Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Xiaobu

#21996of 56,330
12.3Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-76676
6.5
2026-08-17
Unknown · Fetcher-Mcp · CVE-2026-74858
**Name of the Vulnerable Software and Affected Versions** jae-jae fetcher-mcp versions prior to 0.4.0 **Description** An issue exists in the URL Validation component where the `fetch url()` and `fetch urls()` functions in the `/latest/meta-data/iam/security-credentials/` file are susceptible to manipulation. This allows a remote attacker to perform server-side request forgery (SSRF), a technique where the attacker induces the server to make requests to an unintended location. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict the use of the `fetch url()` and `fetch urls()` functions.
PT-2026-69327
5.8
2026-08-10
Saithink/Saigroup · Siadmin · CVE-2026-19383
**Name of the Vulnerable Software and Affected Versions** saithink/saigroup SaiAdmin versions prior to 5.0.2 **Description** A flaw in the Plugin Upload Endpoint allows for unrestricted file upload. This issue occurs within the `shell exec()` function located in the `/app/saipackage/install/upload` file, enabling remote exploitation. **Recommendations** Update to a version newer than 5.0.1. As a temporary mitigation, restrict access to the `/app/saipackage/install/upload` file to prevent unauthorized uploads.