Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Mil4N

#18640of 56,328
15.3Total CVSS
Vulnerabilities · 2
High
2
PT-2026-89000
8.2
2026-09-09
Chainlit · Chainlit · CVE-2026-86099
Chainlit through 2.12.0 fails to validate the client-supplied socket.io sessionId parameter, allowing unauthenticated attackers to traverse filesystem paths by injecting absolute or relative path sequences. Attackers can craft malicious sessionId values that escape the upload directory and recursively delete arbitrary directories accessible to the service process.
PT-2026-84299
7.1
2026-09-01
Unknown · Appium-Mcp-Server · CVE-2026-84201
**Name of the Vulnerable Software and Affected Versions** appium-mcp-server versions prior to 0.1.62 **Description** The software fails to validate or normalize file paths within the `write file` and `write files batch` tools. This allows attackers to use absolute paths or relative paths containing parent directory segments to write files outside the designated `PROJECT ROOT` directory. Consequently, arbitrary files, such as shell profiles and configuration files in the home directory, can be overwritten using the privileges of the server user. **Recommendations** Update appium-mcp-server to version 0.1.62 or later. As a temporary mitigation, restrict the use of the `write file` and `write files batch` tools.