[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 11 21:31:09 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
3ad24b8c by Salvatore Bonaccorso at 2026-08-11T22:30:53+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -146,9 +146,9 @@ CVE-2026-73070 (Vim is an open source, command line text editor. Prior to 9.2.08
 	NOTE: https://github.com/vim/vim/security/advisories/GHSA-49m8-wwxj-mr69
 	NOTE: Fixed by: https://github.com/vim/vim/commit/5598618b2daf8e36b3bf0251caaefcf0bf8e85e4 (v9.2.0842)
 CVE-2026-73069 (Twenty is an open-source CRM (customer relationship management) platfo ...)
-	TODO: check
+	NOT-FOR-US: Twenty CRM
 CVE-2026-73068 (ToolJet is the open-source foundation am AI-native platform for buildi ...)
-	TODO: check
+	NOT-FOR-US: ToolJet
 CVE-2026-73067 (Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .tra ...)
 	- tesseract <unfixed>
 	NOTE: https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-x3vq-7rr7-5x3h
@@ -165,7 +165,7 @@ CVE-2026-72971 (Improper link resolution before file access ('link following') i
 CVE-2026-72925 (SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @s ...)
 	TODO: check
 CVE-2026-72922 (AutoGPT is a workflow automation platform for creating, deploying, and ...)
-	TODO: check
+	NOT-FOR-US: AutoGPT
 CVE-2026-72921 (SeaweedFS is a distributed storage system. Prior to 4.24, the weed/ser ...)
 	- seaweedfs <itp> (bug #956957)
 CVE-2026-72920 (SeaweedFS is a distributed storage system. Prior to 4.24, the filer re ...)
@@ -219,9 +219,9 @@ CVE-2026-72750 (n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection
 CVE-2026-72749 (n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution ...)
 	NOT-FOR-US: n8n
 CVE-2026-72748 (AVideo contains an unauthenticated arbitrary file write vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: WWBN AVideo
 CVE-2026-72747 (AVideo fails to sanitize the phone field during user registration, all ...)
-	TODO: check
+	NOT-FOR-US: WWBN AVideo
 CVE-2026-72746 (FreeRDP before 3.30.0 contains a server-side authentication bypass in  ...)
 	- freerdp3 3.30.0+dfsg-1
 	- freerdp2 <not-affected> (Vulnerable code ot present)
@@ -232,11 +232,11 @@ CVE-2026-72745 (FreeRDP before 3.30.0 contains an out-of-bounds vulnerability in
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vv64-95pc-vj9v
 CVE-2026-72744 (Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, conta ...)
-	TODO: check
+	NOT-FOR-US: Nuxt
 CVE-2026-72742 (DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image a ...)
-	TODO: check
+	NOT-FOR-US: DSPy
 CVE-2026-72713 (XAgent contains a path traversal vulnerability in the workspace file e ...)
-	TODO: check
+	NOT-FOR-US: XAgent
 CVE-2026-72712 (Nmap versions up to and including 7.99 contains a denial of service vu ...)
 	TODO: check
 CVE-2026-72694 (A flaw was found in MRTG. When the MRTG daemon is started as a root us ...)
@@ -1913,7 +1913,7 @@ CVE-2026-72874 (Dokploy is a free, self-hostable Platform as a Service (PaaS). P
 CVE-2026-72873 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
 	NOT-FOR-US: Dokploy
 CVE-2026-72743 (SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cros ...)
-	TODO: check
+	NOT-FOR-US: SQLBot
 CVE-2026-71966 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated c ...)
 	TODO: check
 CVE-2026-71965 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated r ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3ad24b8c2a7ca9add7ec474d9e567cf5a6b1480a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3ad24b8c2a7ca9add7ec474d9e567cf5a6b1480a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260811/3b0a7cad/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list