Security Advisories
Real-world vulnerabilities discovered and responsibly disclosed by turingpoint in widely used open-source and enterprise software.
Security Research
Published Advisories
turingpoint conducts active security research on widely used open-source and enterprise software. Many of these vulnerabilities surface directly during penetration tests for our clients. The following findings were identified by us, disclosed to the vendors through coordinated disclosure, and published as CVEs once a patch became available. Security research made in Germany.
Sort by:
Product
CVE
Vulnerability
CVSS
Advisory
- TypebotpendingServer-Side Request Forgery in the HTTP Request block via a redirect bypass of the SSRF allowlist (incomplete fix of CVE-2025-64709)7.7 · High
- TracecatCVE-2026-58490Unauthenticated account takeover via unsigned SAML responses in Docker Compose (empty signing defaults disable signature verification) up to superadmin9.8 · Critical
- FreeScoutCVE-2026-53595Anonymous account takeover via `/user-setup` empty `invite_hash` (MySQL trailing-space)9.4 · Critical
- ts3-managerCVE-2026-54253Reflected XSS in the `/api/download` `port` parameter → theft of the operator session and ServerQuery password8.2 · High
- EspoCRMCVE-2026-53574Authenticated blind SQL injection via a complex expression in the `streamAttachments` endpoint's `where` parameter → extraction of admin session tokens and privilege escalation7.6 · High
- StatamicCVE-2026-54243CSV formula injection in form submission exports (anonymous field values without `EscapeFormula` neutralization)6.1 · Medium
- NovuCVE-2026-75510Stored XSS in the In-App Inbox via a notification URL with a `javascript:` scheme and `target=_self` (`window.open()` without scheme validation)8.7 · High
- LemmyCVE-2026-54743Stored XSS via Markdown image alt-text (html5-embed)5.4 · Medium
- KestraCVE-2026-53576Unauthenticated RCE via `/configs` auth-filter bypass → root in container + host takeover10.0 · Critical
- WekanCVE-2026-52890Arbitrary file read + DoS via `versions.original.path` in attachments7.1 · High
- SiYuanCVE-2026-54070Stored XSS in the Bazaar marketplace via a package README event-handler denylist bypass (JS in admin origin)7.1 · High
- OpenReplayCVE-2026-55879Unauthenticated stored XSS via tracker event data (`TextEllipsis` `innerHTML`) → dashboard account takeover via JWT in localStorage9.3 · Critical
- OpenReplayCVE-2026-55880Cross-user IDOR: logged-in user deletes/modifies other users' private notes and dashboard widgets (missing `user_id` check)7.1 · High
- OpenReplayCVE-2026-57230Authenticated ClickHouse SQL injection in session search (filter `name` + stored metadata key without escaping) → cross-project data access5.4 · Medium
- trigger.devCVE-2026-73659Cross-tenant object-store access via path traversal in the packet presign routes8.1 · High
- NocoBaseCVE-2026-52887Unauthenticated SQL injection in `/api/myInAppChannels:list` ($lt filter) leading to PG-superuser RCE10.0 · Critical
- TriliumCVE-2026-53580Arbitrary file disclosure and OOM crash via a `file://` URL in a note image `src` (`downloadImage()` passes the path unvalidated to `fs.readFile()`)8.1 · High
- MastodonCVE-2026-50129Persistent federated DoS via unhandled `NoMethodError` in `MATH_TRANSFORMER`7.5 · High
- HoppscotchCVE-2026-59721Admin RCE via insufficiently validated `MAILER_SMTP_URL`: nodemailer activates SendmailTransport and runs commands as root inside the container7.2 · High
- BudibaseCVE-2026-54350Anonymous NoSQL operator injection via published PUBLIC queries (unescaped parameters in JSON body)10.0 · Critical
