À la une
Veille
Sécurité
DevOps
Cloud
IA
Self-hosted
Linux
Réseau
Rechercher
⌘K
EN
en direct
CVE-2025-15662 · CVSS 8.6
CVE-2025-50455 · CVSS 9.1
CVE-2025-59172 · CVSS 8.5
CVE-2025-68686 · Fortinet FortiOS
accueil
veille
Oraios-ai
éditeur
Oraios-ai
1
vulnérabilité suivie
7 juillet 2026
dernière publication
cve
Veille des vulnérabilités
identifiant
vulnérabilité
sévérité
publié
CVE-2026-49471
Serena is a powerful MCP toolkit for coding that provides semantic retrieval and editing capabilities. Prior to v1.5.2, Serena's built-in web dashboard exposes an unauthenticated Flask API on a fixed, predictable port, with no authentication, no CSRF protection, and no Host header validation. A DNS rebinding attack allows a malicious webpage to reach this API from any browser and write arbitrary content to the agent's persistent memory store, which the agent reads and acts on autonomously. Combined with execute_shell_command using shell=True, this creates a remote code execution chain requiring only that the victim visit a malicious webpage while Serena is running. This issue is fixed in version v1.5.2.
Oraios-ai Serena
Élevée
CVSS 8.3
07/07
← Retour à la veille
esc
Tapez au moins deux caractères.
↑
↓
naviguer
↵
ouvrir
esc
fermer