Known Vulnerabilities for Web Agents by Ca
Listed below are 1 of the newest known vulnerabilities associated with "Web Agents" by "Ca".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-65015 json | n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution too... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-61442 json | PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on the PATCH routes for proje... | Not Provided | 2026-07-11 | 2026-07-13 |
| CVE-2026-61437 json | PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFlow._r... | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-61436 json | PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated attackers... | Not Provided | 2026-07-15 | 2026-07-15 |
| CVE-2026-61435 json | PraisonAI before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints (src/praisonai/praisonai... | Not Provided | 2026-07-15 | 2026-07-15 |
| CVE-2026-61426 json | PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement an... | Not Provided | 2026-07-11 | 2026-07-13 |
| CVE-2026-59929 json | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the safe_url filter in src/mistune/renderers/... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-59207 json | n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not enforce the All... | Not Provided | 2026-07-09 | 2026-07-09 |
| CVE-2026-59100 json | LobeChat through 2.2.9 contains a broken object level authorization vulnerability that allows authenticated attackers to acce... | Not Provided | 2026-07-02 | 2026-07-14 |
| CVE-2026-58499 json | EverOS is a memory runtime for agents. Prior to 1.0.1, EverOS is vulnerable to path traversal in the POST /api/v1/memory/add ... | Not Provided | 2026-07-10 | 2026-07-13 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ca | Web Agents | 6.0 |