Security Advisories
Real-world vulnerabilities discovered and responsibly disclosed by turingpoint in widely used open-source and enterprise software.
Security Research
Published Advisories
turingpoint conducts active security research on widely used open-source and enterprise software. Many of these vulnerabilities surface directly during penetration tests for our clients. The following findings were identified by us, disclosed to the vendors through coordinated disclosure, and published as CVEs once a patch became available. Security research made in Germany.
Sort by:
Product
CVE
Vulnerability
CVSS
Advisory
- SurrealDBnot requestedAuthenticated path traversal via an analyzer `mapper` filter (arbitrary file read)7.7 · High
- Kanidmnot requestedAnonymous stack-overflow crash via deeply nested LDAP filter on LDAPS7.5 · High
- SemaphoreCVE-2026-73293Privilege escalation from `manager` to `owner` via a custom-role slug collision (resolver ignores the project id, `ValidateRole` has no blocklist and no permission ceiling)8.8 · High
- UnleashCVE-2026-63462Unauthenticated denial of service via deeply nested JSON to OpenAPI-validated endpoints (unguarded `JSON.stringify` → `RangeError`, process crash)7.5 · High
- Apache AirflowCVE-2026-58076Remote code execution in the Scheduler and the API server via an unchecked `import_string()` on the class name of an exception node in Dag deserialization (`executor_config` reaches the branch)8.8 · High
- Part-DBCVE-2026-54630Authenticated RCE via `.phar` file upload from `public/media`9.6 · Critical
- TypebotCVE-2026-62862Account takeover by anonymous brute-force of the six-digit magic-link login code (no rate limit, no lockout on the verify endpoint)9.1 · Critical
- TypebotCVE-2026-62865Arbitrary server file read via the Send Email block attachment path (missing `disableFileAccess`/`disableUrlAccess` options)7.7 · High
- TypebotpendingServer-Side Request Forgery in the HTTP Request block via a redirect bypass of the SSRF allowlist (incomplete fix of CVE-2025-64709)7.7 · High
- TracecatCVE-2026-58490Unauthenticated account takeover via unsigned SAML responses in Docker Compose (empty signing defaults disable signature verification) up to superadmin9.8 · Critical
- FreeScoutCVE-2026-53595Anonymous account takeover via `/user-setup` empty `invite_hash` (MySQL trailing-space)9.4 · Critical
- ts3-managerCVE-2026-54253Reflected XSS in the `/api/download` `port` parameter → theft of the operator session and ServerQuery password8.2 · High
- EspoCRMCVE-2026-53574Authenticated blind SQL injection via a complex expression in the `streamAttachments` endpoint's `where` parameter → extraction of admin session tokens and privilege escalation7.6 · High
- StatamicCVE-2026-54243CSV formula injection in form submission exports (anonymous field values without `EscapeFormula` neutralization)6.1 · Medium
- NovuCVE-2026-75510Stored XSS in the In-App Inbox via a notification URL with a `javascript:` scheme and `target=_self` (`window.open()` without scheme validation)8.7 · High
- LemmyCVE-2026-54743Stored XSS via Markdown image alt-text (html5-embed)5.4 · Medium
- KestraCVE-2026-53576Unauthenticated RCE via `/configs` auth-filter bypass → root in container + host takeover10.0 · Critical
- WekanCVE-2026-52890Arbitrary file read + DoS via `versions.original.path` in attachments7.1 · High
- SiYuanCVE-2026-54070Stored XSS in the Bazaar marketplace via a package README event-handler denylist bypass (JS in admin origin)7.1 · High
- OpenReplayCVE-2026-55879Unauthenticated stored XSS via tracker event data (`TextEllipsis` `innerHTML`) → dashboard account takeover via JWT in localStorage9.3 · Critical
