Skip to content

ATR: proposals awaiting human PoC #82

Description

@github-actions

Auto-maintained work queue. Each proposal below has a CVE or advisory but NO PoC code block, so the auto-generator could only infer detection patterns from description prose. Promoting prose-grounded patterns detects the sentence that describes the attack, not the attack (the MiroFish failure mode), so these are never auto-promoted.

To clear an item: open the proposal, replace detection.conditions with a regex derived from the real exploit payload, run scripts/check-rules-safety.ts, then scripts/promote-detection-ready.ts --write. It drops off this list automatically once promoted.

Proposal Draft ID Title
proposals/ghsa/GHSA-2jrp-274c-jhv3.proposal.yaml ATR-DRAFT-2026-25580 Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling
proposals/ghsa/GHSA-345p-7cg4-v4c7.proposal.yaml ATR-DRAFT-2026-25536 @modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
proposals/ghsa/GHSA-5h2m-4q8j-pqpj.proposal.yaml ATR-DRAFT-2025-69196 FastMCP OAuth Proxy token reuse across MCP servers
proposals/ghsa/GHSA-c2jp-c369-7pvx.proposal.yaml ATR-DRAFT-GHSA-c2jp-c369-7pvx FastMCP Auth Integration Allows for Confused Deputy Account Takeover
proposals/ghsa/GHSA-mphv-75cg-56wg.proposal.yaml ATR-DRAFT-2026-27795 LangChain Community: redirect chaining can lead to SSRF bypass via RecursiveUrlLoader
proposals/ghsa/GHSA-mxxr-jv3v-6pgc.proposal.yaml ATR-DRAFT-2025-62800 FastMCP vulnerable to reflected XSS in client's callback page
proposals/ghsa/GHSA-qh6h-p6c9-ff54.proposal.yaml ATR-DRAFT-2026-34070 LangChain Core has Path Traversal vulnerabilites in legacy load_prompt functions
proposals/ghsa/GHSA-v34v-rq6j-cj6p.proposal.yaml ATR-DRAFT-2026-25528 LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection
proposals/ghsa/GHSA-v4p8-mg3p-g94g.proposal.yaml ATR-DRAFT-2026-42271 LiteLLM: Authenticated command execution via MCP stdio test endpoints
proposals/ghsa/GHSA-wxxx-gvqv-xp7p.proposal.yaml ATR-DRAFT-2026-40217 LiteLLM has a sandbox escape in custom-code guardrail
proposals/nvd/CVE-2025-64340.proposal.yaml ATR-DRAFT-CVE-2025-64340 FastMCP is the standard framework for building MCP applications.
proposals/nvd/CVE-2026-1839.proposal.yaml ATR-DRAFT-CVE-2026-1839 A vulnerability in the HuggingFace Transformers library, specifically in the Trainer class, allows for arbit
proposals/nvd/CVE-2026-21866.proposal.yaml ATR-DRAFT-CVE-2026-21866 Dify is an open-source LLM app development platform.
proposals/nvd/CVE-2026-25960.proposal.yaml ATR-DRAFT-CVE-2026-25960 vLLM is an inference and serving engine for large language models (LLMs).
proposals/nvd/CVE-2026-27124.proposal.yaml ATR-DRAFT-CVE-2026-27124 FastMCP is the standard framework for building MCP applications.
proposals/nvd/CVE-2026-27740.proposal.yaml ATR-DRAFT-CVE-2026-27740 Discourse is an open-source discussion platform.
proposals/nvd/CVE-2026-27940.proposal.yaml ATR-DRAFT-CVE-2026-27940 llama.cpp is an inference of several LLM models in C/C++.
proposals/nvd/CVE-2026-28788.proposal.yaml ATR-DRAFT-CVE-2026-28788 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline.
proposals/nvd/CVE-2026-29783.proposal.yaml ATR-DRAFT-CVE-2026-29783 The shell tool within GitHub Copilot CLI versions prior to and including 0.0.422 can allow arbitrary code exec
proposals/nvd/CVE-2026-29787.proposal.yaml ATR-DRAFT-CVE-2026-29787 mcp-memory-service is an open-source memory backend for multi-agent systems.
proposals/nvd/CVE-2026-29872.proposal.yaml ATR-DRAFT-CVE-2026-29872 A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f9
proposals/nvd/CVE-2026-30247.proposal.yaml ATR-DRAFT-CVE-2026-30247 WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval.
proposals/nvd/CVE-2026-30306.proposal.yaml ATR-DRAFT-CVE-2026-30306 In its design for automatic terminal command execution, SakaDev offers two options: Execute safe commands and
proposals/nvd/CVE-2026-30308.proposal.yaml ATR-DRAFT-CVE-2026-30308 In its design for automatic terminal command execution, HAI Build Code Generator offers two options: Execute s
proposals/nvd/CVE-2026-30616.proposal.yaml ATR-DRAFT-CVE-2026-30616 Jaaz 1.0.30 contains a remote code execution vulnerability in its MCP STDIO command execution handling.
proposals/nvd/CVE-2026-30617.proposal.yaml ATR-DRAFT-CVE-2026-30617 LangChain-ChatChat 0.3.1 contains a remote code execution vulnerability in its MCP STDIO server configuration
proposals/nvd/CVE-2026-30741.proposal.yaml ATR-DRAFT-CVE-2026-30741 A remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6 allows attackers to execute a
proposals/nvd/CVE-2026-30855.proposal.yaml ATR-DRAFT-CVE-2026-30855 WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval.
proposals/nvd/CVE-2026-30856.proposal.yaml ATR-DRAFT-CVE-2026-30856 WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval.
proposals/nvd/CVE-2026-30857.proposal.yaml ATR-DRAFT-CVE-2026-30857 WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval.
proposals/nvd/CVE-2026-30858.proposal.yaml ATR-DRAFT-CVE-2026-30858 WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval.
proposals/nvd/CVE-2026-30860.proposal.yaml ATR-DRAFT-CVE-2026-30860 WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval.
proposals/nvd/CVE-2026-30861.proposal.yaml ATR-DRAFT-CVE-2026-30861 WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval.
proposals/nvd/CVE-2026-31239.proposal.yaml ATR-DRAFT-CVE-2026-31239 The mamba language model framework thru 2.2.6 is vulnerable to insecure deserialization (CWE-502) when loading
proposals/nvd/CVE-2026-31252.proposal.yaml ATR-DRAFT-CVE-2026-31252 CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserializati
proposals/nvd/CVE-2026-31944.proposal.yaml ATR-DRAFT-CVE-2026-31944 LibreChat is a ChatGPT clone with additional features.
proposals/nvd/CVE-2026-31945.proposal.yaml ATR-DRAFT-CVE-2026-31945 LibreChat is a ChatGPT clone with additional features.

37 proposal(s) awaiting a PoC. Updated automatically by the daily CVE collector.

Metadata

Metadata

Assignees

No one assigned

    Labels

    auto-generatedBot-generated PR or issueneeds-human-pocProposal has a CVE/advisory but no PoC payload; needs a human-authored regex before promotion

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions