[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 25 21:36:31 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ea0b5fb7 by Salvatore Bonaccorso at 2026-08-25T22:36:03+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -69,37 +69,37 @@ CVE-2026-79674 (NLTK versions before 3.10.3 contain a path sandbox bypass vulner
 	- nltk 3.10.3-1
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-3gq4-3j92-5w49
 CVE-2026-79673 (Ech0 before 4.4.3 protects the PUT /user endpoint with the profile:rea ...)
-	TODO: check
+	NOT-FOR-US: Ech0
 CVE-2026-79672 (Ech0 before 4.4.3 fails to enforce scope-based authorization on nine c ...)
-	TODO: check
+	NOT-FOR-US: Ech0
 CVE-2026-79671 (Ech0 through 4.2.1 contains a server-side request forgery vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: Ech0
 CVE-2026-79670 (Ech0 before 4.4.3 contains a stored cross-site scripting vulnerability ...)
-	TODO: check
+	NOT-FOR-US: Ech0
 CVE-2026-79669 (Ech0 before 4.4.3 lacks authorization checks on system log endpoints a ...)
-	TODO: check
+	NOT-FOR-US: Ech0
 CVE-2026-79668 (Ech0 before 4.7.3 contains an authentication bypass vulnerability in t ...)
-	TODO: check
+	NOT-FOR-US: Ech0
 CVE-2026-79667 (Ech0 version 4.3.4 and earlier fails to reliably enforce scoped access ...)
-	TODO: check
+	NOT-FOR-US: Ech0
 CVE-2026-79666 (Ech0 before 4.4.3 fails to enforce administrator authorization on dash ...)
-	TODO: check
+	NOT-FOR-US: Ech0
 CVE-2026-79665 (Ech0 before 4.5.1 contains an authorization bypass vulnerability where ...)
-	TODO: check
+	NOT-FOR-US: Ech0
 CVE-2026-79664 (Ech0 before 4.7.3 fails to properly revoke access tokens created with  ...)
-	TODO: check
+	NOT-FOR-US: Ech0
 CVE-2026-79663 (Ech0 before 4.7.3 contains a stored cross-site scripting vulnerability ...)
-	TODO: check
+	NOT-FOR-US: Ech0
 CVE-2026-79662 (Ech0 through 4.5.6 contains an OAuth redirect URI validation vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: Ech0
 CVE-2026-79661 (Ech0 through 4.5.6 registers the PUT /api/echo/like/:id endpoint on th ...)
-	TODO: check
+	NOT-FOR-US: Ech0
 CVE-2026-79660 (Ech0 versions before 4.7.3 expose guest commenter email addresses thro ...)
-	TODO: check
+	NOT-FOR-US: Ech0
 CVE-2026-79659 (Ech0 before 4.7.3 contains a server-side request forgery vulnerability ...)
-	TODO: check
+	NOT-FOR-US: Ech0
 CVE-2026-79658 (Ech0 before 5.0.1 does not impose any size or shape limit on the Accep ...)
-	TODO: check
+	NOT-FOR-US: Ech0
 CVE-2026-79657 (NLTK versions before 3.10.3 contain a remote code execution vulnerabil ...)
 	- nltk 3.10.3-1
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-x99w-6fgc-pmfw
@@ -369,39 +369,39 @@ CVE-2026-55553 (urllib is an HTTP client for Node.js that supports authenticatio
 CVE-2026-55546 (QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2 ...)
 	TODO: check
 CVE-2026-55541 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, pr ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-55540 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, is ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-55539 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, th ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-55538 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, pr ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-55537 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Jo ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-55536 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Br ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-55535 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, th ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-55534 (PraisonAI is a multi-agent teams system. From praisonai 4.6.34 until 4 ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-55533 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, cr ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-55532 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MC ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-55531 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, th ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-55530 (PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6. ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-55529 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, th ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-55528 (PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6. ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-55527 (PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6. ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-55526 (PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6. ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-55525 (PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6. ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-55419 (Reachy Mini is an SDK for controlling Reachy Mini robots. Prior to 1.8 ...)
 	TODO: check
 CVE-2026-53561 (An improper authentication vulnerability in HiveServer2 SAML bearer-to ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ea0b5fb7f7d0a5190d6e86938cecb1dcde0087e0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ea0b5fb7f7d0a5190d6e86938cecb1dcde0087e0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260825/3988976c/attachment.htm>


More information about the debian-security-tracker-commits mailing list