VulnWatch VulnWatch
← Back to dashboard
#

Auth Bypass

91 entries

Every Auth Bypass entry VulnWatch has indexed, sorted by publication date.

Subscribe to this tag's RSS feed

High github

@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument

## Summary A command injection vulnerability exists in `@cyclonedx/cyclonedx-npm` when the CLI is invoked with the `--workspace ` option while the environment variable `npm_execpath` is unset or empty...

0.0
CVSS
23 hours ago
High github

AgenticMail: Cross-agent task authorization bypass in AgenticMail API

## Summary A low-privileged authenticated AgenticMail agent can enumerate another agent's pending/claimed tasks by supplying the target agent name to `GET /api/agenticmail/tasks/pending?assignee=`. T...

0.0
CVSS
2 days ago
Critical github

PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation

## Summary The `multiedit` tool in `src/praisonai/praisonai/tools/multiedit.py` allows LLM-controlled arbitrary file read and write without any path validation, workspace boundary check, or protected...

9.1
CVSS
2 days ago
High github

npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation

## Summary The published npm package `praisonai` exports an `MCPSecurity` helper described in source as: ```text MCP Security - Authentication, authorization, and rate limiting Provides security pol...

8.2
CVSS
2 days ago
Critical github

PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai

# Unauthenticated PraisonAI UI MCP connect endpoint executes attacker-chosen local commands ## Summary PraisonAI v4.6.48 exposes the PraisonAIUI MCP client management API through the default UI host...

9.8
CVSS
2 days ago
Critical github

PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints

# PraisonAI `AgentTeam.launch()` exposes unauthenticated remote agent invocation endpoints ## Summary PraisonAI's documented Python `AgentTeam.launch()` / `Agents.launch()` HTTP server starts extern...

9.8
CVSS
2 days ago
High github

Docker MCP Gateway: Argument injection via OCI image label YAML

## Summary A maliciously crafted OCI image label can inject arbitrary arguments into the `docker run` command line constructed by the MCP Gateway. An attacker who controls an image that the victim re...

0.0
CVSS
2 days ago
Medium github

Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter

## Summary Several direct, index-addressed Ollama proxy routes accept a caller-supplied `url_idx` path parameter and use it as a raw index into the admin-configured `OLLAMA_BASE_URLS` list. Access co...

6.3
CVSS
3 days ago
Medium github

Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration

## Summary Open WebUI has a Broken Object Level Authorization (BOLA) vulnerability in the builtin `search_knowledge_files` tool. When native function calling is enabled and the selected model has no...

Auth Bypass function calling gpt-4
4.3
CVSS
3 days ago
Medium osv

LiteLLM: Authentication Bypass via Host Header Injection

### Impact A Host-header parsing flaw in the LiteLLM proxy could, under specific conditions, allow unauthenticated access to protected management routes. The auth layer derived the effective route f...

4.0
CVSS
3 days ago
High github

Caddy: Windows `file_server` path authorization bypass via encoded backslash

### Summary On Windows, Caddy `path` matchers treat `/private\secret.txt` as outside `/private/*`, but `file_server` later resolves the same request path as `private\secret.txt` on disk. An unauthen...

7.5
CVSS
3 days ago
High github

Crawl4AI: LLM credential exfiltration in Docker server via request base_url and env: token resolution

### Summary The Docker API server let a request control where LLM calls were sent and which environment variable an LLM token resolved from. Both could be abused to exfiltrate server-held secrets. Th...

Auth Bypass openai llm
8.2
CVSS
3 days ago
Critical github

Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution

### Summary Multiple security vulnerabilities in the Crawl4AI Docker API server affecting endpoints for crawling, markdown/LLM extraction, screenshots, PDFs, webhooks, monitoring, JavaScript executio...

9.8
CVSS
3 days ago
Low osv

vLLM: OpenAI auth bypass

### Summary A vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API `AuthenticationMiddleware`, which was discovered during @...

3.1
CVSS
4 days ago
Low osv

vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution

### Summary An `assert`-based security check in vLLM's activation function loading allows any unauthenticated attacker to achieve arbitrary code execution on the server by publishing a malicious Hugg...

3.1
CVSS
4 days ago
Critical nvd

CVE-2026-11624: The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming conne

The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNS rebinding attacks. Prior to the v0.25.0 release, users had...

Auth Bypass Agentic / MCP model context protocol
9.4
CVSS
1 week ago
High nvd

CVE-2026-47138: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.77 and 9.9.1-alpha.1, an unauthenticated attacker who knows a publicly-kno...

Auth Bypass adversarial
8.7
CVSS
1 week ago
Medium nvd

CVE-2026-47250: mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.7.0, the

mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.7.0, the kubectl_generic tool in mcp-server-kubernetes passes user-supplied flags directl...

Auth Bypass Agentic / MCP model context protocol mcp server ai agent
6.1
CVSS
1 week ago
High nvd

CVE-2026-46519: mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-

mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-server-kubernetes exposes three environment variables (ALLOW_ONLY_READONLY_TOOLS...

Auth Bypass Agentic / MCP model context protocol
8.8
CVSS
1 week ago
Medium nvd

CVE-2025-54509: Improper access control for register interface in the input-output memory management unit (IOMMU) could allow a privileg

Improper access control for register interface in the input-output memory management unit (IOMMU) could allow a privileged attacker to cause non-coherent accesses by the AMD secure processor (ASP) pot...

4.0
CVSS
1 week ago
Low nvd

CVE-2026-11500: A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the f

A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the file usecases/auth/authentication/apikey/client.go of the component Static API Ke...

Auth Bypass weaviate
1.3
CVSS
1 week ago
Medium github

MCP Server Kubernetes: kubectl-generic flag injection enables Kubernetes bearer token exfiltration

### Summary The `kubectl_generic` tool in `mcp-server-kubernetes` passes user-supplied flags directly to kubectl without any allowlist, enabling a **privilege escalation attack** within Kubernetes env...

Prompt Injection Auth Bypass Agentic / MCP prompt injection indirect prompt mcp server anthropic ai agent claude
6.1
CVSS
2 weeks ago
Medium github

praisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id}

## Summary **Type:** Authorization bypass enabling workspace metadata + settings tampering. The `PATCH /workspaces/{workspace_id}` endpoint is gated only by `require_workspace_member(workspace_id)` (...

6.5
CVSS
2 weeks ago
High github

@agenticmail/mcp Missing Authentication for Critical Function

# AgenticMail MCP HTTP authorization bypass ## Summary `@agenticmail/mcp` exposes a Streamable HTTP transport when started with `--http` or `MCP_HTTP=1`. In that mode, the `/mcp` endpoint accepts re...

0.0
CVSS
2 weeks ago
Medium github

nono: Sandbox escape on Linux via D-Bus: `systemd-run --user`

### Summary The nono Landlock/seccomp policies allow access to local Unix domain sockets (concrete and abstract). This allows an easy sandbox escape by talking to the per-user systemd dbus socket. T...

Auth Bypass Agentic / MCP claude code ai agent claude aider
6.1
CVSS
3 weeks ago