary": "NVD: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. NVD: If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker. OSV: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.; CVSS 4.6 (MEDIUM); EPSS percentile 7; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV, Vendor Advisory.", "public_safe_summary": "NVD: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. NVD: If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker. OSV: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists.", "public_status": "public_safe", "published_at": "2026-08-05T11:16:24.887", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14304-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14304.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14304.md", "scan_allowed": false}, "remediation_urls": ["https://eclipse.dev/actf/downloads/tools/miChecker/vulnerability.html", "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/151"], "sort_priority": 46.06863, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "vendor/product: eclipse / accessibility_tools_framework", "source_published_description": "NVD: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. NVD: If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker. OSV: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "reference", "url": "https://eclipse.dev/actf/downloads/tools/miChecker/vulnerability.html"}, {"source": "Reference", "type": "reference", "url": "https://github.com/eclipse-actf/org.eclipse.actf"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/151"}, {"source": "Reference", "type": "reference", "url": "https://www.soumu.go.jp/info-accessibility-portal/webaccessibility/michecker/"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14304"}, {"source": "Official Reference", "type": "reference", "url": "https://osv.dev/vulnerability/CVE-2026-14304"}], "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. NVD: If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker. OSV: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists.", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2026-14304 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 4.6. EPSS score is 0.0017 with percentile 0.0686. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-14304 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 4.6, "disclosure_freshness": 0.9613, "epss_percentile": 0.06863, "epss_score": 0.00172, "evidence_confidence": 1.0, "fallbacks": [], "group_key": "canonical_vendor:eclipse", "group_label": "eclipse", "id": "cve:CVE-2026-14304", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T19:01:10.803000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 6.863, "priority_area": 46.0686, "published_at": "2026-08-05T11:16:24.887000Z", "remediation_reference_count": 2, "schema_version": "vuln-treemap-node-v1", "severity": "medium", "source_count": 6}, "updated_at": "2026-08-10T19:01:10.803", "urgency_reasons": ["affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "eclipse", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may cross a privilege boundary and gain more access than intended; CVSS 4.6 (MEDIUM); EPSS percentile 7; affected product context: eclipse / accessibility_tools_framework; sources: NVD, OSV, Vendor Advisory."}, {"affected_label": "eclipse / theia", "affected_products": [{"canonicalProduct": "theia", "canonicalVendor": "eclipse", "cpe": "cpe:2.3:a:eclipse:theia:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "theia", "purl": null, "vendor": "eclipse", "version": null}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14574/", "cvss_score": 5.7, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-14574.json", "defensive_priority": "Routine monitoring candidate", "epss_percentile": 0.20449, "epss_score": 0.00282, "exposure_hint": "exposure unknown", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "human_impact_label": "defensive exposure review", "human_risk_summary": "CVE-2026-14574 for eclipse / theia: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "id": "CVE-2026-14574", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": "theia", "public_human_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "public_human_summary": "NVD: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype). NVD: Because this function is invoked by PreferenceServiceImpl.doResolve for every preference resolution across scopes (default, user, workspace, folder), a crafted preference value in a workspace settings file (.theia/settings.json or .vscode/settings.json) can... OSV: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype).", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.; CVSS 5.7 (MEDIUM); EPSS percentile 20; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV, Vendor Advisory.", "public_safe_summary": "NVD: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype). NVD: Because this function is invoked by PreferenceServiceImpl.doResolve for every preference resolution across scopes (default, user, workspace, folder), a crafted preference value in a workspace settings file (.theia/settings.json or .vscode/settings.json) can... OSV: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype).", "public_status": "public_safe", "published_at": "2026-08-05T11:16:25.030", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14574-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14574.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14574.md", "scan_allowed": false}, "remediation_urls": ["https://github.com/eclipse-theia/theia/security/advisories/GHSA-f3w9-qfw3-xr32", "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/157", "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/567", "https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/567"], "sort_priority": 57.20449, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "vendor/product: eclipse / theia", "source_published_description": "NVD: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype). NVD: Because this function is invoked by PreferenceServiceImpl.doResolve for every preference resolution across scopes (default, user, workspace, folder), a crafted preference value in a workspace settings file (.theia/settings.json or .vscode/settings.json) can... OSV: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype).", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/eclipse-theia/theia/security/advisories/GHSA-f3w9-qfw3-xr32"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/157"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/567"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/567"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14574"}, {"source": "Official Reference", "type": "reference", "url": "https://osv.dev/vulnerability/CVE-2026-14574"}], "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype). NVD: Because this function is invoked by PreferenceServiceImpl.doResolve for every preference resolution across scopes (default, user, workspace, folder), a crafted preference value in a workspace settings file (.theia/settings.json or .vscode/settings.json) can... OSV: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype).", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2026-14574 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 5.7. EPSS score is 0.0028 with percentile 0.2045. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-14574 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 5.7, "disclosure_freshness": 0.9613, "epss_percentile": 0.20449, "epss_score": 0.00282, "evidence_confidence": 1.0, "fallbacks": [], "group_key": "canonical_vendor:eclipse", "group_label": "eclipse", "id": "cve:CVE-2026-14574", "kev": false, "kev_date_added": null, "last_modified": "2026-08-07T16:02:40.473000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 20.449, "priority_area": 57.2045, "published_at": "2026-08-05T11:16:25.030000Z", "remediation_reference_count": 4, "schema_version": "vuln-treemap-node-v1", "severity": "medium", "source_count": 6}, "updated_at": "2026-08-07T16:02:40.473", "urgency_reasons": ["affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "eclipse", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.7 (MEDIUM); EPSS percentile 20; affected product context: eclipse / theia; sources: NVD, OSV, Vendor Advisory."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17578/", "cvss_score": 2.3, "cvss_severity": "LOW", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-17578.json", "defensive_priority": "Routine monitoring candidate", "epss_percentile": 0.04712, "epss_score": 0.0015, "exposure_hint": "exposure unknown", "human_consequence": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "human_impact_label": "defensive exposure review", "human_risk_summary": "CVE-2026-17578: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "id": "CVE-2026-17578", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "public_human_summary": "NVD: Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled. NVD: If a producer sends messages at a sustained high rate without key rotation, which only occurs on reboot of the Kong Event Gateway instance, the probability of a nonce collision becomes non-negligible. NVD: An authorized consumer who detects a nonce collision can recover parts of plaintext from the affected messages.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.; CVSS 2.3 (LOW); EPSS percentile 5; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled. NVD: If a producer sends messages at a sustained high rate without key rotation, which only occurs on reboot of the Kong Event Gateway instance, the probability of a nonce collision becomes non-negligible. NVD: An authorized consumer who detects a nonce collision can recover parts of plaintext from the affected messages.", "public_status": "public_safe", "published_at": "2026-08-05T11:16:25.197", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-17578-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-17578.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-17578.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-17578"], "sort_priority": 23.04712, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled. NVD: If a producer sends messages at a sustained high rate without key rotation, which only occurs on reboot of the Kong Event Gateway instance, the probability of a nonce collision becomes non-negligible. NVD: An authorized consumer who detects a nonce collision can recover parts of plaintext from the affected messages.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://developer.konghq.com/event-gateway/changelog/"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-17578"}], "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled. NVD: If a producer sends messages at a sustained high rate without key rotation, which only occurs on reboot of the Kong Event Gateway instance, the probability of a nonce collision becomes non-negligible. NVD: An authorized consumer who detects a nonce collision can recover parts of plaintext from the affected messages.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-17578 is a defensive prioritization candidate. NVD lists CVSS severity as LOW. CVSS score is 2.3. EPSS score is 0.0015 with percentile 0.0471. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-17578 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 2.3, "disclosure_freshness": 0.9613, "epss_percentile": 0.04712, "epss_score": 0.0015, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-17578", "kev": false, "kev_date_added": null, "last_modified": "2026-08-05T14:17:04.187000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 6.0, "priority_area": 23.0471, "published_at": "2026-08-05T11:16:25.197000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "low", "source_count": 2}, "updated_at": "2026-08-05T14:17:04.187", "urgency_reasons": ["vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 2.3 (LOW); EPSS percentile 5; sources: NVD."}, {"affected_label": "eclipse / theia", "affected_products": [{"canonicalProduct": "theia", "canonicalVendor": "eclipse", "cpe": "cpe:2.3:a:eclipse:theia:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "theia", "purl": null, "vendor": "eclipse", "version": null}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60009/", "cvss_score": 8.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-60009.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.24854, "epss_score": 0.00323, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may be able to run code or commands on affected systems.", "human_impact_label": "code execution review", "human_risk_summary": "CVE-2026-60009 for eclipse / theia: An attacker may be able to run code or commands on affected systems.", "id": "CVE-2026-60009", "impact_tags": ["code execution review"], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": "theia", "public_human_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.", "public_human_summary": "NVD: In Eclipse Theia versions up to and including 1.73.1, the @theia/filesystem backend binds POST /file-upload in every filesystem-enabled deployment. NVD: The handler takes an attacker-supplied absolute path from the multipart uri field and calls fs.move(tmp, target, { overwrite: true }) with no workspace confinement and no authentication. NVD: In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in @theia/core re-issues the cookie and calls next() without rejecting tokenless HTTP requests.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.; CVSS 8.8 (HIGH); EPSS percentile 25; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV, Vendor Advisory.", "public_safe_summary": "NVD: In Eclipse Theia versions up to and including 1.73.1, the @theia/filesystem backend binds POST /file-upload in every filesystem-enabled deployment. NVD: The handler takes an attacker-supplied absolute path from the multipart uri field and calls fs.move(tmp, target, { overwrite: true }) with no workspace confinement and no authentication. NVD: In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in @theia/core re-issues the cookie and calls next() without rejecting tokenless HTTP requests.", "public_status": "public_safe", "published_at": "2026-08-05T11:16:25.363", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-60009-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-60009.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-60009.md", "scan_allowed": false}, "remediation_urls": ["https://github.com/eclipse-theia/theia/security/advisories/GHSA-62f6-wcvg-54h3", "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/177", "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/595", "https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/595"], "sort_priority": 88.24854, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "vendor/product: eclipse / theia", "source_published_description": "NVD: In Eclipse Theia versions up to and including 1.73.1, the @theia/filesystem backend binds POST /file-upload in every filesystem-enabled deployment. NVD: The handler takes an attacker-supplied absolute path from the multipart uri field and calls fs.move(tmp, target, { overwrite: true }) with no workspace confinement and no authentication. NVD: In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in @theia/core re-issues the cookie and calls next() without rejecting tokenless HTTP requests.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/eclipse-theia/theia/security/advisories/GHSA-62f6-wcvg-54h3"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/177"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/595"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/595"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-60009"}, {"source": "Official Reference", "type": "reference", "url": "https://osv.dev/vulnerability/CVE-2026-60009"}], "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: In Eclipse Theia versions up to and including 1.73.1, the @theia/filesystem backend binds POST /file-upload in every filesystem-enabled deployment. NVD: The handler takes an attacker-supplied absolute path from the multipart uri field and calls fs.move(tmp, target, { overwrite: true }) with no workspace confinement and no authentication. NVD: In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in @theia/core re-issues the cookie and calls next() without rejecting tokenless HTTP requests.", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2026-60009 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.8. EPSS score is 0.0032 with percentile 0.2485. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-60009 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 8.8, "disclosure_freshness": 0.9613, "epss_percentile": 0.24854, "epss_score": 0.00323, "evidence_confidence": 1.0, "fallbacks": [], "group_key": "canonical_vendor:eclipse", "group_label": "eclipse", "id": "cve:CVE-2026-60009", "kev": false, "kev_date_added": null, "last_modified": "2026-08-07T15:54:02.380000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 24.854, "priority_area": 88.2485, "published_at": "2026-08-05T11:16:25.363000Z", "remediation_reference_count": 4, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 6}, "updated_at": "2026-08-07T15:54:02.380", "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "eclipse", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to run code or commands on affected systems; CVSS 8.8 (HIGH); EPSS percentile 25; affected product context: eclipse / theia; sources: NVD, OSV, Vendor Advisory."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66747/", "cvss_score": 9.3, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-66747.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.44552, "epss_score": 0.00579, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may gain root or administrative-level privileges on affected systems.", "human_impact_label": "code execution review · admin privilege risk", "human_risk_summary": "CVE-2026-66747: An attacker may gain root or administrative-level privileges on affected systems.", "id": "CVE-2026-66747", "impact_tags": ["code execution review", "admin privilege risk"], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "Source describes code execution review · admin privilege risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.", "public_human_summary": "NVD: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. NVD: It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. NVD: It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes code execution review · admin privilege risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.; CVSS 9.3 (CRITICAL); EPSS percentile 45; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. NVD: It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. NVD: It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds.", "public_status": "public_safe", "published_at": "2026-08-05T11:16:25.510", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-66747-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-66747.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-66747.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-66747"], "sort_priority": 93.44552, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. NVD: It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. NVD: It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/ycsunjane/rctl"}, {"source": "Reference", "type": "reference", "url": "https://www.vulncheck.com/advisories/zbt-endlessdoors"}, {"source": "Reference", "type": "reference", "url": "https://www.vulncheck.com/blog/zbt-endlessdoors"}, {"source": "Reference", "type": "reference", "url": "https://www.zbtlink.com/pages/zbt-router-firmware-download"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66747"}], "source_published_impact": "Source describes code execution review · admin privilege risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. NVD: It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. NVD: It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-66747 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.3. EPSS score is 0.0058 with percentile 0.4455. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-66747 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 9.3, "disclosure_freshness": 0.9613, "epss_percentile": 0.44552, "epss_score": 0.00579, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-66747", "kev": false, "kev_date_added": null, "last_modified": "2026-08-05T15:17:04.690000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 44.552, "priority_area": 93.4455, "published_at": "2026-08-05T11:16:25.510000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "critical", "source_count": 2}, "updated_at": "2026-08-05T15:17:04.690", "urgency_reasons": ["CVSS CRITICAL", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may gain root or administrative-level privileges on affected systems; CVSS 9.3 (CRITICAL); EPSS percentile 45; sources: NVD."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71231/", "cvss_score": 9.8, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71231.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.28595, "epss_score": 0.00358, "exposure_hint": "exposure unknown", "human_consequence": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "human_impact_label": "critical severity review", "human_risk_summary": "CVE-2026-71231: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "id": "CVE-2026-71231", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "public_human_summary": "NVD: IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.; CVSS 9.8 (CRITICAL); EPSS percentile 29; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding...", "public_status": "public_safe", "published_at": "2026-08-05T11:16:25.740", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71231-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71231.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71231.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71231"], "sort_priority": 98.28595, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/thebradleysanders/IOTSmartHome"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71231"}], "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding...", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71231 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.8. EPSS score is 0.0036 with percentile 0.2859. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71231 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 9.8, "disclosure_freshness": 0.9613, "epss_percentile": 0.28595, "epss_score": 0.00358, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71231", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:25.533000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 28.595, "priority_area": 98.2859, "published_at": "2026-08-05T11:16:25.740000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "critical", "source_count": 2}, "updated_at": "2026-08-10T12:17:25.533", "urgency_reasons": ["CVSS CRITICAL", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review; CVSS 9.8 (CRITICAL); EPSS percentile 29; sources: NVD."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71232/", "cvss_score": 7.2, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71232.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.22368, "epss_score": 0.003, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may be able to run code or commands on affected systems.", "human_impact_label": "code execution review", "human_risk_summary": "CVE-2026-71232: An attacker may be able to run code or commands on affected systems.", "id": "CVE-2026-71232", "impact_tags": ["code execution review"], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.", "public_human_summary": "NVD: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function... OSV: MacCMS10 - Incomplete Function Blacklist in Template Editor Enables Authenticated RCE OSV: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.; CVSS 7.2 (HIGH); EPSS percentile 22; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV.", "public_safe_summary": "NVD: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function... OSV: MacCMS10 - Incomplete Function Blacklist in Template Editor Enables Authenticated RCE OSV: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function...", "public_status": "public_safe", "published_at": "2026-08-05T11:16:25.873", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71232-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71232.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71232.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71232", "https://osv.dev/vulnerability/CVE-2026-71232"], "sort_priority": 72.22368, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function... OSV: MacCMS10 - Incomplete Function Blacklist in Template Editor Enables Authenticated RCE OSV: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/magicblack/maccms10/commit/71ad3bb29570e110d8e973acff68040a3050ddf0"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71232"}, {"source": "Official Reference", "type": "reference", "url": "https://osv.dev/vulnerability/CVE-2026-71232"}], "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function... OSV: MacCMS10 - Incomplete Function Blacklist in Template Editor Enables Authenticated RCE OSV: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function...", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2026-71232 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 7.2. EPSS score is 0.0030 with percentile 0.2237. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71232 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 7.2, "disclosure_freshness": 0.9613, "epss_percentile": 0.22368, "epss_score": 0.003, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71232", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:25.650000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 22.368, "priority_area": 72.2237, "published_at": "2026-08-05T11:16:25.873000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 4}, "updated_at": "2026-08-10T12:17:25.650", "urgency_reasons": ["CVSS HIGH", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to run code or commands on affected systems; CVSS 7.2 (HIGH); EPSS percentile 22; sources: NVD, OSV."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71233/", "cvss_score": 8.7, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71233.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.0994, "epss_score": 0.00199, "exposure_hint": "exposure unknown", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "human_impact_label": "high severity review", "human_risk_summary": "CVE-2026-71233: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "id": "CVE-2026-71233", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "public_human_summary": "NVD: InvoiceNinja v5-stable renders an invoice or quote's \"terms\" field in the client portal using Laravel Blade's raw output directive {!! NVD: ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.; CVSS 8.7 (HIGH); EPSS percentile 10; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: InvoiceNinja v5-stable renders an invoice or quote's \"terms\" field in the client portal using Laravel Blade's raw output directive {!! NVD: ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization.", "public_status": "public_safe", "published_at": "2026-08-05T11:16:25.997", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71233-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71233.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71233.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71233"], "sort_priority": 87.0994, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: InvoiceNinja v5-stable renders an invoice or quote's \"terms\" field in the client portal using Laravel Blade's raw output directive {!! NVD: ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/invoiceninja/invoiceninja"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71233"}], "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: InvoiceNinja v5-stable renders an invoice or quote's \"terms\" field in the client portal using Laravel Blade's raw output directive {!! NVD: ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71233 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.7. EPSS score is 0.0020 with percentile 0.0994. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71233 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 8.7, "disclosure_freshness": 0.9613, "epss_percentile": 0.0994, "epss_score": 0.00199, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71233", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:25.770000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 9.94, "priority_area": 87.0994, "published_at": "2026-08-05T11:16:25.997000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 2}, "updated_at": "2026-08-10T12:17:25.770", "urgency_reasons": ["CVSS HIGH", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 8.7 (HIGH); EPSS percentile 10; sources: NVD."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71234/", "cvss_score": 7.5, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71234.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.15873, "epss_score": 0.00245, "exposure_hint": "exposure unknown", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "human_impact_label": "high severity review", "human_risk_summary": "CVE-2026-71234: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "id": "CVE-2026-71234", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "public_human_summary": "NVD: Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a query parameter and grants access whenever the parameter is simply non-empty (len(secureToken) > 0)...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.; CVSS 7.5 (HIGH); EPSS percentile 16; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a query parameter and grants access whenever the parameter is simply non-empty (len(secureToken) > 0)...", "public_status": "public_safe", "published_at": "2026-08-05T11:16:26.120", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71234-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71234.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71234.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71234"], "sort_priority": 75.15873, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a query parameter and grants access whenever the parameter is simply non-empty (len(secureToken) > 0)...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/documize/community"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71234"}], "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a query parameter and grants access whenever the parameter is simply non-empty (len(secureToken) > 0)...", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71234 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 7.5. EPSS score is 0.0024 with percentile 0.1587. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71234 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 7.5, "disclosure_freshness": 0.9613, "epss_percentile": 0.15873, "epss_score": 0.00245, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71234", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:25.880000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 15.873, "priority_area": 75.1587, "published_at": "2026-08-05T11:16:26.120000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 2}, "updated_at": "2026-08-10T12:17:25.880", "urgency_reasons": ["CVSS HIGH", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 7.5 (HIGH); EPSS percentile 16; sources: NVD."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71235/", "cvss_score": 8.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71235.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.21126, "epss_score": 0.00288, "exposure_hint": "authenticated boundary", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.", "human_impact_label": "authenticated boundary", "human_risk_summary": "CVE-2026-71235: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.", "id": "CVE-2026-71235", "impact_tags": ["authenticated boundary review"], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.", "public_human_summary": "NVD: Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. NVD: The Lua script engine (re/lua.go) performs no input validation at all and preloads dangerous libraries: db (arbitrary database access), ioutil (file I/O), an HTTP client (SSRF), and filepath (traversal).", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.; CVSS 8.8 (HIGH); EPSS percentile 21; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. NVD: The Lua script engine (re/lua.go) performs no input validation at all and preloads dangerous libraries: db (arbitrary database access), ioutil (file I/O), an HTTP client (SSRF), and filepath (traversal).", "public_status": "public_safe", "published_at": "2026-08-05T11:16:26.247", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71235-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71235.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71235.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71235"], "sort_priority": 88.21126, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. NVD: The Lua script engine (re/lua.go) performs no input validation at all and preloads dangerous libraries: db (arbitrary database access), ioutil (file I/O), an HTTP client (SSRF), and filepath (traversal).", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/absmach/magistrala"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71235"}], "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. NVD: The Lua script engine (re/lua.go) performs no input validation at all and preloads dangerous libraries: db (arbitrary database access), ioutil (file I/O), an HTTP client (SSRF), and filepath (traversal).", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71235 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.8. EPSS score is 0.0029 with percentile 0.2113. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71235 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 8.8, "disclosure_freshness": 0.9613, "epss_percentile": 0.21126, "epss_score": 0.00288, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71235", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:25.983000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 21.126, "priority_area": 88.2113, "published_at": "2026-08-05T11:16:26.247000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 2}, "updated_at": "2026-08-10T12:17:25.983", "urgency_reasons": ["CVSS HIGH", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary; CVSS 8.8 (HIGH); EPSS percentile 21; sources: NVD."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71236/", "cvss_score": 8.7, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71236.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.0994, "epss_score": 0.00199, "exposure_hint": "exposure unknown", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "human_impact_label": "high severity review", "human_risk_summary": "CVE-2026-71236: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "id": "CVE-2026-71236", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "public_human_summary": "NVD: Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HTML-entity encoding of the resulting output by replacing &amp;lt;, &amp;gt;, and...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.; CVSS 8.7 (HIGH); EPSS percentile 10; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HTML-entity encoding of the resulting output by replacing &amp;lt;, &amp;gt;, and...", "public_status": "public_safe", "published_at": "2026-08-05T11:16:26.377", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71236-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71236.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71236.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71236"], "sort_priority": 87.0994, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HTML-entity encoding of the resulting output by replacing &amp;lt;, &amp;gt;, and...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/grocy/grocy"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71236"}], "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HTML-entity encoding of the resulting output by replacing &amp;lt;, &amp;gt;, and...", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71236 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.7. EPSS score is 0.0020 with percentile 0.0994. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71236 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 8.7, "disclosure_freshness": 0.9613, "epss_percentile": 0.0994, "epss_score": 0.00199, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71236", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.090000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 9.94, "priority_area": 87.0994, "published_at": "2026-08-05T11:16:26.377000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 2}, "updated_at": "2026-08-10T12:17:26.090", "urgency_reasons": ["CVSS HIGH", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 8.7 (HIGH); EPSS percentile 10; sources: NVD."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71237/", "cvss_score": 9.8, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71237.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.34766, "epss_score": 0.0042, "exposure_hint": "exposure unknown", "human_consequence": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "human_impact_label": "critical severity review", "human_risk_summary": "CVE-2026-71237: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "id": "CVE-2026-71237", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "public_human_summary": "NVD: Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query(\"select * from userlists where username='' and password='' limit 1\").", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.; CVSS 9.8 (CRITICAL); EPSS percentile 35; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query(\"select * from userlists where username='' and password='' limit 1\").", "public_status": "public_safe", "published_at": "2026-08-05T11:16:26.503", "redaction_notes": ["source-published defensive context retained", "exploit string, command, scanner, or code-like detail removed", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71237-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71237.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71237.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71237"], "sort_priority": 98.34766, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query(\"select * from userlists where username='' and password='' limit 1\").", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/Miantang/IoT-PHP"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71237"}], "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query(\"select * from userlists where username='' and password='' limit 1\").", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71237 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.8. EPSS score is 0.0042 with percentile 0.3477. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71237 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 9.8, "disclosure_freshness": 0.9613, "epss_percentile": 0.34766, "epss_score": 0.0042, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71237", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.197000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 34.766, "priority_area": 98.3477, "published_at": "2026-08-05T11:16:26.503000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "critical", "source_count": 2}, "updated_at": "2026-08-10T12:17:26.197", "urgency_reasons": ["CVSS CRITICAL", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review; CVSS 9.8 (CRITICAL); EPSS percentile 35; sources: NVD."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71238/", "cvss_score": 9.1, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71238.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.23765, "epss_score": 0.00313, "exposure_hint": "exposure unknown", "human_consequence": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "human_impact_label": "critical severity review", "human_risk_summary": "CVE-2026-71238: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "id": "CVE-2026-71238", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "public_human_summary": "NVD: DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. NVD: Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.; CVSS 9.1 (CRITICAL); EPSS percentile 24; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. NVD: Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens...", "public_status": "public_safe", "published_at": "2026-08-05T11:16:26.630", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71238-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71238.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71238.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71238"], "sort_priority": 91.23765, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. NVD: Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/DjangoCRM/django-crm"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71238"}], "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. NVD: Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens...", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71238 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.1. EPSS score is 0.0031 with percentile 0.2377. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71238 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 9.1, "disclosure_freshness": 0.9613, "epss_percentile": 0.23765, "epss_score": 0.00313, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71238", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.307000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 23.765, "priority_area": 91.2377, "published_at": "2026-08-05T11:16:26.630000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "critical", "source_count": 2}, "updated_at": "2026-08-10T12:17:26.307", "urgency_reasons": ["CVSS CRITICAL", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review; CVSS 9.1 (CRITICAL); EPSS percentile 24; sources: NVD."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71239/", "cvss_score": 8.1, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71239.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.13231, "epss_score": 0.00225, "exposure_hint": "exposure unknown", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "human_impact_label": "high severity review", "human_risk_summary": "CVE-2026-71239: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "id": "CVE-2026-71239", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "public_human_summary": "NVD: DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no sanitization, in at least three locations: message_previews.py builds an f-string embedding message.subject/message.content...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.; CVSS 8.1 (HIGH); EPSS percentile 13; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no sanitization, in at least three locations: message_previews.py builds an f-string embedding message.subject/message.content...", "public_status": "public_safe", "published_at": "2026-08-05T11:16:26.750", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71239-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71239.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71239.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71239"], "sort_priority": 81.13231, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no sanitization, in at least three locations: message_previews.py builds an f-string embedding message.subject/message.content...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/DjangoCRM/django-crm"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71239"}], "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no sanitization, in at least three locations: message_previews.py builds an f-string embedding message.subject/message.content...", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71239 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.1. EPSS score is 0.0022 with percentile 0.1323. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71239 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 8.1, "disclosure_freshness": 0.9613, "epss_percentile": 0.13231, "epss_score": 0.00225, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71239", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.417000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 13.231, "priority_area": 81.1323, "published_at": "2026-08-05T11:16:26.750000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 2}, "updated_at": "2026-08-10T12:17:26.417", "urgency_reasons": ["CVSS HIGH", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 8.1 (HIGH); EPSS percentile 13; sources: NVD."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71240/", "cvss_score": 4.3, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71240.json", "defensive_priority": "Routine monitoring candidate", "epss_percentile": 0.08769, "epss_score": 0.00189, "exposure_hint": "exposure unknown", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "human_impact_label": "defensive exposure review", "human_risk_summary": "CVE-2026-71240: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "id": "CVE-2026-71240", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "public_human_summary": "NVD: DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or staff_member_required, and it redirects to a caller-supplied next_url GET parameter after only checking secure_url(next_url), which merely...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.; CVSS 4.3 (MEDIUM); EPSS percentile 9; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or staff_member_required, and it redirects to a caller-supplied next_url GET parameter after only checking secure_url(next_url), which merely...", "public_status": "public_safe", "published_at": "2026-08-05T11:16:26.873", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71240-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71240.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71240.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71240"], "sort_priority": 43.08769, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or staff_member_required, and it redirects to a caller-supplied next_url GET parameter after only checking secure_url(next_url), which merely...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/DjangoCRM/django-crm"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71240"}], "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or staff_member_required, and it redirects to a caller-supplied next_url GET parameter after only checking secure_url(next_url), which merely...", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71240 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 4.3. EPSS score is 0.0019 with percentile 0.0877. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71240 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 4.3, "disclosure_freshness": 0.9613, "epss_percentile": 0.08769, "epss_score": 0.00189, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71240", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.527000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 8.769, "priority_area": 43.0877, "published_at": "2026-08-05T11:16:26.873000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "medium", "source_count": 2}, "updated_at": "2026-08-10T12:17:26.527", "urgency_reasons": ["vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 4.3 (MEDIUM); EPSS percentile 9; sources: NVD."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71241/", "cvss_score": 7.5, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71241.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.20477, "epss_score": 0.00282, "exposure_hint": "exposure unknown", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "human_impact_label": "high severity review", "human_risk_summary": "CVE-2026-71241: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "id": "CVE-2026-71241", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "public_human_summary": "NVD: Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. NVD: Because card_id values are sequential integers, the entire student database can be enumerated without authentication.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.; CVSS 7.5 (HIGH); EPSS percentile 20; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. NVD: Because card_id values are sequential integers, the entire student database can be enumerated without authentication.", "public_status": "public_safe", "published_at": "2026-08-05T11:16:26.997", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71241-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71241.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71241.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71241"], "sort_priority": 75.20477, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. NVD: Because card_id values are sequential integers, the entire student database can be enumerated without authentication.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/lyric777/Book-Management-System"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71241"}], "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. NVD: Because card_id values are sequential integers, the entire student database can be enumerated without authentication.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71241 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 7.5. EPSS score is 0.0028 with percentile 0.2048. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71241 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 7.5, "disclosure_freshness": 0.9613, "epss_percentile": 0.20477, "epss_score": 0.00282, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71241", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.633000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 20.477, "priority_area": 75.2048, "published_at": "2026-08-05T11:16:26.997000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 2}, "updated_at": "2026-08-10T12:17:26.633", "urgency_reasons": ["CVSS HIGH", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 7.5 (HIGH); EPSS percentile 20; sources: NVD."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71242/", "cvss_score": 8.3, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71242.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.12013, "epss_score": 0.00215, "exposure_hint": "authenticated boundary", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.", "human_impact_label": "authenticated boundary", "human_risk_summary": "CVE-2026-71242: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.", "id": "CVE-2026-71242", "impact_tags": ["authenticated boundary review"], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.", "public_human_summary": "NVD: Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify ->hasCompany(->company_id). NVD: Any authenticated user of one company can read, edit, or delete another company's notes by ID. OSV: Crater - Cross-Company IDOR on Notes via Missing Company-Ownership Check in NotePolicy", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.; CVSS 8.3 (HIGH); EPSS percentile 12; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV.", "public_safe_summary": "NVD: Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify ->hasCompany(->company_id). NVD: Any authenticated user of one company can read, edit, or delete another company's notes by ID. OSV: Crater - Cross-Company IDOR on Notes via Missing Company-Ownership Check in NotePolicy", "public_status": "public_safe", "published_at": "2026-08-05T11:16:27.123", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71242-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71242.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71242.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71242", "https://osv.dev/vulnerability/CVE-2026-71242"], "sort_priority": 83.12013, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify ->hasCompany(->company_id). NVD: Any authenticated user of one company can read, edit, or delete another company's notes by ID. OSV: Crater - Cross-Company IDOR on Notes via Missing Company-Ownership Check in NotePolicy", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/crater-invoice/crater"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71242"}, {"source": "Official Reference", "type": "reference", "url": "https://osv.dev/vulnerability/CVE-2026-71242"}], "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify ->hasCompany(->company_id). NVD: Any authenticated user of one company can read, edit, or delete another company's notes by ID. OSV: Crater - Cross-Company IDOR on Notes via Missing Company-Ownership Check in NotePolicy", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2026-71242 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.3. EPSS score is 0.0022 with percentile 0.1201. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71242 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 8.3, "disclosure_freshness": 0.9613, "epss_percentile": 0.12013, "epss_score": 0.00215, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71242", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.747000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 12.013, "priority_area": 83.1201, "published_at": "2026-08-05T11:16:27.123000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 4}, "updated_at": "2026-08-10T12:17:26.747", "urgency_reasons": ["CVSS HIGH", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary; CVSS 8.3 (HIGH); EPSS percentile 12; sources: NVD, OSV."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71243/", "cvss_score": 8.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71243.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.21081, "epss_score": 0.00288, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may be able to run unintended system commands through the affected component.", "human_impact_label": "command injection risk", "human_risk_summary": "CVE-2026-71243: An attacker may be able to run unintended system commands through the affected component.", "id": "CVE-2026-71243", "impact_tags": ["command injection risk"], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.", "public_human_summary": "NVD: The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. NVD: cmd = \"mkdir -p \" + path.join(info.destination, info.name) + \"; \" - and executes the resulting string through a shell via ssh2-exec (locally via child_process, or remotely via SSH when an ssh handle is supplied), rather than using execFile/spawn with an... OSV: backmeup (npm) - OS Command Injection via Backup Option Values", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.; CVSS 8.8 (HIGH); EPSS percentile 21; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV.", "public_safe_summary": "NVD: The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. NVD: cmd = \"mkdir -p \" + path.join(info.destination, info.name) + \"; \" - and executes the resulting string through a shell via ssh2-exec (locally via child_process, or remotely via SSH when an ssh handle is supplied), rather than using execFile/spawn with an... OSV: backmeup (npm) - OS Command Injection via Backup Option Values", "public_status": "public_safe", "published_at": "2026-08-05T11:16:27.247", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71243-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71243.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71243.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71243", "https://osv.dev/vulnerability/CVE-2026-71243"], "sort_priority": 88.21081, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. NVD: cmd = \"mkdir -p \" + path.join(info.destination, info.name) + \"; \" - and executes the resulting string through a shell via ssh2-exec (locally via child_process, or remotely via SSH when an ssh handle is supplied), rather than using execFile/spawn with an... OSV: backmeup (npm) - OS Command Injection via Backup Option Values", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/adaltas/node-backmeup"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71243"}, {"source": "Official Reference", "type": "reference", "url": "https://osv.dev/vulnerability/CVE-2026-71243"}], "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. NVD: cmd = \"mkdir -p \" + path.join(info.destination, info.name) + \"; \" - and executes the resulting string through a shell via ssh2-exec (locally via child_process, or remotely via SSH when an ssh handle is supplied), rather than using execFile/spawn with an... OSV: backmeup (npm) - OS Command Injection via Backup Option Values", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2026-71243 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.8. EPSS score is 0.0029 with percentile 0.2108. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71243 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 8.8, "disclosure_freshness": 0.9613, "epss_percentile": 0.21081, "epss_score": 0.00288, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71243", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.857000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 21.081, "priority_area": 88.2108, "published_at": "2026-08-05T11:16:27.247000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 4}, "updated_at": "2026-08-10T12:17:26.857", "urgency_reasons": ["CVSS HIGH", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to run unintended system commands through the affected component; CVSS 8.8 (HIGH); EPSS percentile 21; sources: NVD, OSV."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71244/", "cvss_score": 6.5, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71244.json", "defensive_priority": "Routine monitoring candidate", "epss_percentile": 0.10156, "epss_score": 0.00201, "exposure_hint": "exposure unknown", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "human_impact_label": "defensive exposure review", "human_risk_summary": "CVE-2026-71244: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "id": "CVE-2026-71244", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "public_human_summary": "NVD: Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.; CVSS 6.5 (MEDIUM); EPSS percentile 10; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a...", "public_status": "public_safe", "published_at": "2026-08-05T11:16:27.367", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71244-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71244.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71244.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71244"], "sort_priority": 65.10156, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/paperless-ngx/paperless-ngx"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71244"}], "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a...", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71244 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 6.5. EPSS score is 0.0020 with percentile 0.1016. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71244 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 6.5, "disclosure_freshness": 0.9613, "epss_percentile": 0.10156, "epss_score": 0.00201, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71244", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.970000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 10.156, "priority_area": 65.1016, "published_at": "2026-08-05T11:16:27.367000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "medium", "source_count": 2}, "updated_at": "2026-08-10T12:17:26.970", "urgency_reasons": ["vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 6.5 (MEDIUM); EPSS percentile 10; sources: NVD."}], "manual_public_launch_required": false, "public_launch_allowed": true, "public_safe_export_generated": true, "radar": "vuln", "read_only_static_data": true, "schema_url": "https://vuln.signal-radar.com/data/vuln/schema.json", "schema_version": "v0.1", "search_console_registered": true, "signal_radar_integration_allowed": false, "webmcp_future_contract": {"annotations": {"readOnlyHint": true, "untrustedContentHint": true}, "api": "document.modelContext", "auto_remediation_allowed": false, "cross_origin_exposure_allowed": false, "deploy_allowed": false, "enabled": true, "endpoint": null, "exposed_to": [], "external_execution_allowed": false, "fallback_api": "navigator.modelContext", "fetch_allowed": false, "github_issue_creation_allowed": false, "mode": "browser_imperative_progressive_enhancement", "mutation_allowed": false, "notes": "Browser WebMCP tools are registered only when document.modelContext or navigator.modelContext is available. They read existing public-safe static JSON and perform no network fetch, deploy, scan, patch, or mutation.", "planned": false, "scan_allowed": false, "tool_output_max_items": 10, "tool_output_target_max_chars": 1500, "tools": ["vuln_signal_search", "vuln_signal_get_item", "vuln_signal_list_priority"]}}, "itemsById": {"CVE-2026-12609": {"affected_label": "eclipse / theia", "affected_products": [{"canonicalProduct": "theia", "canonicalVendor": "eclipse", "cpe": "cpe:2.3:a:eclipse:theia:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "theia", "purl": null, "vendor": "eclipse", "version": null}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12609/", "cvss_score": 7.5, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-12609.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.3374, "epss_score": 0.00409, "exposure_hint": "remote exposure", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.", "human_impact_label": "remote exposure", "human_risk_summary": "CVE-2026-12609 for eclipse / theia: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.", "id": "CVE-2026-12609", "impact_tags": ["remote exposure relevant"], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": "theia", "public_human_impact": "Source describes remote exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.", "public_human_summary": "NVD: In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the @theia/plugin-ext backend exposes the /hostedPlugin/:pluginId/:path(*) HTTP endpoint, which resolves the requested file path with path.resolve(localPath, filePath) without verifying that the... NVD: An unauthenticated network attacker can send percent-encoded ../ sequences (%2e%2e%2f) that decode into the path parameter and escape the plugin directory, allowing arbitrary files readable by the Theia backend process to be retrieved. NVD: Plugin IDs are derived deterministically from a plugin's publisher and name, so built-in plugins serve as reliable anchors that require no prior knowledge of the target system.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes remote exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.; CVSS 7.5 (HIGH); EPSS percentile 34; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV, Vendor Advisory.", "public_safe_summary": "NVD: In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the @theia/plugin-ext backend exposes the /hostedPlugin/:pluginId/:path(*) HTTP endpoint, which resolves the requested file path with path.resolve(localPath, filePath) without verifying that the... NVD: An unauthenticated network attacker can send percent-encoded ../ sequences (%2e%2e%2f) that decode into the path parameter and escape the plugin directory, allowing arbitrary files readable by the Theia backend process to be retrieved. NVD: Plugin IDs are derived deterministically from a plugin's publisher and name, so built-in plugins serve as reliable anchors that require no prior knowledge of the target system.", "public_status": "public_safe", "published_at": "2026-08-05T11:16:24.080", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-12609-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-12609.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-12609.md", "scan_allowed": false}, "remediation_urls": ["https://github.com/eclipse-theia/theia/security/advisories/GHSA-qmm6-p8q4-2g48", "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/133", "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/524"], "sort_priority": 75.3374, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "vendor/product: eclipse / theia", "source_published_description": "NVD: In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the @theia/plugin-ext backend exposes the /hostedPlugin/:pluginId/:path(*) HTTP endpoint, which resolves the requested file path with path.resolve(localPath, filePath) without verifying that the... NVD: An unauthenticated network attacker can send percent-encoded ../ sequences (%2e%2e%2f) that decode into the path parameter and escape the plugin directory, allowing arbitrary files readable by the Theia backend process to be retrieved. NVD: Plugin IDs are derived deterministically from a plugin's publisher and name, so built-in plugins serve as reliable anchors that require no prior knowledge of the target system.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/eclipse-theia/theia/security/advisories/GHSA-qmm6-p8q4-2g48"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/133"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/524"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12609"}, {"source": "Official Reference", "type": "reference", "url": "https://osv.dev/vulnerability/CVE-2026-12609"}], "source_published_impact": "Source describes remote exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the @theia/plugin-ext backend exposes the /hostedPlugin/:pluginId/:path(*) HTTP endpoint, which resolves the requested file path with path.resolve(localPath, filePath) without verifying that the... NVD: An unauthenticated network attacker can send percent-encoded ../ sequences (%2e%2e%2f) that decode into the path parameter and escape the plugin directory, allowing arbitrary files readable by the Theia backend process to be retrieved. NVD: Plugin IDs are derived deterministically from a plugin's publisher and name, so built-in plugins serve as reliable anchors that require no prior knowledge of the target system.", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2026-12609 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 7.5. EPSS score is 0.0041 with percentile 0.3374. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-12609 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 7.5, "disclosure_freshness": 0.9613, "epss_percentile": 0.3374, "epss_score": 0.00409, "evidence_confidence": 1.0, "fallbacks": [], "group_key": "canonical_vendor:eclipse", "group_label": "eclipse", "id": "cve:CVE-2026-12609", "kev": false, "kev_date_added": null, "last_modified": "2026-08-07T20:23:46.517000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 33.74, "priority_area": 75.3374, "published_at": "2026-08-05T11:16:24.080000Z", "remediation_reference_count": 3, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 6}, "updated_at": "2026-08-07T20:23:46.517", "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "eclipse", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure; CVSS 7.5 (HIGH); EPSS percentile 34; affected product context: eclipse / theia; sources: NVD, OSV, Vendor Advisory."}, "CVE-2026-14304": {"affected_label": "eclipse / accessibility_tools_framework", "affected_products": [{"canonicalProduct": "accessibility_tools_framework", "canonicalVendor": "eclipse", "cpe": "cpe:2.3:a:eclipse:accessibility_tools_framework:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "accessibility_tools_framework", "purl": null, "vendor": "eclipse", "version": null}, {"canonicalProduct": "michecker", "canonicalVendor": "soumu", "cpe": "cpe:2.3:a:soumu:michecker:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "michecker", "purl": null, "vendor": "soumu", "version": null}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14304/", "cvss_score": 4.6, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-14304.json", "defensive_priority": "Routine monitoring candidate", "epss_percentile": 0.06863, "epss_score": 0.00172, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may cross a privilege boundary and gain more access than intended.", "human_impact_label": "privilege escalation risk", "human_risk_summary": "CVE-2026-14304 for eclipse / accessibility_tools_framework: An attacker may cross a privilege boundary and gain more access than intended.", "id": "CVE-2026-14304", "impact_tags": ["privilege boundary review"], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": "accessibility_tools_framework", "public_human_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.", "public_human_summary": "NVD: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. NVD: If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker. OSV: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.; CVSS 4.6 (MEDIUM); EPSS percentile 7; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV, Vendor Advisory.", "public_safe_summary": "NVD: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. NVD: If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker. OSV: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists.", "public_status": "public_safe", "published_at": "2026-08-05T11:16:24.887", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14304-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14304.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14304.md", "scan_allowed": false}, "remediation_urls": ["https://eclipse.dev/actf/downloads/tools/miChecker/vulnerability.html", "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/151"], "sort_priority": 46.06863, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "vendor/product: eclipse / accessibility_tools_framework", "source_published_description": "NVD: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. NVD: If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker. OSV: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "reference", "url": "https://eclipse.dev/actf/downloads/tools/miChecker/vulnerability.html"}, {"source": "Reference", "type": "reference", "url": "https://github.com/eclipse-actf/org.eclipse.actf"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/151"}, {"source": "Reference", "type": "reference", "url": "https://www.soumu.go.jp/info-accessibility-portal/webaccessibility/michecker/"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14304"}, {"source": "Official Reference", "type": "reference", "url": "https://osv.dev/vulnerability/CVE-2026-14304"}], "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. NVD: If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker. OSV: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists.", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2026-14304 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 4.6. EPSS score is 0.0017 with percentile 0.0686. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-14304 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 4.6, "disclosure_freshness": 0.9613, "epss_percentile": 0.06863, "epss_score": 0.00172, "evidence_confidence": 1.0, "fallbacks": [], "group_key": "canonical_vendor:eclipse", "group_label": "eclipse", "id": "cve:CVE-2026-14304", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T19:01:10.803000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 6.863, "priority_area": 46.0686, "published_at": "2026-08-05T11:16:24.887000Z", "remediation_reference_count": 2, "schema_version": "vuln-treemap-node-v1", "severity": "medium", "source_count": 6}, "updated_at": "2026-08-10T19:01:10.803", "urgency_reasons": ["affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "eclipse", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may cross a privilege boundary and gain more access than intended; CVSS 4.6 (MEDIUM); EPSS percentile 7; affected product context: eclipse / accessibility_tools_framework; sources: NVD, OSV, Vendor Advisory."}, "CVE-2026-14574": {"affected_label": "eclipse / theia", "affected_products": [{"canonicalProduct": "theia", "canonicalVendor": "eclipse", "cpe": "cpe:2.3:a:eclipse:theia:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "theia", "purl": null, "vendor": "eclipse", "version": null}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14574/", "cvss_score": 5.7, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-14574.json", "defensive_priority": "Routine monitoring candidate", "epss_percentile": 0.20449, "epss_score": 0.00282, "exposure_hint": "exposure unknown", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "human_impact_label": "defensive exposure review", "human_risk_summary": "CVE-2026-14574 for eclipse / theia: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "id": "CVE-2026-14574", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": "theia", "public_human_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "public_human_summary": "NVD: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype). NVD: Because this function is invoked by PreferenceServiceImpl.doResolve for every preference resolution across scopes (default, user, workspace, folder), a crafted preference value in a workspace settings file (.theia/settings.json or .vscode/settings.json) can... OSV: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype).", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.; CVSS 5.7 (MEDIUM); EPSS percentile 20; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV, Vendor Advisory.", "public_safe_summary": "NVD: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype). NVD: Because this function is invoked by PreferenceServiceImpl.doResolve for every preference resolution across scopes (default, user, workspace, folder), a crafted preference value in a workspace settings file (.theia/settings.json or .vscode/settings.json) can... OSV: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype).", "public_status": "public_safe", "published_at": "2026-08-05T11:16:25.030", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14574-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14574.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14574.md", "scan_allowed": false}, "remediation_urls": ["https://github.com/eclipse-theia/theia/security/advisories/GHSA-f3w9-qfw3-xr32", "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/157", "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/567", "https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/567"], "sort_priority": 57.20449, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "vendor/product: eclipse / theia", "source_published_description": "NVD: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype). NVD: Because this function is invoked by PreferenceServiceImpl.doResolve for every preference resolution across scopes (default, user, workspace, folder), a crafted preference value in a workspace settings file (.theia/settings.json or .vscode/settings.json) can... OSV: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype).", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/eclipse-theia/theia/security/advisories/GHSA-f3w9-qfw3-xr32"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/157"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/567"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/567"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14574"}, {"source": "Official Reference", "type": "reference", "url": "https://osv.dev/vulnerability/CVE-2026-14574"}], "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype). NVD: Because this function is invoked by PreferenceServiceImpl.doResolve for every preference resolution across scopes (default, user, workspace, folder), a crafted preference value in a workspace settings file (.theia/settings.json or .vscode/settings.json) can... OSV: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype).", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2026-14574 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 5.7. EPSS score is 0.0028 with percentile 0.2045. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-14574 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 5.7, "disclosure_freshness": 0.9613, "epss_percentile": 0.20449, "epss_score": 0.00282, "evidence_confidence": 1.0, "fallbacks": [], "group_key": "canonical_vendor:eclipse", "group_label": "eclipse", "id": "cve:CVE-2026-14574", "kev": false, "kev_date_added": null, "last_modified": "2026-08-07T16:02:40.473000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 20.449, "priority_area": 57.2045, "published_at": "2026-08-05T11:16:25.030000Z", "remediation_reference_count": 4, "schema_version": "vuln-treemap-node-v1", "severity": "medium", "source_count": 6}, "updated_at": "2026-08-07T16:02:40.473", "urgency_reasons": ["affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "eclipse", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.7 (MEDIUM); EPSS percentile 20; affected product context: eclipse / theia; sources: NVD, OSV, Vendor Advisory."}, "CVE-2026-17578": {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17578/", "cvss_score": 2.3, "cvss_severity": "LOW", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-17578.json", "defensive_priority": "Routine monitoring candidate", "epss_percentile": 0.04712, "epss_score": 0.0015, "exposure_hint": "exposure unknown", "human_consequence": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "human_impact_label": "defensive exposure review", "human_risk_summary": "CVE-2026-17578: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "id": "CVE-2026-17578", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "public_human_summary": "NVD: Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled. NVD: If a producer sends messages at a sustained high rate without key rotation, which only occurs on reboot of the Kong Event Gateway instance, the probability of a nonce collision becomes non-negligible. NVD: An authorized consumer who detects a nonce collision can recover parts of plaintext from the affected messages.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.; CVSS 2.3 (LOW); EPSS percentile 5; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled. NVD: If a producer sends messages at a sustained high rate without key rotation, which only occurs on reboot of the Kong Event Gateway instance, the probability of a nonce collision becomes non-negligible. NVD: An authorized consumer who detects a nonce collision can recover parts of plaintext from the affected messages.", "public_status": "public_safe", "published_at": "2026-08-05T11:16:25.197", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-17578-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-17578.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-17578.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-17578"], "sort_priority": 23.04712, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled. NVD: If a producer sends messages at a sustained high rate without key rotation, which only occurs on reboot of the Kong Event Gateway instance, the probability of a nonce collision becomes non-negligible. NVD: An authorized consumer who detects a nonce collision can recover parts of plaintext from the affected messages.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://developer.konghq.com/event-gateway/changelog/"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-17578"}], "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled. NVD: If a producer sends messages at a sustained high rate without key rotation, which only occurs on reboot of the Kong Event Gateway instance, the probability of a nonce collision becomes non-negligible. NVD: An authorized consumer who detects a nonce collision can recover parts of plaintext from the affected messages.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-17578 is a defensive prioritization candidate. NVD lists CVSS severity as LOW. CVSS score is 2.3. EPSS score is 0.0015 with percentile 0.0471. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-17578 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 2.3, "disclosure_freshness": 0.9613, "epss_percentile": 0.04712, "epss_score": 0.0015, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-17578", "kev": false, "kev_date_added": null, "last_modified": "2026-08-05T14:17:04.187000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 6.0, "priority_area": 23.0471, "published_at": "2026-08-05T11:16:25.197000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "low", "source_count": 2}, "updated_at": "2026-08-05T14:17:04.187", "urgency_reasons": ["vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 2.3 (LOW); EPSS percentile 5; sources: NVD."}, "CVE-2026-60009": {"affected_label": "eclipse / theia", "affected_products": [{"canonicalProduct": "theia", "canonicalVendor": "eclipse", "cpe": "cpe:2.3:a:eclipse:theia:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "theia", "purl": null, "vendor": "eclipse", "version": null}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60009/", "cvss_score": 8.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-60009.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.24854, "epss_score": 0.00323, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may be able to run code or commands on affected systems.", "human_impact_label": "code execution review", "human_risk_summary": "CVE-2026-60009 for eclipse / theia: An attacker may be able to run code or commands on affected systems.", "id": "CVE-2026-60009", "impact_tags": ["code execution review"], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": "theia", "public_human_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.", "public_human_summary": "NVD: In Eclipse Theia versions up to and including 1.73.1, the @theia/filesystem backend binds POST /file-upload in every filesystem-enabled deployment. NVD: The handler takes an attacker-supplied absolute path from the multipart uri field and calls fs.move(tmp, target, { overwrite: true }) with no workspace confinement and no authentication. NVD: In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in @theia/core re-issues the cookie and calls next() without rejecting tokenless HTTP requests.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.; CVSS 8.8 (HIGH); EPSS percentile 25; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV, Vendor Advisory.", "public_safe_summary": "NVD: In Eclipse Theia versions up to and including 1.73.1, the @theia/filesystem backend binds POST /file-upload in every filesystem-enabled deployment. NVD: The handler takes an attacker-supplied absolute path from the multipart uri field and calls fs.move(tmp, target, { overwrite: true }) with no workspace confinement and no authentication. NVD: In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in @theia/core re-issues the cookie and calls next() without rejecting tokenless HTTP requests.", "public_status": "public_safe", "published_at": "2026-08-05T11:16:25.363", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-60009-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-60009.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-60009.md", "scan_allowed": false}, "remediation_urls": ["https://github.com/eclipse-theia/theia/security/advisories/GHSA-62f6-wcvg-54h3", "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/177", "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/595", "https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/595"], "sort_priority": 88.24854, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "vendor/product: eclipse / theia", "source_published_description": "NVD: In Eclipse Theia versions up to and including 1.73.1, the @theia/filesystem backend binds POST /file-upload in every filesystem-enabled deployment. NVD: The handler takes an attacker-supplied absolute path from the multipart uri field and calls fs.move(tmp, target, { overwrite: true }) with no workspace confinement and no authentication. NVD: In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in @theia/core re-issues the cookie and calls next() without rejecting tokenless HTTP requests.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/eclipse-theia/theia/security/advisories/GHSA-62f6-wcvg-54h3"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/177"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/595"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/595"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-60009"}, {"source": "Official Reference", "type": "reference", "url": "https://osv.dev/vulnerability/CVE-2026-60009"}], "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: In Eclipse Theia versions up to and including 1.73.1, the @theia/filesystem backend binds POST /file-upload in every filesystem-enabled deployment. NVD: The handler takes an attacker-supplied absolute path from the multipart uri field and calls fs.move(tmp, target, { overwrite: true }) with no workspace confinement and no authentication. NVD: In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in @theia/core re-issues the cookie and calls next() without rejecting tokenless HTTP requests.", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2026-60009 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.8. EPSS score is 0.0032 with percentile 0.2485. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-60009 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 8.8, "disclosure_freshness": 0.9613, "epss_percentile": 0.24854, "epss_score": 0.00323, "evidence_confidence": 1.0, "fallbacks": [], "group_key": "canonical_vendor:eclipse", "group_label": "eclipse", "id": "cve:CVE-2026-60009", "kev": false, "kev_date_added": null, "last_modified": "2026-08-07T15:54:02.380000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 24.854, "priority_area": 88.2485, "published_at": "2026-08-05T11:16:25.363000Z", "remediation_reference_count": 4, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 6}, "updated_at": "2026-08-07T15:54:02.380", "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "eclipse", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to run code or commands on affected systems; CVSS 8.8 (HIGH); EPSS percentile 25; affected product context: eclipse / theia; sources: NVD, OSV, Vendor Advisory."}, "CVE-2026-66747": {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66747/", "cvss_score": 9.3, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-66747.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.44552, "epss_score": 0.00579, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may gain root or administrative-level privileges on affected systems.", "human_impact_label": "code execution review · admin privilege risk", "human_risk_summary": "CVE-2026-66747: An attacker may gain root or administrative-level privileges on affected systems.", "id": "CVE-2026-66747", "impact_tags": ["code execution review", "admin privilege risk"], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "Source describes code execution review · admin privilege risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.", "public_human_summary": "NVD: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. NVD: It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. NVD: It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes code execution review · admin privilege risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.; CVSS 9.3 (CRITICAL); EPSS percentile 45; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. NVD: It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. NVD: It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds.", "public_status": "public_safe", "published_at": "2026-08-05T11:16:25.510", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-66747-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-66747.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-66747.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-66747"], "sort_priority": 93.44552, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. NVD: It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. NVD: It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/ycsunjane/rctl"}, {"source": "Reference", "type": "reference", "url": "https://www.vulncheck.com/advisories/zbt-endlessdoors"}, {"source": "Reference", "type": "reference", "url": "https://www.vulncheck.com/blog/zbt-endlessdoors"}, {"source": "Reference", "type": "reference", "url": "https://www.zbtlink.com/pages/zbt-router-firmware-download"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66747"}], "source_published_impact": "Source describes code execution review · admin privilege risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. NVD: It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. NVD: It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-66747 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.3. EPSS score is 0.0058 with percentile 0.4455. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-66747 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 9.3, "disclosure_freshness": 0.9613, "epss_percentile": 0.44552, "epss_score": 0.00579, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-66747", "kev": false, "kev_date_added": null, "last_modified": "2026-08-05T15:17:04.690000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 44.552, "priority_area": 93.4455, "published_at": "2026-08-05T11:16:25.510000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "critical", "source_count": 2}, "updated_at": "2026-08-05T15:17:04.690", "urgency_reasons": ["CVSS CRITICAL", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may gain root or administrative-level privileges on affected systems; CVSS 9.3 (CRITICAL); EPSS percentile 45; sources: NVD."}, "CVE-2026-71231": {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71231/", "cvss_score": 9.8, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71231.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.28595, "epss_score": 0.00358, "exposure_hint": "exposure unknown", "human_consequence": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "human_impact_label": "critical severity review", "human_risk_summary": "CVE-2026-71231: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "id": "CVE-2026-71231", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "public_human_summary": "NVD: IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.; CVSS 9.8 (CRITICAL); EPSS percentile 29; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding...", "public_status": "public_safe", "published_at": "2026-08-05T11:16:25.740", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71231-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71231.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71231.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71231"], "sort_priority": 98.28595, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/thebradleysanders/IOTSmartHome"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71231"}], "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding...", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71231 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.8. EPSS score is 0.0036 with percentile 0.2859. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71231 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 9.8, "disclosure_freshness": 0.9613, "epss_percentile": 0.28595, "epss_score": 0.00358, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71231", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:25.533000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 28.595, "priority_area": 98.2859, "published_at": "2026-08-05T11:16:25.740000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "critical", "source_count": 2}, "updated_at": "2026-08-10T12:17:25.533", "urgency_reasons": ["CVSS CRITICAL", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review; CVSS 9.8 (CRITICAL); EPSS percentile 29; sources: NVD."}, "CVE-2026-71232": {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71232/", "cvss_score": 7.2, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71232.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.22368, "epss_score": 0.003, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may be able to run code or commands on affected systems.", "human_impact_label": "code execution review", "human_risk_summary": "CVE-2026-71232: An attacker may be able to run code or commands on affected systems.", "id": "CVE-2026-71232", "impact_tags": ["code execution review"], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.", "public_human_summary": "NVD: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function... OSV: MacCMS10 - Incomplete Function Blacklist in Template Editor Enables Authenticated RCE OSV: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.; CVSS 7.2 (HIGH); EPSS percentile 22; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV.", "public_safe_summary": "NVD: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function... OSV: MacCMS10 - Incomplete Function Blacklist in Template Editor Enables Authenticated RCE OSV: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function...", "public_status": "public_safe", "published_at": "2026-08-05T11:16:25.873", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71232-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71232.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71232.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71232", "https://osv.dev/vulnerability/CVE-2026-71232"], "sort_priority": 72.22368, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function... OSV: MacCMS10 - Incomplete Function Blacklist in Template Editor Enables Authenticated RCE OSV: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/magicblack/maccms10/commit/71ad3bb29570e110d8e973acff68040a3050ddf0"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71232"}, {"source": "Official Reference", "type": "reference", "url": "https://osv.dev/vulnerability/CVE-2026-71232"}], "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function... OSV: MacCMS10 - Incomplete Function Blacklist in Template Editor Enables Authenticated RCE OSV: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function...", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2026-71232 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 7.2. EPSS score is 0.0030 with percentile 0.2237. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71232 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 7.2, "disclosure_freshness": 0.9613, "epss_percentile": 0.22368, "epss_score": 0.003, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71232", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:25.650000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 22.368, "priority_area": 72.2237, "published_at": "2026-08-05T11:16:25.873000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 4}, "updated_at": "2026-08-10T12:17:25.650", "urgency_reasons": ["CVSS HIGH", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to run code or commands on affected systems; CVSS 7.2 (HIGH); EPSS percentile 22; sources: NVD, OSV."}, "CVE-2026-71233": {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71233/", "cvss_score": 8.7, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71233.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.0994, "epss_score": 0.00199, "exposure_hint": "exposure unknown", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "human_impact_label": "high severity review", "human_risk_summary": "CVE-2026-71233: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "id": "CVE-2026-71233", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "public_human_summary": "NVD: InvoiceNinja v5-stable renders an invoice or quote's \"terms\" field in the client portal using Laravel Blade's raw output directive {!! NVD: ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.; CVSS 8.7 (HIGH); EPSS percentile 10; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: InvoiceNinja v5-stable renders an invoice or quote's \"terms\" field in the client portal using Laravel Blade's raw output directive {!! NVD: ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization.", "public_status": "public_safe", "published_at": "2026-08-05T11:16:25.997", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71233-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71233.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71233.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71233"], "sort_priority": 87.0994, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: InvoiceNinja v5-stable renders an invoice or quote's \"terms\" field in the client portal using Laravel Blade's raw output directive {!! NVD: ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/invoiceninja/invoiceninja"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71233"}], "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: InvoiceNinja v5-stable renders an invoice or quote's \"terms\" field in the client portal using Laravel Blade's raw output directive {!! NVD: ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71233 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.7. EPSS score is 0.0020 with percentile 0.0994. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71233 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 8.7, "disclosure_freshness": 0.9613, "epss_percentile": 0.0994, "epss_score": 0.00199, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71233", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:25.770000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 9.94, "priority_area": 87.0994, "published_at": "2026-08-05T11:16:25.997000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 2}, "updated_at": "2026-08-10T12:17:25.770", "urgency_reasons": ["CVSS HIGH", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 8.7 (HIGH); EPSS percentile 10; sources: NVD."}, "CVE-2026-71234": {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71234/", "cvss_score": 7.5, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71234.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.15873, "epss_score": 0.00245, "exposure_hint": "exposure unknown", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "human_impact_label": "high severity review", "human_risk_summary": "CVE-2026-71234: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "id": "CVE-2026-71234", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "public_human_summary": "NVD: Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a query parameter and grants access whenever the parameter is simply non-empty (len(secureToken) > 0)...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.; CVSS 7.5 (HIGH); EPSS percentile 16; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a query parameter and grants access whenever the parameter is simply non-empty (len(secureToken) > 0)...", "public_status": "public_safe", "published_at": "2026-08-05T11:16:26.120", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71234-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71234.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71234.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71234"], "sort_priority": 75.15873, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a query parameter and grants access whenever the parameter is simply non-empty (len(secureToken) > 0)...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/documize/community"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71234"}], "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a query parameter and grants access whenever the parameter is simply non-empty (len(secureToken) > 0)...", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71234 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 7.5. EPSS score is 0.0024 with percentile 0.1587. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71234 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 7.5, "disclosure_freshness": 0.9613, "epss_percentile": 0.15873, "epss_score": 0.00245, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71234", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:25.880000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 15.873, "priority_area": 75.1587, "published_at": "2026-08-05T11:16:26.120000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 2}, "updated_at": "2026-08-10T12:17:25.880", "urgency_reasons": ["CVSS HIGH", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 7.5 (HIGH); EPSS percentile 16; sources: NVD."}, "CVE-2026-71235": {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71235/", "cvss_score": 8.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71235.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.21126, "epss_score": 0.00288, "exposure_hint": "authenticated boundary", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.", "human_impact_label": "authenticated boundary", "human_risk_summary": "CVE-2026-71235: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.", "id": "CVE-2026-71235", "impact_tags": ["authenticated boundary review"], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.", "public_human_summary": "NVD: Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. NVD: The Lua script engine (re/lua.go) performs no input validation at all and preloads dangerous libraries: db (arbitrary database access), ioutil (file I/O), an HTTP client (SSRF), and filepath (traversal).", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.; CVSS 8.8 (HIGH); EPSS percentile 21; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. NVD: The Lua script engine (re/lua.go) performs no input validation at all and preloads dangerous libraries: db (arbitrary database access), ioutil (file I/O), an HTTP client (SSRF), and filepath (traversal).", "public_status": "public_safe", "published_at": "2026-08-05T11:16:26.247", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71235-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71235.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71235.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71235"], "sort_priority": 88.21126, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. NVD: The Lua script engine (re/lua.go) performs no input validation at all and preloads dangerous libraries: db (arbitrary database access), ioutil (file I/O), an HTTP client (SSRF), and filepath (traversal).", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/absmach/magistrala"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71235"}], "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. NVD: The Lua script engine (re/lua.go) performs no input validation at all and preloads dangerous libraries: db (arbitrary database access), ioutil (file I/O), an HTTP client (SSRF), and filepath (traversal).", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71235 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.8. EPSS score is 0.0029 with percentile 0.2113. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71235 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 8.8, "disclosure_freshness": 0.9613, "epss_percentile": 0.21126, "epss_score": 0.00288, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71235", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:25.983000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 21.126, "priority_area": 88.2113, "published_at": "2026-08-05T11:16:26.247000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 2}, "updated_at": "2026-08-10T12:17:25.983", "urgency_reasons": ["CVSS HIGH", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary; CVSS 8.8 (HIGH); EPSS percentile 21; sources: NVD."}, "CVE-2026-71236": {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71236/", "cvss_score": 8.7, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71236.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.0994, "epss_score": 0.00199, "exposure_hint": "exposure unknown", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "human_impact_label": "high severity review", "human_risk_summary": "CVE-2026-71236: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "id": "CVE-2026-71236", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "public_human_summary": "NVD: Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HTML-entity encoding of the resulting output by replacing &amp;lt;, &amp;gt;, and...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.; CVSS 8.7 (HIGH); EPSS percentile 10; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HTML-entity encoding of the resulting output by replacing &amp;lt;, &amp;gt;, and...", "public_status": "public_safe", "published_at": "2026-08-05T11:16:26.377", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71236-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71236.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71236.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71236"], "sort_priority": 87.0994, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HTML-entity encoding of the resulting output by replacing &amp;lt;, &amp;gt;, and...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/grocy/grocy"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71236"}], "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HTML-entity encoding of the resulting output by replacing &amp;lt;, &amp;gt;, and...", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71236 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.7. EPSS score is 0.0020 with percentile 0.0994. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71236 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 8.7, "disclosure_freshness": 0.9613, "epss_percentile": 0.0994, "epss_score": 0.00199, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71236", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.090000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 9.94, "priority_area": 87.0994, "published_at": "2026-08-05T11:16:26.377000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 2}, "updated_at": "2026-08-10T12:17:26.090", "urgency_reasons": ["CVSS HIGH", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 8.7 (HIGH); EPSS percentile 10; sources: NVD."}, "CVE-2026-71237": {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71237/", "cvss_score": 9.8, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71237.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.34766, "epss_score": 0.0042, "exposure_hint": "exposure unknown", "human_consequence": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "human_impact_label": "critical severity review", "human_risk_summary": "CVE-2026-71237: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "id": "CVE-2026-71237", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "public_human_summary": "NVD: Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query(\"select * from userlists where username='' and password='' limit 1\").", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.; CVSS 9.8 (CRITICAL); EPSS percentile 35; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query(\"select * from userlists where username='' and password='' limit 1\").", "public_status": "public_safe", "published_at": "2026-08-05T11:16:26.503", "redaction_notes": ["source-published defensive context retained", "exploit string, command, scanner, or code-like detail removed", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71237-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71237.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71237.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71237"], "sort_priority": 98.34766, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query(\"select * from userlists where username='' and password='' limit 1\").", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/Miantang/IoT-PHP"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71237"}], "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query(\"select * from userlists where username='' and password='' limit 1\").", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71237 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.8. EPSS score is 0.0042 with percentile 0.3477. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71237 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 9.8, "disclosure_freshness": 0.9613, "epss_percentile": 0.34766, "epss_score": 0.0042, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71237", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.197000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 34.766, "priority_area": 98.3477, "published_at": "2026-08-05T11:16:26.503000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "critical", "source_count": 2}, "updated_at": "2026-08-10T12:17:26.197", "urgency_reasons": ["CVSS CRITICAL", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review; CVSS 9.8 (CRITICAL); EPSS percentile 35; sources: NVD."}, "CVE-2026-71238": {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71238/", "cvss_score": 9.1, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71238.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.23765, "epss_score": 0.00313, "exposure_hint": "exposure unknown", "human_consequence": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "human_impact_label": "critical severity review", "human_risk_summary": "CVE-2026-71238: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "id": "CVE-2026-71238", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "public_human_summary": "NVD: DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. NVD: Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.; CVSS 9.1 (CRITICAL); EPSS percentile 24; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. NVD: Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens...", "public_status": "public_safe", "published_at": "2026-08-05T11:16:26.630", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71238-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71238.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71238.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71238"], "sort_priority": 91.23765, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. NVD: Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/DjangoCRM/django-crm"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71238"}], "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. NVD: Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens...", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71238 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.1. EPSS score is 0.0031 with percentile 0.2377. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71238 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 9.1, "disclosure_freshness": 0.9613, "epss_percentile": 0.23765, "epss_score": 0.00313, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71238", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.307000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 23.765, "priority_area": 91.2377, "published_at": "2026-08-05T11:16:26.630000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "critical", "source_count": 2}, "updated_at": "2026-08-10T12:17:26.307", "urgency_reasons": ["CVSS CRITICAL", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review; CVSS 9.1 (CRITICAL); EPSS percentile 24; sources: NVD."}, "CVE-2026-71239": {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71239/", "cvss_score": 8.1, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71239.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.13231, "epss_score": 0.00225, "exposure_hint": "exposure unknown", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "human_impact_label": "high severity review", "human_risk_summary": "CVE-2026-71239: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "id": "CVE-2026-71239", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "public_human_summary": "NVD: DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no sanitization, in at least three locations: message_previews.py builds an f-string embedding message.subject/message.content...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.; CVSS 8.1 (HIGH); EPSS percentile 13; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no sanitization, in at least three locations: message_previews.py builds an f-string embedding message.subject/message.content...", "public_status": "public_safe", "published_at": "2026-08-05T11:16:26.750", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71239-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71239.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71239.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71239"], "sort_priority": 81.13231, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no sanitization, in at least three locations: message_previews.py builds an f-string embedding message.subject/message.content...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/DjangoCRM/django-crm"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71239"}], "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no sanitization, in at least three locations: message_previews.py builds an f-string embedding message.subject/message.content...", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71239 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.1. EPSS score is 0.0022 with percentile 0.1323. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71239 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 8.1, "disclosure_freshness": 0.9613, "epss_percentile": 0.13231, "epss_score": 0.00225, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71239", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.417000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 13.231, "priority_area": 81.1323, "published_at": "2026-08-05T11:16:26.750000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 2}, "updated_at": "2026-08-10T12:17:26.417", "urgency_reasons": ["CVSS HIGH", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 8.1 (HIGH); EPSS percentile 13; sources: NVD."}, "CVE-2026-71240": {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71240/", "cvss_score": 4.3, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71240.json", "defensive_priority": "Routine monitoring candidate", "epss_percentile": 0.08769, "epss_score": 0.00189, "exposure_hint": "exposure unknown", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "human_impact_label": "defensive exposure review", "human_risk_summary": "CVE-2026-71240: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "id": "CVE-2026-71240", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "public_human_summary": "NVD: DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or staff_member_required, and it redirects to a caller-supplied next_url GET parameter after only checking secure_url(next_url), which merely...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.; CVSS 4.3 (MEDIUM); EPSS percentile 9; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or staff_member_required, and it redirects to a caller-supplied next_url GET parameter after only checking secure_url(next_url), which merely...", "public_status": "public_safe", "published_at": "2026-08-05T11:16:26.873", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71240-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71240.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71240.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71240"], "sort_priority": 43.08769, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or staff_member_required, and it redirects to a caller-supplied next_url GET parameter after only checking secure_url(next_url), which merely...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/DjangoCRM/django-crm"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71240"}], "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or staff_member_required, and it redirects to a caller-supplied next_url GET parameter after only checking secure_url(next_url), which merely...", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71240 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 4.3. EPSS score is 0.0019 with percentile 0.0877. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71240 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 4.3, "disclosure_freshness": 0.9613, "epss_percentile": 0.08769, "epss_score": 0.00189, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71240", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.527000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 8.769, "priority_area": 43.0877, "published_at": "2026-08-05T11:16:26.873000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "medium", "source_count": 2}, "updated_at": "2026-08-10T12:17:26.527", "urgency_reasons": ["vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 4.3 (MEDIUM); EPSS percentile 9; sources: NVD."}, "CVE-2026-71241": {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71241/", "cvss_score": 7.5, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71241.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.20477, "epss_score": 0.00282, "exposure_hint": "exposure unknown", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "human_impact_label": "high severity review", "human_risk_summary": "CVE-2026-71241: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "id": "CVE-2026-71241", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "public_human_summary": "NVD: Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. NVD: Because card_id values are sequential integers, the entire student database can be enumerated without authentication.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.; CVSS 7.5 (HIGH); EPSS percentile 20; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. NVD: Because card_id values are sequential integers, the entire student database can be enumerated without authentication.", "public_status": "public_safe", "published_at": "2026-08-05T11:16:26.997", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71241-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71241.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71241.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71241"], "sort_priority": 75.20477, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. NVD: Because card_id values are sequential integers, the entire student database can be enumerated without authentication.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/lyric777/Book-Management-System"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71241"}], "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. NVD: Because card_id values are sequential integers, the entire student database can be enumerated without authentication.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71241 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 7.5. EPSS score is 0.0028 with percentile 0.2048. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71241 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 7.5, "disclosure_freshness": 0.9613, "epss_percentile": 0.20477, "epss_score": 0.00282, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71241", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.633000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 20.477, "priority_area": 75.2048, "published_at": "2026-08-05T11:16:26.997000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 2}, "updated_at": "2026-08-10T12:17:26.633", "urgency_reasons": ["CVSS HIGH", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 7.5 (HIGH); EPSS percentile 20; sources: NVD."}, "CVE-2026-71242": {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71242/", "cvss_score": 8.3, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71242.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.12013, "epss_score": 0.00215, "exposure_hint": "authenticated boundary", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.", "human_impact_label": "authenticated boundary", "human_risk_summary": "CVE-2026-71242: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.", "id": "CVE-2026-71242", "impact_tags": ["authenticated boundary review"], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.", "public_human_summary": "NVD: Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify ->hasCompany(->company_id). NVD: Any authenticated user of one company can read, edit, or delete another company's notes by ID. OSV: Crater - Cross-Company IDOR on Notes via Missing Company-Ownership Check in NotePolicy", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.; CVSS 8.3 (HIGH); EPSS percentile 12; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV.", "public_safe_summary": "NVD: Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify ->hasCompany(->company_id). NVD: Any authenticated user of one company can read, edit, or delete another company's notes by ID. OSV: Crater - Cross-Company IDOR on Notes via Missing Company-Ownership Check in NotePolicy", "public_status": "public_safe", "published_at": "2026-08-05T11:16:27.123", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71242-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71242.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71242.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71242", "https://osv.dev/vulnerability/CVE-2026-71242"], "sort_priority": 83.12013, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify ->hasCompany(->company_id). NVD: Any authenticated user of one company can read, edit, or delete another company's notes by ID. OSV: Crater - Cross-Company IDOR on Notes via Missing Company-Ownership Check in NotePolicy", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/crater-invoice/crater"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71242"}, {"source": "Official Reference", "type": "reference", "url": "https://osv.dev/vulnerability/CVE-2026-71242"}], "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify ->hasCompany(->company_id). NVD: Any authenticated user of one company can read, edit, or delete another company's notes by ID. OSV: Crater - Cross-Company IDOR on Notes via Missing Company-Ownership Check in NotePolicy", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2026-71242 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.3. EPSS score is 0.0022 with percentile 0.1201. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71242 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 8.3, "disclosure_freshness": 0.9613, "epss_percentile": 0.12013, "epss_score": 0.00215, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71242", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.747000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 12.013, "priority_area": 83.1201, "published_at": "2026-08-05T11:16:27.123000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 4}, "updated_at": "2026-08-10T12:17:26.747", "urgency_reasons": ["CVSS HIGH", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary; CVSS 8.3 (HIGH); EPSS percentile 12; sources: NVD, OSV."}, "CVE-2026-71243": {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71243/", "cvss_score": 8.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71243.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.21081, "epss_score": 0.00288, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may be able to run unintended system commands through the affected component.", "human_impact_label": "command injection risk", "human_risk_summary": "CVE-2026-71243: An attacker may be able to run unintended system commands through the affected component.", "id": "CVE-2026-71243", "impact_tags": ["command injection risk"], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.", "public_human_summary": "NVD: The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. NVD: cmd = \"mkdir -p \" + path.join(info.destination, info.name) + \"; \" - and executes the resulting string through a shell via ssh2-exec (locally via child_process, or remotely via SSH when an ssh handle is supplied), rather than using execFile/spawn with an... OSV: backmeup (npm) - OS Command Injection via Backup Option Values", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.; CVSS 8.8 (HIGH); EPSS percentile 21; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV.", "public_safe_summary": "NVD: The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. NVD: cmd = \"mkdir -p \" + path.join(info.destination, info.name) + \"; \" - and executes the resulting string through a shell via ssh2-exec (locally via child_process, or remotely via SSH when an ssh handle is supplied), rather than using execFile/spawn with an... OSV: backmeup (npm) - OS Command Injection via Backup Option Values", "public_status": "public_safe", "published_at": "2026-08-05T11:16:27.247", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71243-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71243.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71243.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71243", "https://osv.dev/vulnerability/CVE-2026-71243"], "sort_priority": 88.21081, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. NVD: cmd = \"mkdir -p \" + path.join(info.destination, info.name) + \"; \" - and executes the resulting string through a shell via ssh2-exec (locally via child_process, or remotely via SSH when an ssh handle is supplied), rather than using execFile/spawn with an... OSV: backmeup (npm) - OS Command Injection via Backup Option Values", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/adaltas/node-backmeup"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71243"}, {"source": "Official Reference", "type": "reference", "url": "https://osv.dev/vulnerability/CVE-2026-71243"}], "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. NVD: cmd = \"mkdir -p \" + path.join(info.destination, info.name) + \"; \" - and executes the resulting string through a shell via ssh2-exec (locally via child_process, or remotely via SSH when an ssh handle is supplied), rather than using execFile/spawn with an... OSV: backmeup (npm) - OS Command Injection via Backup Option Values", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2026-71243 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.8. EPSS score is 0.0029 with percentile 0.2108. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71243 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 8.8, "disclosure_freshness": 0.9613, "epss_percentile": 0.21081, "epss_score": 0.00288, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71243", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.857000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 21.081, "priority_area": 88.2108, "published_at": "2026-08-05T11:16:27.247000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 4}, "updated_at": "2026-08-10T12:17:26.857", "urgency_reasons": ["CVSS HIGH", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to run unintended system commands through the affected component; CVSS 8.8 (HIGH); EPSS percentile 21; sources: NVD, OSV."}, "CVE-2026-71244": {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71244/", "cvss_score": 6.5, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71244.json", "defensive_priority": "Routine monitoring candidate", "epss_percentile": 0.10156, "epss_score": 0.00201, "exposure_hint": "exposure unknown", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "human_impact_label": "defensive exposure review", "human_risk_summary": "CVE-2026-71244: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "id": "CVE-2026-71244", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "public_human_summary": "NVD: Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.; CVSS 6.5 (MEDIUM); EPSS percentile 10; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a...", "public_status": "public_safe", "published_at": "2026-08-05T11:16:27.367", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71244-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71244.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71244.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71244"], "sort_priority": 65.10156, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/paperless-ngx/paperless-ngx"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71244"}], "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a...", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71244 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 6.5. EPSS score is 0.0020 with percentile 0.1016. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71244 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 6.5, "disclosure_freshness": 0.9613, "epss_percentile": 0.10156, "epss_score": 0.00201, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71244", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.970000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 10.156, "priority_area": 65.1016, "published_at": "2026-08-05T11:16:27.367000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "medium", "source_count": 2}, "updated_at": "2026-08-10T12:17:26.970", "urgency_reasons": ["vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 6.5 (MEDIUM); EPSS percentile 10; sources: NVD."}}, "readModel": {"ageDistribution": {"0-24h": 0, "2-7d": 20, "8-30d": 0, ">30d": 0, "unknown": 0}, "enrichmentCoverage": {"affected_products": 5, "canonical_vendor_product": 5, "coverage_label": "partial", "cpe": 5, "purl": 0, "sources": {"CISA KEV": 0, "NVD": 20, "OSV": 7, "Vendor Advisory": 20}}, "feedItems": [{"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71237/", "cvss_score": 9.8, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71237.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.34766, "epss_score": 0.0042, "exposure_hint": "exposure unknown", "human_consequence": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "human_impact_label": "critical severity review", "human_risk_summary": "CVE-2026-71237: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "id": "CVE-2026-71237", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "public_human_summary": "NVD: Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query(\"select * from userlists where username='' and password='' limit 1\").", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.; CVSS 9.8 (CRITICAL); EPSS percentile 35; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query(\"select * from userlists where username='' and password='' limit 1\").", "public_status": "public_safe", "published_at": "2026-08-05T11:16:26.503", "redaction_notes": ["source-published defensive context retained", "exploit string, command, scanner, or code-like detail removed", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71237-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71237.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71237.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71237"], "sort_priority": 98.34766, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query(\"select * from userlists where username='' and password='' limit 1\").", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/Miantang/IoT-PHP"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71237"}], "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query(\"select * from userlists where username='' and password='' limit 1\").", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71237 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.8. EPSS score is 0.0042 with percentile 0.3477. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71237 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 9.8, "disclosure_freshness": 0.9613, "epss_percentile": 0.34766, "epss_score": 0.0042, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71237", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.197000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 34.766, "priority_area": 98.3477, "published_at": "2026-08-05T11:16:26.503000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "critical", "source_count": 2}, "updated_at": "2026-08-10T12:17:26.197", "urgency_reasons": ["CVSS CRITICAL", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review; CVSS 9.8 (CRITICAL); EPSS percentile 35; sources: NVD."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71231/", "cvss_score": 9.8, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71231.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.28595, "epss_score": 0.00358, "exposure_hint": "exposure unknown", "human_consequence": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "human_impact_label": "critical severity review", "human_risk_summary": "CVE-2026-71231: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "id": "CVE-2026-71231", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "public_human_summary": "NVD: IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.; CVSS 9.8 (CRITICAL); EPSS percentile 29; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding...", "public_status": "public_safe", "published_at": "2026-08-05T11:16:25.740", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71231-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71231.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71231.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71231"], "sort_priority": 98.28595, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/thebradleysanders/IOTSmartHome"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71231"}], "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding...", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71231 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.8. EPSS score is 0.0036 with percentile 0.2859. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71231 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 9.8, "disclosure_freshness": 0.9613, "epss_percentile": 0.28595, "epss_score": 0.00358, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71231", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:25.533000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 28.595, "priority_area": 98.2859, "published_at": "2026-08-05T11:16:25.740000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "critical", "source_count": 2}, "updated_at": "2026-08-10T12:17:25.533", "urgency_reasons": ["CVSS CRITICAL", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review; CVSS 9.8 (CRITICAL); EPSS percentile 29; sources: NVD."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66747/", "cvss_score": 9.3, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-66747.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.44552, "epss_score": 0.00579, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may gain root or administrative-level privileges on affected systems.", "human_impact_label": "code execution review · admin privilege risk", "human_risk_summary": "CVE-2026-66747: An attacker may gain root or administrative-level privileges on affected systems.", "id": "CVE-2026-66747", "impact_tags": ["code execution review", "admin privilege risk"], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "Source describes code execution review · admin privilege risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.", "public_human_summary": "NVD: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. NVD: It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. NVD: It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes code execution review · admin privilege risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.; CVSS 9.3 (CRITICAL); EPSS percentile 45; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. NVD: It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. NVD: It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds.", "public_status": "public_safe", "published_at": "2026-08-05T11:16:25.510", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-66747-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-66747.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-66747.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-66747"], "sort_priority": 93.44552, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. NVD: It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. NVD: It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/ycsunjane/rctl"}, {"source": "Reference", "type": "reference", "url": "https://www.vulncheck.com/advisories/zbt-endlessdoors"}, {"source": "Reference", "type": "reference", "url": "https://www.vulncheck.com/blog/zbt-endlessdoors"}, {"source": "Reference", "type": "reference", "url": "https://www.zbtlink.com/pages/zbt-router-firmware-download"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66747"}], "source_published_impact": "Source describes code execution review · admin privilege risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. NVD: It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. NVD: It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-66747 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.3. EPSS score is 0.0058 with percentile 0.4455. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-66747 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 9.3, "disclosure_freshness": 0.9613, "epss_percentile": 0.44552, "epss_score": 0.00579, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-66747", "kev": false, "kev_date_added": null, "last_modified": "2026-08-05T15:17:04.690000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 44.552, "priority_area": 93.4455, "published_at": "2026-08-05T11:16:25.510000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "critical", "source_count": 2}, "updated_at": "2026-08-05T15:17:04.690", "urgency_reasons": ["CVSS CRITICAL", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may gain root or administrative-level privileges on affected systems; CVSS 9.3 (CRITICAL); EPSS percentile 45; sources: NVD."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71238/", "cvss_score": 9.1, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71238.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.23765, "epss_score": 0.00313, "exposure_hint": "exposure unknown", "human_consequence": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "human_impact_label": "critical severity review", "human_risk_summary": "CVE-2026-71238: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "id": "CVE-2026-71238", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "public_human_summary": "NVD: DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. NVD: Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.; CVSS 9.1 (CRITICAL); EPSS percentile 24; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. NVD: Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens...", "public_status": "public_safe", "published_at": "2026-08-05T11:16:26.630", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71238-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71238.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71238.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71238"], "sort_priority": 91.23765, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. NVD: Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/DjangoCRM/django-crm"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71238"}], "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. NVD: Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens...", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71238 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.1. EPSS score is 0.0031 with percentile 0.2377. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71238 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 9.1, "disclosure_freshness": 0.9613, "epss_percentile": 0.23765, "epss_score": 0.00313, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71238", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.307000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 23.765, "priority_area": 91.2377, "published_at": "2026-08-05T11:16:26.630000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "critical", "source_count": 2}, "updated_at": "2026-08-10T12:17:26.307", "urgency_reasons": ["CVSS CRITICAL", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review; CVSS 9.1 (CRITICAL); EPSS percentile 24; sources: NVD."}, {"affected_label": "eclipse / theia", "affected_products": [{"canonicalProduct": "theia", "canonicalVendor": "eclipse", "cpe": "cpe:2.3:a:eclipse:theia:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "theia", "purl": null, "vendor": "eclipse", "version": null}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60009/", "cvss_score": 8.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-60009.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.24854, "epss_score": 0.00323, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may be able to run code or commands on affected systems.", "human_impact_label": "code execution review", "human_risk_summary": "CVE-2026-60009 for eclipse / theia: An attacker may be able to run code or commands on affected systems.", "id": "CVE-2026-60009", "impact_tags": ["code execution review"], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": "theia", "public_human_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.", "public_human_summary": "NVD: In Eclipse Theia versions up to and including 1.73.1, the @theia/filesystem backend binds POST /file-upload in every filesystem-enabled deployment. NVD: The handler takes an attacker-supplied absolute path from the multipart uri field and calls fs.move(tmp, target, { overwrite: true }) with no workspace confinement and no authentication. NVD: In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in @theia/core re-issues the cookie and calls next() without rejecting tokenless HTTP requests.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.; CVSS 8.8 (HIGH); EPSS percentile 25; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV, Vendor Advisory.", "public_safe_summary": "NVD: In Eclipse Theia versions up to and including 1.73.1, the @theia/filesystem backend binds POST /file-upload in every filesystem-enabled deployment. NVD: The handler takes an attacker-supplied absolute path from the multipart uri field and calls fs.move(tmp, target, { overwrite: true }) with no workspace confinement and no authentication. NVD: In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in @theia/core re-issues the cookie and calls next() without rejecting tokenless HTTP requests.", "public_status": "public_safe", "published_at": "2026-08-05T11:16:25.363", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-60009-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-60009.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-60009.md", "scan_allowed": false}, "remediation_urls": ["https://github.com/eclipse-theia/theia/security/advisories/GHSA-62f6-wcvg-54h3", "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/177", "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/595", "https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/595"], "sort_priority": 88.24854, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "vendor/product: eclipse / theia", "source_published_description": "NVD: In Eclipse Theia versions up to and including 1.73.1, the @theia/filesystem backend binds POST /file-upload in every filesystem-enabled deployment. NVD: The handler takes an attacker-supplied absolute path from the multipart uri field and calls fs.move(tmp, target, { overwrite: true }) with no workspace confinement and no authentication. NVD: In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in @theia/core re-issues the cookie and calls next() without rejecting tokenless HTTP requests.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/eclipse-theia/theia/security/advisories/GHSA-62f6-wcvg-54h3"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/177"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/595"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/595"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-60009"}, {"source": "Official Reference", "type": "reference", "url": "https://osv.dev/vulnerability/CVE-2026-60009"}], "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: In Eclipse Theia versions up to and including 1.73.1, the @theia/filesystem backend binds POST /file-upload in every filesystem-enabled deployment. NVD: The handler takes an attacker-supplied absolute path from the multipart uri field and calls fs.move(tmp, target, { overwrite: true }) with no workspace confinement and no authentication. NVD: In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in @theia/core re-issues the cookie and calls next() without rejecting tokenless HTTP requests.", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2026-60009 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.8. EPSS score is 0.0032 with percentile 0.2485. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-60009 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 8.8, "disclosure_freshness": 0.9613, "epss_percentile": 0.24854, "epss_score": 0.00323, "evidence_confidence": 1.0, "fallbacks": [], "group_key": "canonical_vendor:eclipse", "group_label": "eclipse", "id": "cve:CVE-2026-60009", "kev": false, "kev_date_added": null, "last_modified": "2026-08-07T15:54:02.380000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 24.854, "priority_area": 88.2485, "published_at": "2026-08-05T11:16:25.363000Z", "remediation_reference_count": 4, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 6}, "updated_at": "2026-08-07T15:54:02.380", "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "eclipse", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to run code or commands on affected systems; CVSS 8.8 (HIGH); EPSS percentile 25; affected product context: eclipse / theia; sources: NVD, OSV, Vendor Advisory."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71235/", "cvss_score": 8.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71235.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.21126, "epss_score": 0.00288, "exposure_hint": "authenticated boundary", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.", "human_impact_label": "authenticated boundary", "human_risk_summary": "CVE-2026-71235: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.", "id": "CVE-2026-71235", "impact_tags": ["authenticated boundary review"], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.", "public_human_summary": "NVD: Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. NVD: The Lua script engine (re/lua.go) performs no input validation at all and preloads dangerous libraries: db (arbitrary database access), ioutil (file I/O), an HTTP client (SSRF), and filepath (traversal).", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.; CVSS 8.8 (HIGH); EPSS percentile 21; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. NVD: The Lua script engine (re/lua.go) performs no input validation at all and preloads dangerous libraries: db (arbitrary database access), ioutil (file I/O), an HTTP client (SSRF), and filepath (traversal).", "public_status": "public_safe", "published_at": "2026-08-05T11:16:26.247", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71235-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71235.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71235.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71235"], "sort_priority": 88.21126, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. NVD: The Lua script engine (re/lua.go) performs no input validation at all and preloads dangerous libraries: db (arbitrary database access), ioutil (file I/O), an HTTP client (SSRF), and filepath (traversal).", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/absmach/magistrala"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71235"}], "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. NVD: The Lua script engine (re/lua.go) performs no input validation at all and preloads dangerous libraries: db (arbitrary database access), ioutil (file I/O), an HTTP client (SSRF), and filepath (traversal).", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71235 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.8. EPSS score is 0.0029 with percentile 0.2113. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71235 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 8.8, "disclosure_freshness": 0.9613, "epss_percentile": 0.21126, "epss_score": 0.00288, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71235", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:25.983000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 21.126, "priority_area": 88.2113, "published_at": "2026-08-05T11:16:26.247000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 2}, "updated_at": "2026-08-10T12:17:25.983", "urgency_reasons": ["CVSS HIGH", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary; CVSS 8.8 (HIGH); EPSS percentile 21; sources: NVD."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71243/", "cvss_score": 8.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71243.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.21081, "epss_score": 0.00288, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may be able to run unintended system commands through the affected component.", "human_impact_label": "command injection risk", "human_risk_summary": "CVE-2026-71243: An attacker may be able to run unintended system commands through the affected component.", "id": "CVE-2026-71243", "impact_tags": ["command injection risk"], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.", "public_human_summary": "NVD: The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. NVD: cmd = \"mkdir -p \" + path.join(info.destination, info.name) + \"; \" - and executes the resulting string through a shell via ssh2-exec (locally via child_process, or remotely via SSH when an ssh handle is supplied), rather than using execFile/spawn with an... OSV: backmeup (npm) - OS Command Injection via Backup Option Values", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.; CVSS 8.8 (HIGH); EPSS percentile 21; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV.", "public_safe_summary": "NVD: The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. NVD: cmd = \"mkdir -p \" + path.join(info.destination, info.name) + \"; \" - and executes the resulting string through a shell via ssh2-exec (locally via child_process, or remotely via SSH when an ssh handle is supplied), rather than using execFile/spawn with an... OSV: backmeup (npm) - OS Command Injection via Backup Option Values", "public_status": "public_safe", "published_at": "2026-08-05T11:16:27.247", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71243-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71243.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71243.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71243", "https://osv.dev/vulnerability/CVE-2026-71243"], "sort_priority": 88.21081, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. NVD: cmd = \"mkdir -p \" + path.join(info.destination, info.name) + \"; \" - and executes the resulting string through a shell via ssh2-exec (locally via child_process, or remotely via SSH when an ssh handle is supplied), rather than using execFile/spawn with an... OSV: backmeup (npm) - OS Command Injection via Backup Option Values", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/adaltas/node-backmeup"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71243"}, {"source": "Official Reference", "type": "reference", "url": "https://osv.dev/vulnerability/CVE-2026-71243"}], "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. NVD: cmd = \"mkdir -p \" + path.join(info.destination, info.name) + \"; \" - and executes the resulting string through a shell via ssh2-exec (locally via child_process, or remotely via SSH when an ssh handle is supplied), rather than using execFile/spawn with an... OSV: backmeup (npm) - OS Command Injection via Backup Option Values", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2026-71243 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.8. EPSS score is 0.0029 with percentile 0.2108. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71243 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 8.8, "disclosure_freshness": 0.9613, "epss_percentile": 0.21081, "epss_score": 0.00288, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71243", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.857000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 21.081, "priority_area": 88.2108, "published_at": "2026-08-05T11:16:27.247000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 4}, "updated_at": "2026-08-10T12:17:26.857", "urgency_reasons": ["CVSS HIGH", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to run unintended system commands through the affected component; CVSS 8.8 (HIGH); EPSS percentile 21; sources: NVD, OSV."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71233/", "cvss_score": 8.7, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71233.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.0994, "epss_score": 0.00199, "exposure_hint": "exposure unknown", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "human_impact_label": "high severity review", "human_risk_summary": "CVE-2026-71233: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "id": "CVE-2026-71233", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "public_human_summary": "NVD: InvoiceNinja v5-stable renders an invoice or quote's \"terms\" field in the client portal using Laravel Blade's raw output directive {!! NVD: ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.; CVSS 8.7 (HIGH); EPSS percentile 10; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: InvoiceNinja v5-stable renders an invoice or quote's \"terms\" field in the client portal using Laravel Blade's raw output directive {!! NVD: ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization.", "public_status": "public_safe", "published_at": "2026-08-05T11:16:25.997", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71233-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71233.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71233.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71233"], "sort_priority": 87.0994, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: InvoiceNinja v5-stable renders an invoice or quote's \"terms\" field in the client portal using Laravel Blade's raw output directive {!! NVD: ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/invoiceninja/invoiceninja"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71233"}], "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: InvoiceNinja v5-stable renders an invoice or quote's \"terms\" field in the client portal using Laravel Blade's raw output directive {!! NVD: ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71233 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.7. EPSS score is 0.0020 with percentile 0.0994. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71233 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 8.7, "disclosure_freshness": 0.9613, "epss_percentile": 0.0994, "epss_score": 0.00199, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71233", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:25.770000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 9.94, "priority_area": 87.0994, "published_at": "2026-08-05T11:16:25.997000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 2}, "updated_at": "2026-08-10T12:17:25.770", "urgency_reasons": ["CVSS HIGH", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 8.7 (HIGH); EPSS percentile 10; sources: NVD."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71236/", "cvss_score": 8.7, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71236.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.0994, "epss_score": 0.00199, "exposure_hint": "exposure unknown", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "human_impact_label": "high severity review", "human_risk_summary": "CVE-2026-71236: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "id": "CVE-2026-71236", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "public_human_summary": "NVD: Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HTML-entity encoding of the resulting output by replacing &amp;lt;, &amp;gt;, and...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.; CVSS 8.7 (HIGH); EPSS percentile 10; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HTML-entity encoding of the resulting output by replacing &amp;lt;, &amp;gt;, and...", "public_status": "public_safe", "published_at": "2026-08-05T11:16:26.377", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71236-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71236.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71236.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71236"], "sort_priority": 87.0994, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HTML-entity encoding of the resulting output by replacing &amp;lt;, &amp;gt;, and...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/grocy/grocy"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71236"}], "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HTML-entity encoding of the resulting output by replacing &amp;lt;, &amp;gt;, and...", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71236 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.7. EPSS score is 0.0020 with percentile 0.0994. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71236 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 8.7, "disclosure_freshness": 0.9613, "epss_percentile": 0.0994, "epss_score": 0.00199, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71236", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.090000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 9.94, "priority_area": 87.0994, "published_at": "2026-08-05T11:16:26.377000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 2}, "updated_at": "2026-08-10T12:17:26.090", "urgency_reasons": ["CVSS HIGH", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 8.7 (HIGH); EPSS percentile 10; sources: NVD."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71242/", "cvss_score": 8.3, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71242.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.12013, "epss_score": 0.00215, "exposure_hint": "authenticated boundary", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.", "human_impact_label": "authenticated boundary", "human_risk_summary": "CVE-2026-71242: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.", "id": "CVE-2026-71242", "impact_tags": ["authenticated boundary review"], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.", "public_human_summary": "NVD: Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify ->hasCompany(->company_id). NVD: Any authenticated user of one company can read, edit, or delete another company's notes by ID. OSV: Crater - Cross-Company IDOR on Notes via Missing Company-Ownership Check in NotePolicy", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.; CVSS 8.3 (HIGH); EPSS percentile 12; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV.", "public_safe_summary": "NVD: Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify ->hasCompany(->company_id). NVD: Any authenticated user of one company can read, edit, or delete another company's notes by ID. OSV: Crater - Cross-Company IDOR on Notes via Missing Company-Ownership Check in NotePolicy", "public_status": "public_safe", "published_at": "2026-08-05T11:16:27.123", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71242-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71242.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71242.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71242", "https://osv.dev/vulnerability/CVE-2026-71242"], "sort_priority": 83.12013, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify ->hasCompany(->company_id). NVD: Any authenticated user of one company can read, edit, or delete another company's notes by ID. OSV: Crater - Cross-Company IDOR on Notes via Missing Company-Ownership Check in NotePolicy", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/crater-invoice/crater"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71242"}, {"source": "Official Reference", "type": "reference", "url": "https://osv.dev/vulnerability/CVE-2026-71242"}], "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify ->hasCompany(->company_id). NVD: Any authenticated user of one company can read, edit, or delete another company's notes by ID. OSV: Crater - Cross-Company IDOR on Notes via Missing Company-Ownership Check in NotePolicy", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2026-71242 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.3. EPSS score is 0.0022 with percentile 0.1201. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71242 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 8.3, "disclosure_freshness": 0.9613, "epss_percentile": 0.12013, "epss_score": 0.00215, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71242", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.747000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 12.013, "priority_area": 83.1201, "published_at": "2026-08-05T11:16:27.123000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 4}, "updated_at": "2026-08-10T12:17:26.747", "urgency_reasons": ["CVSS HIGH", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary; CVSS 8.3 (HIGH); EPSS percentile 12; sources: NVD, OSV."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71239/", "cvss_score": 8.1, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71239.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.13231, "epss_score": 0.00225, "exposure_hint": "exposure unknown", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "human_impact_label": "high severity review", "human_risk_summary": "CVE-2026-71239: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "id": "CVE-2026-71239", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "public_human_summary": "NVD: DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no sanitization, in at least three locations: message_previews.py builds an f-string embedding message.subject/message.content...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.; CVSS 8.1 (HIGH); EPSS percentile 13; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no sanitization, in at least three locations: message_previews.py builds an f-string embedding message.subject/message.content...", "public_status": "public_safe", "published_at": "2026-08-05T11:16:26.750", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71239-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71239.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71239.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71239"], "sort_priority": 81.13231, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no sanitization, in at least three locations: message_previews.py builds an f-string embedding message.subject/message.content...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/DjangoCRM/django-crm"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71239"}], "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no sanitization, in at least three locations: message_previews.py builds an f-string embedding message.subject/message.content...", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71239 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.1. EPSS score is 0.0022 with percentile 0.1323. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71239 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 8.1, "disclosure_freshness": 0.9613, "epss_percentile": 0.13231, "epss_score": 0.00225, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71239", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.417000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 13.231, "priority_area": 81.1323, "published_at": "2026-08-05T11:16:26.750000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 2}, "updated_at": "2026-08-10T12:17:26.417", "urgency_reasons": ["CVSS HIGH", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 8.1 (HIGH); EPSS percentile 13; sources: NVD."}, {"affected_label": "eclipse / theia", "affected_products": [{"canonicalProduct": "theia", "canonicalVendor": "eclipse", "cpe": "cpe:2.3:a:eclipse:theia:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "theia", "purl": null, "vendor": "eclipse", "version": null}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12609/", "cvss_score": 7.5, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-12609.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.3374, "epss_score": 0.00409, "exposure_hint": "remote exposure", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.", "human_impact_label": "remote exposure", "human_risk_summary": "CVE-2026-12609 for eclipse / theia: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.", "id": "CVE-2026-12609", "impact_tags": ["remote exposure relevant"], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": "theia", "public_human_impact": "Source describes remote exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.", "public_human_summary": "NVD: In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the @theia/plugin-ext backend exposes the /hostedPlugin/:pluginId/:path(*) HTTP endpoint, which resolves the requested file path with path.resolve(localPath, filePath) without verifying that the... NVD: An unauthenticated network attacker can send percent-encoded ../ sequences (%2e%2e%2f) that decode into the path parameter and escape the plugin directory, allowing arbitrary files readable by the Theia backend process to be retrieved. NVD: Plugin IDs are derived deterministically from a plugin's publisher and name, so built-in plugins serve as reliable anchors that require no prior knowledge of the target system.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes remote exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.; CVSS 7.5 (HIGH); EPSS percentile 34; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV, Vendor Advisory.", "public_safe_summary": "NVD: In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the @theia/plugin-ext backend exposes the /hostedPlugin/:pluginId/:path(*) HTTP endpoint, which resolves the requested file path with path.resolve(localPath, filePath) without verifying that the... NVD: An unauthenticated network attacker can send percent-encoded ../ sequences (%2e%2e%2f) that decode into the path parameter and escape the plugin directory, allowing arbitrary files readable by the Theia backend process to be retrieved. NVD: Plugin IDs are derived deterministically from a plugin's publisher and name, so built-in plugins serve as reliable anchors that require no prior knowledge of the target system.", "public_status": "public_safe", "published_at": "2026-08-05T11:16:24.080", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-12609-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-12609.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-12609.md", "scan_allowed": false}, "remediation_urls": ["https://github.com/eclipse-theia/theia/security/advisories/GHSA-qmm6-p8q4-2g48", "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/133", "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/524"], "sort_priority": 75.3374, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "vendor/product: eclipse / theia", "source_published_description": "NVD: In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the @theia/plugin-ext backend exposes the /hostedPlugin/:pluginId/:path(*) HTTP endpoint, which resolves the requested file path with path.resolve(localPath, filePath) without verifying that the... NVD: An unauthenticated network attacker can send percent-encoded ../ sequences (%2e%2e%2f) that decode into the path parameter and escape the plugin directory, allowing arbitrary files readable by the Theia backend process to be retrieved. NVD: Plugin IDs are derived deterministically from a plugin's publisher and name, so built-in plugins serve as reliable anchors that require no prior knowledge of the target system.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/eclipse-theia/theia/security/advisories/GHSA-qmm6-p8q4-2g48"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/133"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/524"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12609"}, {"source": "Official Reference", "type": "reference", "url": "https://osv.dev/vulnerability/CVE-2026-12609"}], "source_published_impact": "Source describes remote exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the @theia/plugin-ext backend exposes the /hostedPlugin/:pluginId/:path(*) HTTP endpoint, which resolves the requested file path with path.resolve(localPath, filePath) without verifying that the... NVD: An unauthenticated network attacker can send percent-encoded ../ sequences (%2e%2e%2f) that decode into the path parameter and escape the plugin directory, allowing arbitrary files readable by the Theia backend process to be retrieved. NVD: Plugin IDs are derived deterministically from a plugin's publisher and name, so built-in plugins serve as reliable anchors that require no prior knowledge of the target system.", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2026-12609 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 7.5. EPSS score is 0.0041 with percentile 0.3374. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-12609 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 7.5, "disclosure_freshness": 0.9613, "epss_percentile": 0.3374, "epss_score": 0.00409, "evidence_confidence": 1.0, "fallbacks": [], "group_key": "canonical_vendor:eclipse", "group_label": "eclipse", "id": "cve:CVE-2026-12609", "kev": false, "kev_date_added": null, "last_modified": "2026-08-07T20:23:46.517000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 33.74, "priority_area": 75.3374, "published_at": "2026-08-05T11:16:24.080000Z", "remediation_reference_count": 3, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 6}, "updated_at": "2026-08-07T20:23:46.517", "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "eclipse", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure; CVSS 7.5 (HIGH); EPSS percentile 34; affected product context: eclipse / theia; sources: NVD, OSV, Vendor Advisory."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71241/", "cvss_score": 7.5, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71241.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.20477, "epss_score": 0.00282, "exposure_hint": "exposure unknown", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "human_impact_label": "high severity review", "human_risk_summary": "CVE-2026-71241: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "id": "CVE-2026-71241", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "public_human_summary": "NVD: Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. NVD: Because card_id values are sequential integers, the entire student database can be enumerated without authentication.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.; CVSS 7.5 (HIGH); EPSS percentile 20; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. NVD: Because card_id values are sequential integers, the entire student database can be enumerated without authentication.", "public_status": "public_safe", "published_at": "2026-08-05T11:16:26.997", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71241-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71241.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71241.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71241"], "sort_priority": 75.20477, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. NVD: Because card_id values are sequential integers, the entire student database can be enumerated without authentication.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/lyric777/Book-Management-System"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71241"}], "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. NVD: Because card_id values are sequential integers, the entire student database can be enumerated without authentication.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71241 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 7.5. EPSS score is 0.0028 with percentile 0.2048. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71241 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 7.5, "disclosure_freshness": 0.9613, "epss_percentile": 0.20477, "epss_score": 0.00282, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71241", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.633000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 20.477, "priority_area": 75.2048, "published_at": "2026-08-05T11:16:26.997000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 2}, "updated_at": "2026-08-10T12:17:26.633", "urgency_reasons": ["CVSS HIGH", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 7.5 (HIGH); EPSS percentile 20; sources: NVD."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71234/", "cvss_score": 7.5, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71234.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.15873, "epss_score": 0.00245, "exposure_hint": "exposure unknown", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "human_impact_label": "high severity review", "human_risk_summary": "CVE-2026-71234: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "id": "CVE-2026-71234", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "public_human_summary": "NVD: Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a query parameter and grants access whenever the parameter is simply non-empty (len(secureToken) > 0)...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.; CVSS 7.5 (HIGH); EPSS percentile 16; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a query parameter and grants access whenever the parameter is simply non-empty (len(secureToken) > 0)...", "public_status": "public_safe", "published_at": "2026-08-05T11:16:26.120", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71234-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71234.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71234.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71234"], "sort_priority": 75.15873, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a query parameter and grants access whenever the parameter is simply non-empty (len(secureToken) > 0)...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/documize/community"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71234"}], "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a query parameter and grants access whenever the parameter is simply non-empty (len(secureToken) > 0)...", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71234 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 7.5. EPSS score is 0.0024 with percentile 0.1587. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71234 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 7.5, "disclosure_freshness": 0.9613, "epss_percentile": 0.15873, "epss_score": 0.00245, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71234", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:25.880000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 15.873, "priority_area": 75.1587, "published_at": "2026-08-05T11:16:26.120000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 2}, "updated_at": "2026-08-10T12:17:25.880", "urgency_reasons": ["CVSS HIGH", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 7.5 (HIGH); EPSS percentile 16; sources: NVD."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71232/", "cvss_score": 7.2, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71232.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.22368, "epss_score": 0.003, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may be able to run code or commands on affected systems.", "human_impact_label": "code execution review", "human_risk_summary": "CVE-2026-71232: An attacker may be able to run code or commands on affected systems.", "id": "CVE-2026-71232", "impact_tags": ["code execution review"], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.", "public_human_summary": "NVD: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function... OSV: MacCMS10 - Incomplete Function Blacklist in Template Editor Enables Authenticated RCE OSV: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.; CVSS 7.2 (HIGH); EPSS percentile 22; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV.", "public_safe_summary": "NVD: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function... OSV: MacCMS10 - Incomplete Function Blacklist in Template Editor Enables Authenticated RCE OSV: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function...", "public_status": "public_safe", "published_at": "2026-08-05T11:16:25.873", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71232-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71232.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71232.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71232", "https://osv.dev/vulnerability/CVE-2026-71232"], "sort_priority": 72.22368, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function... OSV: MacCMS10 - Incomplete Function Blacklist in Template Editor Enables Authenticated RCE OSV: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/magicblack/maccms10/commit/71ad3bb29570e110d8e973acff68040a3050ddf0"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71232"}, {"source": "Official Reference", "type": "reference", "url": "https://osv.dev/vulnerability/CVE-2026-71232"}], "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function... OSV: MacCMS10 - Incomplete Function Blacklist in Template Editor Enables Authenticated RCE OSV: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function...", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2026-71232 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 7.2. EPSS score is 0.0030 with percentile 0.2237. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71232 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 7.2, "disclosure_freshness": 0.9613, "epss_percentile": 0.22368, "epss_score": 0.003, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71232", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:25.650000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 22.368, "priority_area": 72.2237, "published_at": "2026-08-05T11:16:25.873000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 4}, "updated_at": "2026-08-10T12:17:25.650", "urgency_reasons": ["CVSS HIGH", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to run code or commands on affected systems; CVSS 7.2 (HIGH); EPSS percentile 22; sources: NVD, OSV."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71244/", "cvss_score": 6.5, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71244.json", "defensive_priority": "Routine monitoring candidate", "epss_percentile": 0.10156, "epss_score": 0.00201, "exposure_hint": "exposure unknown", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "human_impact_label": "defensive exposure review", "human_risk_summary": "CVE-2026-71244: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "id": "CVE-2026-71244", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "public_human_summary": "NVD: Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.; CVSS 6.5 (MEDIUM); EPSS percentile 10; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a...", "public_status": "public_safe", "published_at": "2026-08-05T11:16:27.367", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71244-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71244.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71244.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71244"], "sort_priority": 65.10156, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/paperless-ngx/paperless-ngx"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71244"}], "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a...", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71244 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 6.5. EPSS score is 0.0020 with percentile 0.1016. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71244 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 6.5, "disclosure_freshness": 0.9613, "epss_percentile": 0.10156, "epss_score": 0.00201, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71244", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.970000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 10.156, "priority_area": 65.1016, "published_at": "2026-08-05T11:16:27.367000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "medium", "source_count": 2}, "updated_at": "2026-08-10T12:17:26.970", "urgency_reasons": ["vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 6.5 (MEDIUM); EPSS percentile 10; sources: NVD."}, {"affected_label": "eclipse / theia", "affected_products": [{"canonicalProduct": "theia", "canonicalVendor": "eclipse", "cpe": "cpe:2.3:a:eclipse:theia:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "theia", "purl": null, "vendor": "eclipse", "version": null}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14574/", "cvss_score": 5.7, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-14574.json", "defensive_priority": "Routine monitoring candidate", "epss_percentile": 0.20449, "epss_score": 0.00282, "exposure_hint": "exposure unknown", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "human_impact_label": "defensive exposure review", "human_risk_summary": "CVE-2026-14574 for eclipse / theia: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "id": "CVE-2026-14574", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": "theia", "public_human_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "public_human_summary": "NVD: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype). NVD: Because this function is invoked by PreferenceServiceImpl.doResolve for every preference resolution across scopes (default, user, workspace, folder), a crafted preference value in a workspace settings file (.theia/settings.json or .vscode/settings.json) can... OSV: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype).", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.; CVSS 5.7 (MEDIUM); EPSS percentile 20; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV, Vendor Advisory.", "public_safe_summary": "NVD: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype). NVD: Because this function is invoked by PreferenceServiceImpl.doResolve for every preference resolution across scopes (default, user, workspace, folder), a crafted preference value in a workspace settings file (.theia/settings.json or .vscode/settings.json) can... OSV: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype).", "public_status": "public_safe", "published_at": "2026-08-05T11:16:25.030", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14574-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14574.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14574.md", "scan_allowed": false}, "remediation_urls": ["https://github.com/eclipse-theia/theia/security/advisories/GHSA-f3w9-qfw3-xr32", "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/157", "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/567", "https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/567"], "sort_priority": 57.20449, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "vendor/product: eclipse / theia", "source_published_description": "NVD: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype). NVD: Because this function is invoked by PreferenceServiceImpl.doResolve for every preference resolution across scopes (default, user, workspace, folder), a crafted preference value in a workspace settings file (.theia/settings.json or .vscode/settings.json) can... OSV: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype).", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/eclipse-theia/theia/security/advisories/GHSA-f3w9-qfw3-xr32"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/157"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/567"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/567"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14574"}, {"source": "Official Reference", "type": "reference", "url": "https://osv.dev/vulnerability/CVE-2026-14574"}], "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype). NVD: Because this function is invoked by PreferenceServiceImpl.doResolve for every preference resolution across scopes (default, user, workspace, folder), a crafted preference value in a workspace settings file (.theia/settings.json or .vscode/settings.json) can... OSV: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype).", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2026-14574 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 5.7. EPSS score is 0.0028 with percentile 0.2045. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-14574 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 5.7, "disclosure_freshness": 0.9613, "epss_percentile": 0.20449, "epss_score": 0.00282, "evidence_confidence": 1.0, "fallbacks": [], "group_key": "canonical_vendor:eclipse", "group_label": "eclipse", "id": "cve:CVE-2026-14574", "kev": false, "kev_date_added": null, "last_modified": "2026-08-07T16:02:40.473000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 20.449, "priority_area": 57.2045, "published_at": "2026-08-05T11:16:25.030000Z", "remediation_reference_count": 4, "schema_version": "vuln-treemap-node-v1", "severity": "medium", "source_count": 6}, "updated_at": "2026-08-07T16:02:40.473", "urgency_reasons": ["affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "eclipse", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.7 (MEDIUM); EPSS percentile 20; affected product context: eclipse / theia; sources: NVD, OSV, Vendor Advisory."}, {"affected_label": "eclipse / accessibility_tools_framework", "affected_products": [{"canonicalProduct": "accessibility_tools_framework", "canonicalVendor": "eclipse", "cpe": "cpe:2.3:a:eclipse:accessibility_tools_framework:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "accessibility_tools_framework", "purl": null, "vendor": "eclipse", "version": null}, {"canonicalProduct": "michecker", "canonicalVendor": "soumu", "cpe": "cpe:2.3:a:soumu:michecker:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "michecker", "purl": null, "vendor": "soumu", "version": null}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14304/", "cvss_score": 4.6, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-14304.json", "defensive_priority": "Routine monitoring candidate", "epss_percentile": 0.06863, "epss_score": 0.00172, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may cross a privilege boundary and gain more access than intended.", "human_impact_label": "privilege escalation risk", "human_risk_summary": "CVE-2026-14304 for eclipse / accessibility_tools_framework: An attacker may cross a privilege boundary and gain more access than intended.", "id": "CVE-2026-14304", "impact_tags": ["privilege boundary review"], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": "accessibility_tools_framework", "public_human_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.", "public_human_summary": "NVD: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. NVD: If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker. OSV: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.; CVSS 4.6 (MEDIUM); EPSS percentile 7; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV, Vendor Advisory.", "public_safe_summary": "NVD: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. NVD: If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker. OSV: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists.", "public_status": "public_safe", "published_at": "2026-08-05T11:16:24.887", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14304-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14304.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14304.md", "scan_allowed": false}, "remediation_urls": ["https://eclipse.dev/actf/downloads/tools/miChecker/vulnerability.html", "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/151"], "sort_priority": 46.06863, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "vendor/product: eclipse / accessibility_tools_framework", "source_published_description": "NVD: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. NVD: If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker. OSV: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "reference", "url": "https://eclipse.dev/actf/downloads/tools/miChecker/vulnerability.html"}, {"source": "Reference", "type": "reference", "url": "https://github.com/eclipse-actf/org.eclipse.actf"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/151"}, {"source": "Reference", "type": "reference", "url": "https://www.soumu.go.jp/info-accessibility-portal/webaccessibility/michecker/"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14304"}, {"source": "Official Reference", "type": "reference", "url": "https://osv.dev/vulnerability/CVE-2026-14304"}], "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. NVD: If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker. OSV: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists.", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2026-14304 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 4.6. EPSS score is 0.0017 with percentile 0.0686. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-14304 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 4.6, "disclosure_freshness": 0.9613, "epss_percentile": 0.06863, "epss_score": 0.00172, "evidence_confidence": 1.0, "fallbacks": [], "group_key": "canonical_vendor:eclipse", "group_label": "eclipse", "id": "cve:CVE-2026-14304", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T19:01:10.803000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 6.863, "priority_area": 46.0686, "published_at": "2026-08-05T11:16:24.887000Z", "remediation_reference_count": 2, "schema_version": "vuln-treemap-node-v1", "severity": "medium", "source_count": 6}, "updated_at": "2026-08-10T19:01:10.803", "urgency_reasons": ["affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "eclipse", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may cross a privilege boundary and gain more access than intended; CVSS 4.6 (MEDIUM); EPSS percentile 7; affected product context: eclipse / accessibility_tools_framework; sources: NVD, OSV, Vendor Advisory."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71240/", "cvss_score": 4.3, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71240.json", "defensive_priority": "Routine monitoring candidate", "epss_percentile": 0.08769, "epss_score": 0.00189, "exposure_hint": "exposure unknown", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "human_impact_label": "defensive exposure review", "human_risk_summary": "CVE-2026-71240: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "id": "CVE-2026-71240", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "public_human_summary": "NVD: DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or staff_member_required, and it redirects to a caller-supplied next_url GET parameter after only checking secure_url(next_url), which merely...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.; CVSS 4.3 (MEDIUM); EPSS percentile 9; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or staff_member_required, and it redirects to a caller-supplied next_url GET parameter after only checking secure_url(next_url), which merely...", "public_status": "public_safe", "published_at": "2026-08-05T11:16:26.873", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71240-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71240.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71240.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71240"], "sort_priority": 43.08769, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or staff_member_required, and it redirects to a caller-supplied next_url GET parameter after only checking secure_url(next_url), which merely...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/DjangoCRM/django-crm"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71240"}], "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or staff_member_required, and it redirects to a caller-supplied next_url GET parameter after only checking secure_url(next_url), which merely...", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71240 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 4.3. EPSS score is 0.0019 with percentile 0.0877. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71240 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 4.3, "disclosure_freshness": 0.9613, "epss_percentile": 0.08769, "epss_score": 0.00189, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71240", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.527000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 8.769, "priority_area": 43.0877, "published_at": "2026-08-05T11:16:26.873000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "medium", "source_count": 2}, "updated_at": "2026-08-10T12:17:26.527", "urgency_reasons": ["vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 4.3 (MEDIUM); EPSS percentile 9; sources: NVD."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17578/", "cvss_score": 2.3, "cvss_severity": "LOW", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-17578.json", "defensive_priority": "Routine monitoring candidate", "epss_percentile": 0.04712, "epss_score": 0.0015, "exposure_hint": "exposure unknown", "human_consequence": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "human_impact_label": "defensive exposure review", "human_risk_summary": "CVE-2026-17578: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "id": "CVE-2026-17578", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "public_human_summary": "NVD: Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled. NVD: If a producer sends messages at a sustained high rate without key rotation, which only occurs on reboot of the Kong Event Gateway instance, the probability of a nonce collision becomes non-negligible. NVD: An authorized consumer who detects a nonce collision can recover parts of plaintext from the affected messages.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.; CVSS 2.3 (LOW); EPSS percentile 5; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled. NVD: If a producer sends messages at a sustained high rate without key rotation, which only occurs on reboot of the Kong Event Gateway instance, the probability of a nonce collision becomes non-negligible. NVD: An authorized consumer who detects a nonce collision can recover parts of plaintext from the affected messages.", "public_status": "public_safe", "published_at": "2026-08-05T11:16:25.197", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-17578-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-17578.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-17578.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-17578"], "sort_priority": 23.04712, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled. NVD: If a producer sends messages at a sustained high rate without key rotation, which only occurs on reboot of the Kong Event Gateway instance, the probability of a nonce collision becomes non-negligible. NVD: An authorized consumer who detects a nonce collision can recover parts of plaintext from the affected messages.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://developer.konghq.com/event-gateway/changelog/"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-17578"}], "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled. NVD: If a producer sends messages at a sustained high rate without key rotation, which only occurs on reboot of the Kong Event Gateway instance, the probability of a nonce collision becomes non-negligible. NVD: An authorized consumer who detects a nonce collision can recover parts of plaintext from the affected messages.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-17578 is a defensive prioritization candidate. NVD lists CVSS severity as LOW. CVSS score is 2.3. EPSS score is 0.0015 with percentile 0.0471. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-17578 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 2.3, "disclosure_freshness": 0.9613, "epss_percentile": 0.04712, "epss_score": 0.0015, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-17578", "kev": false, "kev_date_added": null, "last_modified": "2026-08-05T14:17:04.187000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 6.0, "priority_area": 23.0471, "published_at": "2026-08-05T11:16:25.197000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "low", "source_count": 2}, "updated_at": "2026-08-05T14:17:04.187", "urgency_reasons": ["vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 2.3 (LOW); EPSS percentile 5; sources: NVD."}], "footerStats": {"dataSources": 3, "itemCount": 20}, "generatedAt": "2026-08-12T10:39:32.977657+00:00", "observedBuckets": {"2026-08-12": 20}, "reportPreview": {"count": 20, "defensive_checklist": ["Confirm affected products", "Review official source references", "Prioritize KEV, critical CVSS, and high EPSS percentile items", "Record human confirmation"], "mode": "read_only_public_beta_dashboard", "safety": {"procedural_detail": false, "public_launch": true, "scanner_execution": false}, "severity_distribution": {"CRITICAL": 4, "HIGH": 11, "LOW": 1, "MEDIUM": 4, "NONE": 0, "UNKNOWN": 0}, "top_risk": "CVE-2026-71237"}, "severityDistribution": {"CRITICAL": 4, "HIGH": 11, "LOW": 1, "MEDIUM": 4, "NONE": 0, "UNKNOWN": 0}, "sourceDistribution": {"NVD": 20, "OSV": 7, "Vendor Advisory": 20}, "sourceHealth": {"deploy_mode": "fresh_fetch", "errors": [], "generated_at": "2026-08-12T10:29:37.203277+00:00", "normalized_count": 20, "note": "Latest public surface was generated from a successful safety-gated source fetch.", "public_safe_count": 20, "source_counts": {"epss": 20, "nvd": 20, "osv": 7}, "source_error_count": 0, "status": "healthy", "summary_available": true}, "sourceStatus": [{"count": 20, "errorType": null, "lastObserved": "2026-08-12", "name": "NVD", "status": "healthy"}, {"count": 20, "errorType": null, "lastObserved": "2026-08-12", "name": "EPSS", "status": "healthy"}, {"count": 7, "errorType": null, "lastObserved": "2026-08-12", "name": "OSV", "status": "healthy"}, {"count": 0, "errorType": null, "lastObserved": "2026-08-12", "name": "CISA KEV", "status": "not observed"}, {"count": 20, "errorType": null, "lastObserved": "2026-08-12", "name": "Vendor Advisory", "status": "observed"}], "topRisks": [{"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71237/", "cvss_score": 9.8, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71237.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.34766, "epss_score": 0.0042, "exposure_hint": "exposure unknown", "human_consequence": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "human_impact_label": "critical severity review", "human_risk_summary": "CVE-2026-71237: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "id": "CVE-2026-71237", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "public_human_summary": "NVD: Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query(\"select * from userlists where username='' and password='' limit 1\").", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.; CVSS 9.8 (CRITICAL); EPSS percentile 35; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query(\"select * from userlists where username='' and password='' limit 1\").", "public_status": "public_safe", "published_at": "2026-08-05T11:16:26.503", "redaction_notes": ["source-published defensive context retained", "exploit string, command, scanner, or code-like detail removed", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71237-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71237.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71237.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71237"], "sort_priority": 98.34766, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query(\"select * from userlists where username='' and password='' limit 1\").", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/Miantang/IoT-PHP"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71237"}], "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query(\"select * from userlists where username='' and password='' limit 1\").", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71237 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.8. EPSS score is 0.0042 with percentile 0.3477. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71237 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 9.8, "disclosure_freshness": 0.9613, "epss_percentile": 0.34766, "epss_score": 0.0042, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71237", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.197000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 34.766, "priority_area": 98.3477, "published_at": "2026-08-05T11:16:26.503000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "critical", "source_count": 2}, "updated_at": "2026-08-10T12:17:26.197", "urgency_reasons": ["CVSS CRITICAL", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review; CVSS 9.8 (CRITICAL); EPSS percentile 35; sources: NVD."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71231/", "cvss_score": 9.8, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71231.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.28595, "epss_score": 0.00358, "exposure_hint": "exposure unknown", "human_consequence": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "human_impact_label": "critical severity review", "human_risk_summary": "CVE-2026-71231: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "id": "CVE-2026-71231", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "public_human_summary": "NVD: IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.; CVSS 9.8 (CRITICAL); EPSS percentile 29; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding...", "public_status": "public_safe", "published_at": "2026-08-05T11:16:25.740", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71231-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71231.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71231.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71231"], "sort_priority": 98.28595, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/thebradleysanders/IOTSmartHome"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71231"}], "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding...", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71231 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.8. EPSS score is 0.0036 with percentile 0.2859. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71231 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 9.8, "disclosure_freshness": 0.9613, "epss_percentile": 0.28595, "epss_score": 0.00358, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71231", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:25.533000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 28.595, "priority_area": 98.2859, "published_at": "2026-08-05T11:16:25.740000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "critical", "source_count": 2}, "updated_at": "2026-08-10T12:17:25.533", "urgency_reasons": ["CVSS CRITICAL", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review; CVSS 9.8 (CRITICAL); EPSS percentile 29; sources: NVD."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66747/", "cvss_score": 9.3, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-66747.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.44552, "epss_score": 0.00579, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may gain root or administrative-level privileges on affected systems.", "human_impact_label": "code execution review · admin privilege risk", "human_risk_summary": "CVE-2026-66747: An attacker may gain root or administrative-level privileges on affected systems.", "id": "CVE-2026-66747", "impact_tags": ["code execution review", "admin privilege risk"], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "Source describes code execution review · admin privilege risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.", "public_human_summary": "NVD: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. NVD: It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. NVD: It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes code execution review · admin privilege risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.; CVSS 9.3 (CRITICAL); EPSS percentile 45; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. NVD: It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. NVD: It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds.", "public_status": "public_safe", "published_at": "2026-08-05T11:16:25.510", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-66747-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-66747.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-66747.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-66747"], "sort_priority": 93.44552, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. NVD: It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. NVD: It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/ycsunjane/rctl"}, {"source": "Reference", "type": "reference", "url": "https://www.vulncheck.com/advisories/zbt-endlessdoors"}, {"source": "Reference", "type": "reference", "url": "https://www.vulncheck.com/blog/zbt-endlessdoors"}, {"source": "Reference", "type": "reference", "url": "https://www.zbtlink.com/pages/zbt-router-firmware-download"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66747"}], "source_published_impact": "Source describes code execution review · admin privilege risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. NVD: It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. NVD: It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-66747 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.3. EPSS score is 0.0058 with percentile 0.4455. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-66747 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 9.3, "disclosure_freshness": 0.9613, "epss_percentile": 0.44552, "epss_score": 0.00579, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-66747", "kev": false, "kev_date_added": null, "last_modified": "2026-08-05T15:17:04.690000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 44.552, "priority_area": 93.4455, "published_at": "2026-08-05T11:16:25.510000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "critical", "source_count": 2}, "updated_at": "2026-08-05T15:17:04.690", "urgency_reasons": ["CVSS CRITICAL", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may gain root or administrative-level privileges on affected systems; CVSS 9.3 (CRITICAL); EPSS percentile 45; sources: NVD."}, {"affected_label": "-", "affected_products": [], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71238/", "cvss_score": 9.1, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71238.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.23765, "epss_score": 0.00313, "exposure_hint": "exposure unknown", "human_consequence": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "human_impact_label": "critical severity review", "human_risk_summary": "CVE-2026-71238: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "id": "CVE-2026-71238", "impact_tags": [], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": null, "public_human_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "public_human_summary": "NVD: DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. NVD: Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.; CVSS 9.1 (CRITICAL); EPSS percentile 24; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. NVD: Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens...", "public_status": "public_safe", "published_at": "2026-08-05T11:16:26.630", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71238-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71238.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71238.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2026-71238"], "sort_priority": 91.23765, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "Affected product or version requires source confirmation.", "source_published_description": "NVD: DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. NVD: Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/DjangoCRM/django-crm"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71238"}], "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. NVD: Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens...", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2026-71238 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.1. EPSS score is 0.0031 with percentile 0.2377. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-71238 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 9.1, "disclosure_freshness": 0.9613, "epss_percentile": 0.23765, "epss_score": 0.00313, "evidence_confidence": 0.6667, "fallbacks": ["group:unmapped"], "group_key": "unmapped", "group_label": "UNMAPPED", "id": "cve:CVE-2026-71238", "kev": false, "kev_date_added": null, "last_modified": "2026-08-10T12:17:26.307000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 23.765, "priority_area": 91.2377, "published_at": "2026-08-05T11:16:26.630000Z", "remediation_reference_count": 0, "schema_version": "vuln-treemap-node-v1", "severity": "critical", "source_count": 2}, "updated_at": "2026-08-10T12:17:26.307", "urgency_reasons": ["CVSS CRITICAL", "vendor advisory present", "recent update"], "vendor": null, "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review; CVSS 9.1 (CRITICAL); EPSS percentile 24; sources: NVD."}, {"affected_label": "eclipse / theia", "affected_products": [{"canonicalProduct": "theia", "canonicalVendor": "eclipse", "cpe": "cpe:2.3:a:eclipse:theia:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "theia", "purl": null, "vendor": "eclipse", "version": null}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60009/", "cvss_score": 8.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-60009.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.24854, "epss_score": 0.00323, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may be able to run code or commands on affected systems.", "human_impact_label": "code execution review", "human_risk_summary": "CVE-2026-60009 for eclipse / theia: An attacker may be able to run code or commands on affected systems.", "id": "CVE-2026-60009", "impact_tags": ["code execution review"], "kev": false, "kev_date_added": null, "observed_at": "2026-08-12T10:29:37.194110+00:00", "product": "theia", "public_human_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.", "public_human_summary": "NVD: In Eclipse Theia versions up to and including 1.73.1, the @theia/filesystem backend binds POST /file-upload in every filesystem-enabled deployment. NVD: The handler takes an attacker-supplied absolute path from the multipart uri field and calls fs.move(tmp, target, { overwrite: true }) with no workspace confinement and no authentication. NVD: In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in @theia/core re-issues the cookie and calls next() without rejecting tokenless HTTP requests.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.; CVSS 8.8 (HIGH); EPSS percentile 25; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV, Vendor Advisory.", "public_safe_summary": "NVD: In Eclipse Theia versions up to and including 1.73.1, the @theia/filesystem backend binds POST /file-upload in every filesystem-enabled deployment. NVD: The handler takes an attacker-supplied absolute path from the multipart uri field and calls fs.move(tmp, target, { overwrite: true }) with no workspace confinement and no authentication. NVD: In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in @theia/core re-issues the cookie and calls next() without rejecting tokenless HTTP requests.", "public_status": "public_safe", "published_at": "2026-08-05T11:16:25.363", "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-60009-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-60009.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-60009.md", "scan_allowed": false}, "remediation_urls": ["https://github.com/eclipse-theia/theia/security/advisories/GHSA-62f6-wcvg-54h3", "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/177", "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/595", "https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/595"], "sort_priority": 88.24854, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "vendor/product: eclipse / theia", "source_published_description": "NVD: In Eclipse Theia versions up to and including 1.73.1, the @theia/filesystem backend binds POST /file-upload in every filesystem-enabled deployment. NVD: The handler takes an attacker-supplied absolute path from the multipart uri field and calls fs.move(tmp, target, { overwrite: true }) with no workspace confinement and no authentication. NVD: In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in @theia/core re-issues the cookie and calls next() without rejecting tokenless HTTP requests.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/eclipse-theia/theia/security/advisories/GHSA-62f6-wcvg-54h3"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/177"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/595"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/595"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-60009"}, {"source": "Official Reference", "type": "reference", "url": "https://osv.dev/vulnerability/CVE-2026-60009"}], "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: In Eclipse Theia versions up to and including 1.73.1, the @theia/filesystem backend binds POST /file-upload in every filesystem-enabled deployment. NVD: The handler takes an attacker-supplied absolute path from the multipart uri field and calls fs.move(tmp, target, { overwrite: true }) with no workspace confinement and no authentication. NVD: In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in @theia/core re-issues the cookie and calls next() without rejecting tokenless HTTP requests.", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2026-60009 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.8. EPSS score is 0.0032 with percentile 0.2485. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2026-60009 defensive priority signal", "title_ja": null, "translation": null, "treemap": {"cvss_score": 8.8, "disclosure_freshness": 0.9613, "epss_percentile": 0.24854, "epss_score": 0.00323, "evidence_confidence": 1.0, "fallbacks": [], "group_key": "canonical_vendor:eclipse", "group_label": "eclipse", "id": "cve:CVE-2026-60009", "kev": false, "kev_date_added": null, "last_modified": "2026-08-07T15:54:02.380000Z", "observation_freshness": 1.0, "observed_at": "2026-08-12T10:29:37.194110Z", "pressure_area": 24.854, "priority_area": 88.2485, "published_at": "2026-08-05T11:16:25.363000Z", "remediation_reference_count": 4, "schema_version": "vuln-treemap-node-v1", "severity": "high", "source_count": 6}, "updated_at": "2026-08-07T15:54:02.380", "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "eclipse", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to run code or commands on affected systems; CVSS 8.8 (HIGH); EPSS percentile 25; affected product context: eclipse / theia; sources: NVD, OSV, Vendor Advisory."}], "vendorDistribution": {"Unspecified vendor": 16, "eclipse": 4}}, "wellKnown": {"archive_index_url": "https://vuln.signal-radar.com/data/vuln/archive/index.json", "archive_latest_url": "https://vuln.signal-radar.com/data/vuln/archive/latest.json", "auto_remediation_allowed": false, "data_index_url": "https://vuln.signal-radar.com/data/vuln/index.json", "external_execution_allowed": false, "generated_at": "2026-08-12T10:39:32.977657+00:00", "github_issue_creation_allowed": false, "indexing_allowed": true, "machine_readable_surface": {"knowledge_graph_jsonld": {"content_type": "application/ld+json", "description": "JSON-LD graph of radar signals, source links, affected products, and trust metadata for agent-side provenance checks.", "enabled": true, "expected_shape": "@context plus @graph containing radar-specific vulnerability signal nodes", "primary_endpoint": "https://vuln.signal-radar.com/data/v1/graph/latest.jsonld", "well_known_endpoint": "https://vuln.signal-radar.com/.well-known/signal-graph.jsonld"}, "local_first_personal_data_vault": {"capabilities": ["import", "export", "clear", "shape validation"], "contains_public_signal_source_data": false, "description": "Browser-local vault for personal review context such as vendors, products, packages, CPE prefixes, saved signals, muted signals, and preferences.", "enabled": true, "network_behavior": "no fetch, XMLHttpRequest, sendBeacon, WebSocket, or EventSource", "server_sync": false, "storage": "localStorage"}, "purpose": "Expose public-safe vulnerability signals in formats that humans can inspect and AI agents can consume without mutation or external execution.", "rirastafab_trust_layer": {"attestation_ledger": "https://vuln.signal-radar.com/data/v1/attestations/vuln-signal-ledger.json", "canonical_envelope_index": "https://vuln.signal-radar.com/data/v1/proof/canonical-envelope-index.json", "description": "Read-only proof surface with hash-only integrity metadata, canonical envelopes, signed-JSON readiness, EAS preflight metadata, and attestation ledger endpoints.", "enabled": true, "external_submission_performed": false, "proof_latest": "https://vuln.signal-radar.com/data/v1/proof/latest.json", "proof_level": "hash-only", "trust_manifest": "https://vuln.signal-radar.com/.well-known/rirastafab-trust.json"}, "safety_boundary": {"auto_remediation_allowed": false, "external_execution_allowed": false, "github_issue_creation_allowed": false, "patch_allowed": false, "read_only": true, "runtime_server_endpoints": [], "scan_allowed": false}}, "mcp_http_endpoint": null, "pages_functions_enabled": false, "public_launch_allowed": true, "radar": "vuln", "read_only_static_data": true, "remediation_handoff": {"base_path": "/data/v1/remediation-handoff", "index_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/index.json", "item_count": 20, "packs": [{"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71237-codex-prompt.md", "cve_id": "CVE-2026-71237", "epss_percentile": 0.34766, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71237.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71237.md", "product": null, "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "CRITICAL", "vendor": null}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71231-codex-prompt.md", "cve_id": "CVE-2026-71231", "epss_percentile": 0.28595, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71231.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71231.md", "product": null, "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "CRITICAL", "vendor": null}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-66747-codex-prompt.md", "cve_id": "CVE-2026-66747", "epss_percentile": 0.44552, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-66747.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-66747.md", "product": null, "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "CRITICAL", "vendor": null}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71238-codex-prompt.md", "cve_id": "CVE-2026-71238", "epss_percentile": 0.23765, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71238.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71238.md", "product": null, "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "CRITICAL", "vendor": null}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-60009-codex-prompt.md", "cve_id": "CVE-2026-60009", "epss_percentile": 0.24854, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-60009.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-60009.md", "product": "theia", "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "HIGH", "vendor": "eclipse"}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71235-codex-prompt.md", "cve_id": "CVE-2026-71235", "epss_percentile": 0.21126, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71235.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71235.md", "product": null, "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "HIGH", "vendor": null}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71243-codex-prompt.md", "cve_id": "CVE-2026-71243", "epss_percentile": 0.21081, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71243.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71243.md", "product": null, "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "HIGH", "vendor": null}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71233-codex-prompt.md", "cve_id": "CVE-2026-71233", "epss_percentile": 0.0994, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71233.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71233.md", "product": null, "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "HIGH", "vendor": null}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71236-codex-prompt.md", "cve_id": "CVE-2026-71236", "epss_percentile": 0.0994, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71236.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71236.md", "product": null, "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "HIGH", "vendor": null}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71242-codex-prompt.md", "cve_id": "CVE-2026-71242", "epss_percentile": 0.12013, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71242.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71242.md", "product": null, "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "HIGH", "vendor": null}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71239-codex-prompt.md", "cve_id": "CVE-2026-71239", "epss_percentile": 0.13231, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71239.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71239.md", "product": null, "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "HIGH", "vendor": null}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-12609-codex-prompt.md", "cve_id": "CVE-2026-12609", "epss_percentile": 0.3374, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-12609.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-12609.md", "product": "theia", "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "HIGH", "vendor": "eclipse"}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71241-codex-prompt.md", "cve_id": "CVE-2026-71241", "epss_percentile": 0.20477, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71241.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71241.md", "product": null, "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "HIGH", "vendor": null}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71234-codex-prompt.md", "cve_id": "CVE-2026-71234", "epss_percentile": 0.15873, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71234.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71234.md", "product": null, "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "HIGH", "vendor": null}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71232-codex-prompt.md", "cve_id": "CVE-2026-71232", "epss_percentile": 0.22368, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71232.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71232.md", "product": null, "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "HIGH", "vendor": null}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71244-codex-prompt.md", "cve_id": "CVE-2026-71244", "epss_percentile": 0.10156, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71244.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71244.md", "product": null, "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "MEDIUM", "vendor": null}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14574-codex-prompt.md", "cve_id": "CVE-2026-14574", "epss_percentile": 0.20449, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14574.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14574.md", "product": "theia", "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "MEDIUM", "vendor": "eclipse"}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14304-codex-prompt.md", "cve_id": "CVE-2026-14304", "epss_percentile": 0.06863, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14304.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14304.md", "product": "accessibility_tools_framework", "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "MEDIUM", "vendor": "eclipse"}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71240-codex-prompt.md", "cve_id": "CVE-2026-71240", "epss_percentile": 0.08769, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71240.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71240.md", "product": null, "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "MEDIUM", "vendor": null}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-17578-codex-prompt.md", "cve_id": "CVE-2026-17578", "epss_percentile": 0.04712, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-17578.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-17578.md", "product": null, "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "LOW", "vendor": null}], "runtime_endpoint": false}, "runtime_endpoints": [], "schema_url": "https://vuln.signal-radar.com/data/vuln/schema.json", "schema_version": "v0.1", "search_console_registered": true, "signal_radar_integration_allowed": false, "source_health": {"deploy_mode": "fresh_fetch", "errors": [], "generated_at": "2026-08-12T10:29:37.203277+00:00", "normalized_count": 20, "note": "Latest public surface was generated from a successful safety-gated source fetch.", "public_safe_count": 20, "source_counts": {"epss": 20, "nvd": 20, "osv": 7}, "source_error_count": 0, "status": "healthy", "summary_available": true}, "trust_layer": {"attestation_ledger_envelope_url": "https://vuln.signal-radar.com/data/v1/proof/envelopes/attestation-ledger.json", "attestation_ledger_url": "https://vuln.signal-radar.com/data/v1/attestations/vuln-signal-ledger.json", "canonical_envelope_index_url": "https://vuln.signal-radar.com/data/v1/proof/canonical-envelope-index.json", "canonical_envelope_url": "https://vuln.signal-radar.com/data/v1/proof/canonical-envelope.json", "canonical_policy_url": "https://vuln.signal-radar.com/data/v1/proof/canonical-policy.json", "canonicalization_profile": "json-sort-keys-no-whitespace-v0", "eas_candidate_url": "https://vuln.signal-radar.com/data/v1/proof/eas-candidate.json", "eas_dry_run_status": "local_only", "eas_encoder_dry_run_url": "https://vuln.signal-radar.com/data/v1/proof/eas-encoder-dry-run.json", "eas_encoder_mode": "local_shape_check", "eas_mode": "reserved_offchain", "eas_preflight_url": "https://vuln.signal-radar.com/data/v1/proof/eas-preflight.json", "eas_rc_status": "frozen", "eas_rc_status_url": "https://vuln.signal-radar.com/data/v1/proof/eas-rc-status.json", "eas_schema_mapping_url": "https://vuln.signal-radar.com/data/v1/proof/eas-schema-mapping.json", "eas_schema_registration_status": "not_registered", "eas_sdk_adapter_contract_url": "https://vuln.signal-radar.com/data/v1/proof/eas-sdk-adapter-contract.json", "eas_sdk_encode_dry_run_url": "https://vuln.signal-radar.com/data/v1/proof/eas-sdk-encode-dry-run.json", "eas_sdk_execution_status": "not_available", "eas_status": "not_enabled", "eas_submission_status": "not_submitted", "eas_typed_payload_url": "https://vuln.signal-radar.com/data/v1/proof/eas-typed-payload.json", "external_call_performed": false, "manifest_url": "https://vuln.signal-radar.com/.well-known/rirastafab-trust.json", "proof_archive_index_url": "https://vuln.signal-radar.com/data/v1/proof/archive-index.json", "proof_latest_envelope_url": "https://vuln.signal-radar.com/data/v1/proof/envelopes/proof-latest.json", "proof_latest_url": "https://vuln.signal-radar.com/data/v1/proof/latest.json", "proof_level": "hash-only", "public_key_status": "not_available_until_signature_enabled", "public_key_url": "https://vuln.signal-radar.com/data/v1/proof/public-key.json", "remediation_proof_status": "not_enabled", "signal_graph_url": "https://vuln.signal-radar.com/data/v1/graph/latest.jsonld", "signature_algorithm": "Ed25519", "signature_status": "not_enabled", "signature_target_url": "https://vuln.signal-radar.com/data/v1/proof/canonical-envelope-index.json", "signed_json_ready": true, "signed_json_status_url": "https://vuln.signal-radar.com/data/v1/proof/signed-json-status.json", "signing_target_status": "preflight_frozen", "source_health_url": "https://vuln.signal-radar.com/data/v1/source-health.json", "status": "public_indexable", "trust_layer_eas_version": "0.3-rc", "trust_layer_version": "0.1", "trust_manifest_envelope_url": "https://vuln.signal-radar.com/data/v1/proof/envelopes/trust-manifest.json", "well_known_signal_graph_url": "https://vuln.signal-radar.com/.well-known/signal-graph.jsonld"}, "webmcp_runtime": {"annotations": {"readOnlyHint": true, "untrustedContentHint": true}, "api": "document.modelContext", "auto_remediation_allowed": false, "cross_origin_exposure_allowed": false, "deploy_allowed": false, "enabled": true, "endpoint": null, "exposed_to": [], "external_execution_allowed": false, "fallback_api": "navigator.modelContext", "fetch_allowed": false, "github_issue_creation_allowed": false, "mode": "browser_imperative_progressive_enhancement", "mutation_allowed": false, "planned": false, "scan_allowed": false, "tool_output_max_items": 10, "tool_output_target_max_chars": 1500, "tools": ["vuln_signal_search", "vuln_signal_get_item", "vuln_signal_list_priority"]}, "worker_enabled": false}}</template>
<script src="/assets/vuln/gsap.min.js?v=20260718-vuln-treemap-1" defer></script><script src="/assets/vuln/d3-hierarchy.min.js?v=20260718-vuln-treemap-1" defer></script><script src="/assets/vuln/vuln-treemap.js?v=20260718-vuln-treemap-1" defer></script><script src="/assets/vuln/dashboard.js?v=20260718-vuln-treemap-1" defer></script><script src="/assets/vuln/ScrambleTextPlugin.min.js?v=20260718-vuln-treemap-1" defer></script><script src="/assets/vuln/motion-links.js?v=20260718-vuln-treemap-1" defer></script>
</body></html>