Known Vulnerabilities for Workspaces by @turbo
Listed below are 10 of the newest known vulnerabilities associated with "Workspaces" by "@turbo".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-82291 json | HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-ori... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-80209 json | The updateWorkspace handler in mods/identity/src/workspaces/createUpdateWorkspace.ts in Fonoster through 0.22.7 invokes the g... | Not Provided | 2026-08-27 | 2026-08-27 |
| CVE-2026-80049 json | Airbyte Platform resolves the workspace used for its authorization decision from a field the caller supplies. AuthorizationSe... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-75481 json | SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account p... | Not Provided | 2026-08-17 | 2026-08-18 |
| CVE-2026-71962 json | Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants-file... | Not Provided | 2026-08-10 | 2026-08-10 |
| CVE-2026-71476 json | Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx self-hos... | Not Provided | 2026-08-06 | 2026-08-08 |
| CVE-2026-70474 json | Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise h... | Not Provided | 2026-08-04 | 2026-08-05 |
| CVE-2026-70436 json | Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or perfor... | Not Provided | 2026-08-05 | 2026-08-06 |
| CVE-2026-69252 json | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/files ro... | Not Provided | 2026-08-04 | 2026-08-04 |
| CVE-2026-67622 json | Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that al... | Not Provided | 2026-08-06 | 2026-08-07 |