VulnWatch VulnWatch
← Back to dashboard
#

Remote Code Execution

654 entries

Every Remote Code Execution entry VulnWatch has indexed, sorted by publication date.

Subscribe to this tag's RSS feed

Low nvd

CVE-2026-10180: A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. Impacted is the function formSysCmd of the file /goform/f

A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. Impacted is the function formSysCmd of the file /goform/formSysCmd. Such manipulation of the argument sysCmd leads to command injection....

2.1
CVSS
3 months ago
Low github

Aider is vulnerable to Code Injection via editor_coder.run function

A security flaw has been discovered in Aider-AI Aider 0.86.3.dev. Affected by this vulnerability is the function editor_coder.run of the file auth.py of the component Architect Mode. Performing a mani...

6.3
CVSS
3 months ago
Low nvd

CVE-2026-10175: A security flaw has been discovered in Aider-AI Aider 0.86.3. Affected by this vulnerability is the function editor_code

A security flaw has been discovered in Aider-AI Aider 0.86.3. Affected by this vulnerability is the function editor_coder.run of the file auth.py of the component Architect Mode. Performing a manipula...

2.1
CVSS
3 months ago
High github

PraisonAI has an Arbitrary File Write in Python API

# Bug Report: Arbitrary File Write in Python API ## Summary Hidden metadata in a webpage causes PraisonAI agents to write attacker-controlled content to arbitrary paths. `write_file` skips path vali...

Prompt Injection Remote Code Execution prompt injection deepseek openai llm
0.0
CVSS
3 months ago
Critical github

PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution

## Summary The first-party PraisonAI A2A server example combines three behaviors into a remotely exploitable Critical chain: 1. The example exposes an A2A server without configuring `auth_token`. 2....

Remote Code Execution Data Leakage anthropic litellm openai gemini a2a llm
9.8
CVSS
3 months ago
High github

PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate

## Summary The fix for GHSA-9mqq-jqxf-grvw / CVE-2026-44336 is incomplete. The original advisory description named four vulnerable handlers in `mcp_server/adapters/cli_tools.py`: > "registers four f...

Remote Code Execution Agentic / MCP claude code mcp server openai claude cursor llm
0.0
CVSS
3 months ago
High github

PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334

Arbitrary code execution via ungated spec.loader.exec_module in agents_generator.py (v4.6.32 chokepoint refactor bypass) Summary The v4.6.32 chokepoint refactor (which patched CVE-2026-44334 / GHSA-xc...

8.1
CVSS
3 months ago
High nvd

CVE-2026-45555: Roslyn CodeLens MCP Server is a Roslyn-based MCP server providing semantic code intelligence for .NET codebases. From 0.

Roslyn CodeLens MCP Server is a Roslyn-based MCP server providing semantic code intelligence for .NET codebases. From 0.0.9 to 1.17.0, the get_diagnostics MCP tool loads and executes all DiagnosticAna...

7.8
CVSS
3 months ago
Low nvd

CVE-2026-10061: A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS.

A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. The manipulation of the argument peerPin results in command injection. The attac...

2.1
CVSS
3 months ago
Low nvd

CVE-2026-10060: A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /gofor

A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /goform/formSetRoute. The manipulation of the argument ip/mask/gateway leads to comman...

2.1
CVSS
3 months ago
High nvd

CVE-2026-4944: vllm-project/vllm version 0.14.1 contains a vulnerability where the `trust_remote_code=True` parameter is hardcoded in t

vllm-project/vllm version 0.14.1 contains a vulnerability where the `trust_remote_code=True` parameter is hardcoded in two model implementation files (`vllm/model_executor/models/nemotron_vl.py` and `...

Remote Code Execution huggingface vllm
8.8
CVSS
3 months ago
High github

Symfony has Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address

### Description `Symfony\Component\Mime\Address` is the value-object every Symfony Mailer address (to/cc/bcc/from/reply-to) flows through; its constructor is documented as validating the address and...

0.0
CVSS
3 months ago
Critical github

Langroid has Prompt to SQL Injection, Leading to RCE

# Security Vulnerability Report: Prompt to SQL Injection leading to RCE in latest Langroid ## Affected Scope langroid < 0.63.0 ## Vulnerability Description SQLChatAgent executes SQL produced by an...

Prompt Injection Remote Code Execution prompt injection deepseek openai llm
9.8
CVSS
3 months ago
Critical nvd

CVE-2026-7524: IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links duri

IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction.

9.8
CVSS
3 months ago
High nvd

CVE-2026-44843: LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains

LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other app...

8.2
CVSS
3 months ago
High nvd

CVE-2026-44209: Banks generates meaningful LLM prompts using a template language that makes sense. Prior to 2.4.2, banks uses jinja2.Env

Banks generates meaningful LLM prompts using a template language that makes sense. Prior to 2.4.2, banks uses jinja2.Environment() (unsandboxed) to render prompt templates. Applications that pass user...

7.5
CVSS
3 months ago
Low osv

HuggingFace transformers vulnerable to remote code execution

A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config....

3.0
CVSS
3 months ago
Low osv

PYSEC-2026-2220

A vulnerability in MLflow versions

3.1
CVSS
3 months ago
Low osv

PYSEC-2026-2289

A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config....

3.0
CVSS
3 months ago
Critical github

Twig: PHP code injection via `{% use %}` template name

### Description `Compiler::string()` escapes `"`, `$`, `\`, NUL and TAB when generating PHP double-quoted string literals, but does not escape single quotes. In `ModuleNode::compileConstructor()`, th...

Remote Code Execution anthropic claude
0.0
CVSS
4 months ago
High github

lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out

> ## 📋 Reframing (2026-05-02): implicit unsafe remote-code path, not "supply-chain" > > The accurate description of this vulnerability is: > **"`get_model_arch` and related helpers hardcode `trust_re...

Supply Chain Remote Code Execution transformers hugging face huggingface pytorch vllm
7.8
CVSS
4 months ago
Medium github

Amazon SageMaker Python SDK is missing integrity verification in its Triton inference handler

## Summary Amazon SageMaker Python SDK is an open-source library for training and deploying machine learning models on Amazon SageMaker. An issue exists where, under certain circumstances, the Triton...

Remote Code Execution machine learning triton
7.2
CVSS
4 months ago
High github

LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization

## Summary lmdeploy hardcodes `trust_remote_code=True` in multiple HuggingFace model-loading call sites. The affected code paths are in: ```text lmdeploy/archs.py lmdeploy/utils.py ```` The vulner...

Remote Code Execution transformers huggingface
7.8
CVSS
4 months ago
Low osv

Diffusers: TOCTOU Trust Remote Code Bypass

## Background This vulnerability is found in the `diffusers` package - the `transformers`-equivalent library for diffusion models. It is found in the `DiffusionPipeline.from_pretrained` flow, which...

3.1
CVSS
4 months ago