Labs
Short research notes on newly disclosed vulnerabilities: the problem, the payload, and the fix.
- highCVE-2026-61687
CVE-2026-61687: Hatchet OAuth State CSRF via Empty-State Collision
Hatchet clears the OAuth anti-CSRF state to an empty string instead of deleting it from the session, so any callback request carrying an empty state parameter bypasses the check and can hijack an…
- high
LMDeploy SSRF Bypass via urlparse and requests Parser Disagreement
A backslash in a crafted URL tricks LMDeploy's safety check into seeing a public IP while the actual HTTP request goes to an internal address, letting an attacker reach services inside the server's…
- criticalCVE-2026-59163
CVE-2026-59163: mnemosyne-memory JWT Signature Verification Bypass
The mnemosyne sync server accepted any well-formed JWT token without ever checking its signature, letting anyone impersonate any user and read or overwrite their synced memory data without knowing…
- highCVE-2026-85058
CVE-2026-85058: moquette-broker Will Message ACL Authorization Bypass
Moquette MQTT Broker skips write-permission checks when publishing Last Will and Testament messages, letting any anonymous client inject messages into ACL-protected topics by setting a restricted…
- high
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion
A chain of three flaws in Obot's MCP OAuth layer let an unauthenticated attacker register a malicious redirect URI, silently steal an authorization code when a logged-in user visits a crafted link…
- high
Obot: Server-Side Request Forgery via Remote MCP Server URL
Obot let privileged users register a remote MCP server pointing at any internal address, including the cloud metadata service, causing Obot to silently fetch it server-side and leak the response in…
- highCVE-2026-61672
CVE-2026-61672: Capsule Tenant Forbidden Metadata Enforcement Bypass
A sorting bug in Capsule's forbidden-metadata checker lets a tenant owner apply labels or annotations the cluster administrator explicitly blocked, silently breaking multi-tenant isolation on…
- highCVE-2026-61833
CVE-2026-61833: zot Bearer Token Scope Collapse Allows Unauthorized Manifest and Blob Deletion
A bearer token issued with only pull and push permissions can delete container images and blobs from a zot registry, because the registry never checks for a separate delete permission on HTTP DELETE…
- highCVE-2026-63458
CVE-2026-63458: Perses Project Query Parameter Authorization Bypass
Any authenticated Perses user can read dashboards, datasources, and variables from projects they have no access to, just by adding a ?project= query parameter to a standard API request.
- highCVE-2026-63199
CVE-2026-63199: Perses Datasource Proxy Cross-Scope Secret Disclosure
A user with only datasource-create permission can attach any named secret to a datasource or unsaved proxy request and receive that secret decrypted in plain text, bypassing Perses's role-based…
- criticalCVE-2026-61682
CVE-2026-61682: kcp Front-Proxy Identity Header Injection Authentication Bypass
Any authenticated kcp tenant can inject X-Remote-Group and related identity headers through the front-proxy to impersonate system:masters and gain full admin access over any workspace on the shard.
- highCVE-2026-58197
CVE-2026-58197: ToolHive Container Lateral Movement via host.docker.internal
Containerized MCP servers running in ToolHive could reach the host network via host.docker.internal and call unauthenticated ToolHive and MCP proxy endpoints, letting a malicious container pivot to…