Known Vulnerabilities for Oci-helper by Yohann0617
Listed below are 10 of the newest known vulnerabilities associated with "Oci-helper" by "Yohann0617".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-82862 json | Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing workspace files to shadow ... | Not Provided | 2026-08-31 | 2026-09-01 |
| CVE-2026-82249 json | gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attackers can... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-81731 json | Frappe 15.11.0 through 16.32.0 stores and renders the workspace card description without XSS filtering. The description field... | Not Provided | 2026-08-27 | 2026-08-31 |
| CVE-2026-81722 json | nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service i... | Not Provided | 2026-08-27 | 2026-08-27 |
| CVE-2026-81101 json | The configure command accepted any endpoint URL and stored it beside the user's access token. ConfigureCommand.execute in src... | Not Provided | 2026-08-27 | 2026-08-27 |
| CVE-2026-81100 json | tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/http... | Not Provided | 2026-08-27 | 2026-08-29 |
| CVE-2026-81099 json | tiger-slack started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. mcp/src/httpServ... | Not Provided | 2026-08-27 | 2026-08-27 |
| CVE-2026-81095 json | pg-aiguide started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts... | Not Provided | 2026-08-27 | 2026-08-29 |
| CVE-2026-81035 json | Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc/routers/team.ts authorises the cal... | Not Provided | 2026-08-26 | 2026-08-26 |
| CVE-2026-81030 json | Mage AI does not confine the paths accepted by its browser-items API to the project directory. BrowserItemResource in mage_ai... | Not Provided | 2026-08-26 | 2026-08-26 |