Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Sivaadityacoder

#17171de 56,328
16.7CVSS total
Vulnerabilidades · 2
Alta
2
PT-2026-71424
8.6
2026-08-13
Flowise · Flowise · CVE-2026-73484
**Nome do Software Vulnerável e Versões Afetadas** Flowise versões anteriores a 3.1.3 **Description** Existe uma fuga de sandbox em `pythonCodeValidator.ts` porque o componente falha ao bloquear métodos nativos do Pandas DataFrame, incluindo `to csv`, `to json`, `pipe` e `query`. Atacantes autenticados podem explorar isso para exfiltrar dados de CSV carregados ou gravar arquivos arbitrários no sistema de arquivos do servidor. **Recommendations** Atualize para a versão 3.1.3 ou posterior.
PT-2026-6101
8.1
2026-02-04
Significant Gravitas · Autogpt · CVE-2026-22038
**Name of the Vulnerable Software and Affected Versions** AutoGPT versions prior to 0.6.46 **Description** AutoGPT is a platform for creating and managing AI agents to automate workflows. The Stagehand integration improperly logs API keys and authentication secrets in plaintext using `logger.info()` statements. This occurs within the `StagehandObserveBlock`, `StagehandActBlock`, and `StagehandExtractBlock` implementations, where the code calls `api key.get secret value()` and logs the returned value. The vulnerable code exposes sensitive information through logging mechanisms. **Recommendations** Update to version 0.6.46 or later.