🔓 CVEs & KEV
-
CVE-2026-77956 — CVSS 10.0 — EEx template evaluation of prompt content in AshAi enables remote code execut...
-
CVE-2026-75759 — CVSS 7.6 — Encrypted ID token or JARM response accepted without a nested signature in er...
-
CVE-2026-81315 — CVSS 7.4 — MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-...
-
CVE-2026-75760 — CVSS 7.1 — AshAi vectorize change leaks raw embedding-provider errors, including credent...
-
CVE-2026-82564 — CVSS 7.1 — Identity tool filter in AshAi accepts operator maps, allowing update or destr...
-
CVE-2026-82579 — CVSS 6.0 — AshAi tool loop never terminates when all tool calls are filtered out, enabli...
📋 ADVISORIES
- 📄 Source for Critical Buffer Overflow Hits D-Link DIR-825M Firmware 1.1.8 — github.com