[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 18 08:50:04 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ec1d18b5 by Salvatore Bonaccorso at 2026-08-18T09:49:03+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -5,21 +5,21 @@ CVE-2026-9816 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x
 CVE-2026-9693 (Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost f ...)
 	- mattermost-server <itp> (bug #823556)
 CVE-2026-75587 (Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-a ...)
-	TODO: check
+	NOT-FOR-US: Mattermost Desktop App
 CVE-2026-75531 (Pandora contains a stored cross-site scripting (XSS) vulnerability in  ...)
-	TODO: check
+	NOT-FOR-US: Pandora
 CVE-2026-75529 (Pandora is affected by a stored cross-site scripting vulnerability in  ...)
-	TODO: check
+	NOT-FOR-US: Pandora
 CVE-2026-75483 (powerlevel10k fails to neutralize control characters in the package.js ...)
-	TODO: check
+	NOT-FOR-US: powerlevel10k
 CVE-2026-75482 (SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1 ...)
-	TODO: check
+	NOT-FOR-US: SWE-agent
 CVE-2026-75481 (SkyPilot fails to validate that authenticated users are entitled to gr ...)
-	TODO: check
+	NOT-FOR-US: SkyPilot
 CVE-2026-75480 (OpenViking debug vector scroll and count endpoints apply only account- ...)
-	TODO: check
+	NOT-FOR-US: OpenViking
 CVE-2026-75479 (JimuReport contains an authentication bypass vulnerability in the repo ...)
-	TODO: check
+	NOT-FOR-US: JimuReport
 CVE-2026-75151 (A vulnerability has been found in SourceCodester Onlne Examination & L ...)
 	NOT-FOR-US: SourceCodester
 CVE-2026-75111 (Evidently UI fails to properly validate the filename parameter in the  ...)
@@ -229,11 +229,11 @@ CVE-2026-52886 (Notepad++ is a free and open-source source code editor. Prior to
 CVE-2026-51977 (An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Ve ...)
 	TODO: check
 CVE-2026-47698 (vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bri ...)
-	TODO: check
+	NOT-FOR-US: Node.js vm2
 CVE-2026-47686 (vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleE ...)
-	TODO: check
+	NOT-FOR-US: Node.js vm2
 CVE-2026-47683 (vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the buf ...)
-	TODO: check
+	NOT-FOR-US: Node.js vm2
 CVE-2026-45791 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
 	TODO: check
 CVE-2026-45790 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ec1d18b5dc5af0997f72ee5d62cd1c890e8ca237

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ec1d18b5dc5af0997f72ee5d62cd1c890e8ca237
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260818/ffe86d7c/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list