{
  "append_only": true,
  "archive_index_url": "https://vuln.signal-radar.com/data/vuln/archive/index.json",
  "archive_version": "v0.1",
  "generated_at": "2026-08-12T10:39:32.977657+00:00",
  "immutable_run": true,
  "item_count": 20,
  "items": [
    {
      "affected_label": "eclipse / theia",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12609/",
      "current_public_safe_latest": true,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.3374,
      "epss_score": 0.00409,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-12609",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-12609.json",
      "product": "theia",
      "public_safe_summary": "NVD: In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the @theia/plugin-ext backend exposes the /hostedPlugin/:pluginId/:path(*) HTTP endpoint, which resolves the requested file path with path.resolve(localPath, filePath) without verifying that the... NVD: An unauthenticated network attacker can send percent-encoded ../ sequences (%2e%2e%2f) that decode into the path parameter and escape the plugin directory, allowing arbitrary files readable by the Theia backend process to be retrieved. NVD: Plugin IDs are derived deterministically from a plugin's publisher and name, so built-in plugins serve as reliable anchors that require no prior knowledge of the target system.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-12609.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: eclipse / theia",
      "source_published_impact": "Source describes remote exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the @theia/plugin-ext backend exposes the /hostedPlugin/:pluginId/:path(*) HTTP endpoint, which resolves the requested file path with path.resolve(localPath, filePath) without verifying that the... NVD: An unauthenticated network attacker can send percent-encoded ../ sequences (%2e%2e%2f) that decode into the path parameter and escape the plugin directory, allowing arbitrary files readable by the Theia backend process to be retrieved. NVD: Plugin IDs are derived deterministically from a plugin's publisher and name, so built-in plugins serve as reliable anchors that require no prior knowledge of the target system.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12609/timeline.json",
      "vendor": "eclipse"
    },
    {
      "affected_label": "eclipse / accessibility_tools_framework",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14304/",
      "current_public_safe_latest": true,
      "cvss_score": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06863,
      "epss_score": 0.00172,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-14304",
      "impact_tags": [
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-14304.json",
      "product": "accessibility_tools_framework",
      "public_safe_summary": "NVD: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. NVD: If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker. OSV: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-14304.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: eclipse / accessibility_tools_framework",
      "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. NVD: If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker. OSV: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14304/timeline.json",
      "vendor": "eclipse"
    },
    {
      "affected_label": "eclipse / theia",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14574/",
      "current_public_safe_latest": true,
      "cvss_score": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.20449,
      "epss_score": 0.00282,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-14574",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-14574.json",
      "product": "theia",
      "public_safe_summary": "NVD: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype). NVD: Because this function is invoked by PreferenceServiceImpl.doResolve for every preference resolution across scopes (default, user, workspace, folder), a crafted preference value in a workspace settings file (.theia/settings.json or .vscode/settings.json) can... OSV: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype).",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-14574.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: eclipse / theia",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype). NVD: Because this function is invoked by PreferenceServiceImpl.doResolve for every preference resolution across scopes (default, user, workspace, folder), a crafted preference value in a workspace settings file (.theia/settings.json or .vscode/settings.json) can... OSV: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype).",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14574/timeline.json",
      "vendor": "eclipse"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17578/",
      "current_public_safe_latest": true,
      "cvss_score": 2.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.04712,
      "epss_score": 0.0015,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-17578",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-17578.json",
      "product": null,
      "public_safe_summary": "NVD: Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled. NVD: If a producer sends messages at a sustained high rate without key rotation, which only occurs on reboot of the Kong Event Gateway instance, the probability of a nonce collision becomes non-negligible. NVD: An authorized consumer who detects a nonce collision can recover parts of plaintext from the affected messages.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-17578.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled. NVD: If a producer sends messages at a sustained high rate without key rotation, which only occurs on reboot of the Kong Event Gateway instance, the probability of a nonce collision becomes non-negligible. NVD: An authorized consumer who detects a nonce collision can recover parts of plaintext from the affected messages.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17578/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "eclipse / theia",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60009/",
      "current_public_safe_latest": true,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.24854,
      "epss_score": 0.00323,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-60009",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-60009.json",
      "product": "theia",
      "public_safe_summary": "NVD: In Eclipse Theia versions up to and including 1.73.1, the @theia/filesystem backend binds POST /file-upload in every filesystem-enabled deployment. NVD: The handler takes an attacker-supplied absolute path from the multipart uri field and calls fs.move(tmp, target, { overwrite: true }) with no workspace confinement and no authentication. NVD: In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in @theia/core re-issues the cookie and calls next() without rejecting tokenless HTTP requests.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-60009.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: eclipse / theia",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Eclipse Theia versions up to and including 1.73.1, the @theia/filesystem backend binds POST /file-upload in every filesystem-enabled deployment. NVD: The handler takes an attacker-supplied absolute path from the multipart uri field and calls fs.move(tmp, target, { overwrite: true }) with no workspace confinement and no authentication. NVD: In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in @theia/core re-issues the cookie and calls next() without rejecting tokenless HTTP requests.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-60009/timeline.json",
      "vendor": "eclipse"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66747/",
      "current_public_safe_latest": true,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.44552,
      "epss_score": 0.00579,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-66747",
      "impact_tags": [
        "code execution review",
        "admin privilege risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-66747.json",
      "product": null,
      "public_safe_summary": "NVD: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. NVD: It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. NVD: It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-66747.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · admin privilege risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. NVD: It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. NVD: It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66747/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71231/",
      "current_public_safe_latest": true,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.28595,
      "epss_score": 0.00358,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71231",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71231.json",
      "product": null,
      "public_safe_summary": "NVD: IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71231.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71231/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71232/",
      "current_public_safe_latest": true,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22368,
      "epss_score": 0.003,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71232",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71232.json",
      "product": null,
      "public_safe_summary": "NVD: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function... OSV: MacCMS10 - Incomplete Function Blacklist in Template Editor Enables Authenticated RCE OSV: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71232.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function... OSV: MacCMS10 - Incomplete Function Blacklist in Template Editor Enables Authenticated RCE OSV: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71232/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71233/",
      "current_public_safe_latest": true,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.0994,
      "epss_score": 0.00199,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71233",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71233.json",
      "product": null,
      "public_safe_summary": "NVD: InvoiceNinja v5-stable renders an invoice or quote's \"terms\" field in the client portal using Laravel Blade's raw output directive {!! NVD: ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71233.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: InvoiceNinja v5-stable renders an invoice or quote's \"terms\" field in the client portal using Laravel Blade's raw output directive {!! NVD: ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71233/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71234/",
      "current_public_safe_latest": true,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.15873,
      "epss_score": 0.00245,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71234",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71234.json",
      "product": null,
      "public_safe_summary": "NVD: Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a query parameter and grants access whenever the parameter is simply non-empty (len(secureToken) > 0)...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71234.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a query parameter and grants access whenever the parameter is simply non-empty (len(secureToken) > 0)...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71234/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71235/",
      "current_public_safe_latest": true,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21126,
      "epss_score": 0.00288,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71235",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71235.json",
      "product": null,
      "public_safe_summary": "NVD: Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. NVD: The Lua script engine (re/lua.go) performs no input validation at all and preloads dangerous libraries: db (arbitrary database access), ioutil (file I/O), an HTTP client (SSRF), and filepath (traversal).",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71235.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. NVD: The Lua script engine (re/lua.go) performs no input validation at all and preloads dangerous libraries: db (arbitrary database access), ioutil (file I/O), an HTTP client (SSRF), and filepath (traversal).",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71235/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71236/",
      "current_public_safe_latest": true,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.0994,
      "epss_score": 0.00199,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71236",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71236.json",
      "product": null,
      "public_safe_summary": "NVD: Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HTML-entity encoding of the resulting output by replacing &amp;lt;, &amp;gt;, and...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71236.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HTML-entity encoding of the resulting output by replacing &amp;lt;, &amp;gt;, and...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71236/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71237/",
      "current_public_safe_latest": true,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.34766,
      "epss_score": 0.0042,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71237",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71237.json",
      "product": null,
      "public_safe_summary": "NVD: Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query(\"select * from userlists where username='' and password='' limit 1\").",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71237.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query(\"select * from userlists where username='' and password='' limit 1\").",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71237/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71238/",
      "current_public_safe_latest": true,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.23765,
      "epss_score": 0.00313,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71238",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71238.json",
      "product": null,
      "public_safe_summary": "NVD: DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. NVD: Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71238.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. NVD: Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71238/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71239/",
      "current_public_safe_latest": true,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.13231,
      "epss_score": 0.00225,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71239",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71239.json",
      "product": null,
      "public_safe_summary": "NVD: DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no sanitization, in at least three locations: message_previews.py builds an f-string embedding message.subject/message.content...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71239.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no sanitization, in at least three locations: message_previews.py builds an f-string embedding message.subject/message.content...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71239/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71240/",
      "current_public_safe_latest": true,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08769,
      "epss_score": 0.00189,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71240",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71240.json",
      "product": null,
      "public_safe_summary": "NVD: DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or staff_member_required, and it redirects to a caller-supplied next_url GET parameter after only checking secure_url(next_url), which merely...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71240.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or staff_member_required, and it redirects to a caller-supplied next_url GET parameter after only checking secure_url(next_url), which merely...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71240/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71241/",
      "current_public_safe_latest": true,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20477,
      "epss_score": 0.00282,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71241",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71241.json",
      "product": null,
      "public_safe_summary": "NVD: Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. NVD: Because card_id values are sequential integers, the entire student database can be enumerated without authentication.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71241.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. NVD: Because card_id values are sequential integers, the entire student database can be enumerated without authentication.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71241/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71242/",
      "current_public_safe_latest": true,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.12013,
      "epss_score": 0.00215,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71242",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71242.json",
      "product": null,
      "public_safe_summary": "NVD: Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify ->hasCompany(->company_id). NVD: Any authenticated user of one company can read, edit, or delete another company's notes by ID. OSV: Crater - Cross-Company IDOR on Notes via Missing Company-Ownership Check in NotePolicy",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71242.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify ->hasCompany(->company_id). NVD: Any authenticated user of one company can read, edit, or delete another company's notes by ID. OSV: Crater - Cross-Company IDOR on Notes via Missing Company-Ownership Check in NotePolicy",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71242/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71243/",
      "current_public_safe_latest": true,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21081,
      "epss_score": 0.00288,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71243",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71243.json",
      "product": null,
      "public_safe_summary": "NVD: The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. NVD: cmd = \"mkdir -p \" + path.join(info.destination, info.name) + \"; \" - and executes the resulting string through a shell via ssh2-exec (locally via child_process, or remotely via SSH when an ssh handle is supplied), rather than using execFile/spawn with an... OSV: backmeup (npm) - OS Command Injection via Backup Option Values",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71243.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. NVD: cmd = \"mkdir -p \" + path.join(info.destination, info.name) + \"; \" - and executes the resulting string through a shell via ssh2-exec (locally via child_process, or remotely via SSH when an ssh handle is supplied), rather than using execFile/spawn with an... OSV: backmeup (npm) - OS Command Injection via Backup Option Values",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71243/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71244/",
      "current_public_safe_latest": true,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10156,
      "epss_score": 0.00201,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71244",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71244.json",
      "product": null,
      "public_safe_summary": "NVD: Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71244.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71244/timeline.json",
      "vendor": null
    }
  ],
  "public_safe_only": true,
  "radar": "vuln",
  "run_id": "20260812T103932Z",
  "run_index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/index.json",
  "safety": {
    "auto_remediation_allowed": false,
    "exploit_detail_allowed": false,
    "external_execution_allowed": false,
    "github_issue_creation_allowed": false,
    "indexing_allowed": true,
    "noindex_removal_allowed": true,
    "noindex_required": false,
    "patch_allowed": false,
    "public_launch_allowed": true,
    "public_safe_only": true,
    "raw_source_included": false,
    "read_only": true,
    "scan_allowed": false,
    "search_console_registered": true,
    "signal_radar_integration_allowed": false
  },
  "schema_version": "v0.1"
}