These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,201 reserved CVEs with public mentions, ranked by all-time mention count.
Page 23 of 49
CVE-2026-57148 is an improper authentication vulnerability in praisonai-platform caused by use of a hardcoded default JWT signing secret together with a production configuration that remains permissive by default. In affected default deployments, if the platform secret is unset or left at the known default value, an attacker can generate forged JWTs that are accepted as valid by the application. Because the forged tokens can encode arbitrary user identity and authorization context, the flaw enables authentication bypass and impersonation of legitimate users, including high-privilege workspace owners. The issue stems from insecure default credential material and insufficient fail-closed validation around JWT secret configuration in production deployments.
CVE-2026-57148First seen Jul 21, 2026
CVE-2026-57147 is an authentication bypass vulnerability in praisonai-platform caused by use of an insecure default JWT signing secret. When the platform is deployed with default or unset environment variables, it may use the hardcoded development secret for HS256 token signing. An attacker who knows this default secret can generate forged JWTs that the application will accept as valid, allowing impersonation of arbitrary identities without legitimate authentication.
CVE-2026-57147First seen Jul 21, 2026
CVE-2026-57131 is an improper authentication vulnerability in PraisonAI's Jobs API. Agent-execution and job-management endpoints are exposed without authentication, allowing unauthenticated access to functionality for submitting jobs, listing jobs, reading job details and results, canceling jobs, deleting jobs, and streaming job output. Because the API permits attacker-controlled job submission and execution in the operator's process context, the flaw can enable arbitrary agent-driven actions and expose sensitive execution data. The issue affects deployments where the Jobs API is reachable without access controls and was fixed in praisonai version 4.6.59 and later.
CVE-2026-57131First seen Jul 21, 2026
CVE-2026-57145 is an arbitrary file read and write vulnerability in PraisonAI's multiedit tool. The flaw is caused by insufficient path validation on the filepath parameter, including failure to block directory traversal sequences, failure to enforce workspace boundary restrictions on resolved paths, inadequate protection for sensitive paths, and failure to safely resolve symlinks before file operations. As a result, attacker-controlled path input can cause the tool to access files outside the intended workspace and perform unauthorized read or overwrite operations on files accessible to the running process.
CVE-2026-57145First seen Jul 21, 2026
CVE-2026-57124 is a vulnerability in PraisonAI UI affecting the MCP connect endpoint. The issue combines missing authentication on MCP management functionality with operating system command injection in the endpoint used to initiate MCP stdio connections. A remote attacker can send a crafted POST request to the MCP connect API and influence the command and arguments used to launch local processes, causing the application to start attacker-chosen processes on the host. The vulnerability results in arbitrary command execution in the security context of the PraisonAI UI service.
CVE-2026-57124First seen Jul 21, 2026
CVE-2026-57116 is an authentication flaw in PraisonAI AgentOS caused by an incomplete fix for a prior advisory. Exposed FastAPI routes handling agent discovery and chat invocation remain accessible without authentication, allowing remote unauthenticated clients to enumerate deployed agents and invoke them. The issue affects the security boundary around AgentOS and AgentApp by failing to consistently enforce bearer authentication on sensitive API endpoints. In reachable deployments, this permits unauthorized interaction with agent functionality and any downstream capabilities exposed through those agents.
CVE-2026-57116First seen Jul 21, 2026
CVE-2026-57127 is a fail-open authentication vulnerability in the PraisonAI `praisonai` package affecting recipe serve middleware. When authentication is configured to use API key or JWT, the middleware silently disables authentication if the corresponding secret is not configured. As a result, requests to recipe execution endpoints may be processed without any authentication despite the deployment being configured for protected access. The flaw is rooted in authentication initialization logic that does not fail closed when required secret material is absent, causing protected endpoints to become unintentionally unauthenticated.
CVE-2026-57127First seen Jul 21, 2026
CVE-2025-60034 is a vulnerability in the Bosch MAP 5000 family caused by the SSH service being configured to permit insecure cryptographic algorithms. The weakness allows use of deprecated or otherwise insufficiently strong cryptographic mechanisms during SSH sessions, reducing the security guarantees normally provided by the protocol. As a result, an attacker in a suitable network position may be able to attack SSH communications and undermine confidentiality or integrity protections, with potential downstream consequences including unauthorized access and exposure of sensitive data.
CVE-2025-60034First seen Jul 23, 2026
CVE-2025-4995 is a cryptographic weakness in the TLS server implementation of Bosch MAP 5000. The product uses outdated TLS cryptographic settings, specifically weak Diffie-Hellman key exchange parameters, during TLS session establishment. This weakness reduces the effective security of encrypted connections and can allow an attacker positioned on the network path to undermine the protection expected from TLS. The issue affects the confidentiality and integrity of communications by making it feasible to passively decrypt traffic or actively intercept and manipulate supposedly secured sessions.
CVE-2025-4995First seen Jul 23, 2026
First seen Jul 23, 2026
First seen Jul 22, 2026
First seen Jul 22, 2026
First seen Jul 22, 2026
First seen Jul 22, 2026
First seen Jul 22, 2026
First seen Jul 22, 2026
First seen Jul 22, 2026
First seen Jul 22, 2026
First seen Jul 22, 2026
First seen Jul 22, 2026
First seen Jul 22, 2026
First seen Jul 20, 2026
CVE-2026-46495 is a pre-authentication remote code execution vulnerability in OpenDJ Community Edition affecting the JMX RMI connector. The flaw is caused by unsafe Java deserialization of untrusted data received by the JMX RMI listener before authentication is completed. An unauthenticated attacker with network reachability to the exposed JMX service can supply a crafted serialized object stream and trigger deserialization in the target JVM. In environments where suitable gadget chains are present on the runtime classpath, successful exploitation can result in arbitrary code execution. Unauthenticated remote code execution was demonstrated against OpenDJ 4.4.15 running on JDK 11 with Jackson 2.12.6.1 present in the classpath.
CVE-2026-46495First seen Jun 23, 2026
First seen Jul 20, 2026
CVE-2026-54503 is a stored cross-site scripting vulnerability affecting plone.app.textfield and related Plone deployments using RichText rendering, including environments exposing the issue through plone.restapi. The flaw arises when attacker-controlled RichText content is stored with a spoofed MIME type such that the stored mimeType matches the outputMimeType. In that condition, expected safe_html sanitization is bypassed and unsanitized RichText content can be rendered directly. This allows malicious script content embedded in persisted RichText fields to be stored server-side and later executed in the browsers of users who view the affected content.
CVE-2026-54503First seen Jun 23, 2026