Tag
#Unauthenticated Attack
Critical Vulnerability in Clawvet Self-Hosted API Server: CVE-2026-62241
A critical vulnerability (CVE-2026-62241, CVSS 9.1) exists in the Clawvet self-hosted API server (apps/api) before version 0.7.5. The vulnerability allows a remote unauthenticated attacker to harvest user IDs, forge a valid session cookie, and obtain sensitive user information. The vulnerability has not been actively exploited but poses a significant risk due to its severity and the potential for exploitation. Immediate patching to version 0.7.5 or later is strongly recommended.
CVE-2026-61436: PraisonAI Webhook Signature Verification Bypass
A vulnerability in PraisonAI before version 4.6.78 allows unauthenticated attackers to forge message.received events by sending crafted JSON payloads to the webhook endpoint, potentially invoking configured agents with arbitrary sender addresses and message content. This vulnerability has a CVSS score of 8.6 and is classified as HIGH severity.
Critical Command Injection Vulnerability in Sustainable Irrigation Platform (SIP)
A critical command injection vulnerability (CVE-2026-58479) has been discovered in the Sustainable Irrigation Platform (SIP) through version 5.2.16. The vulnerability, located in the optional cli_control plugin, allows unauthenticated or cross-site request forgery attackers to execute arbitrary operating-system commands. This can be achieved by storing a malicious payload via the plugin's HTTP endpoint and triggering execution by activating the associated irrigation station, exploiting the absence of passphrase protection or the default passphrase 'opendoor'. The vulnerability has a CVSS score of 9.8 and is considered critical.