Security Advisories
Real-world vulnerabilities discovered and responsibly disclosed by turingpoint in widely used open-source and enterprise software.
Security Research
Published Advisories
turingpoint conducts active security research on widely used open-source and enterprise software. Many of these vulnerabilities surface directly during penetration tests for our clients. The following findings were identified by us, disclosed to the vendors through coordinated disclosure, and published as CVEs once a patch became available. Security research made in Germany.
Sort by:
Product
CVE
Vulnerability
CVSS
Advisory
- BudibaseCVE-2026-54352Arbitrary file read by a workspace builder via a symlink in a PWA zip (`/data/.env` → JWT forgery → global admin)9.6 · Critical
- Frigatenot requestedRTSP credential leak via a user-shared nginx proxy cache6.5 · Medium
- DokployCVE-2026-72868Command injection as host root by a member role via `destination.testConnection` (unescaped S3 fields in an `rclone` shell command plus a skipped permission check)9.9 · Critical
- NocoDBCVE-2026-47387Stored XSS via a form view's `redirect_url` → account takeover8.7 · High
- CasdoorCVE-2026-52352Stored XSS via uploaded SVG files served from the public `/files` path (no `nosniff`, no CSP, no `Content-Disposition`) → privilege escalation to administrator8.7 · High
- HeadplaneCVE-2026-46484Path traversal + RBAC bypass in `renameNode`8.1 · High
- authentikCVE-2026-42849Reflected XSS in the SFE AutosubmitStage via OAuth2 redirect_uri/state9.3 · Critical
- Argo CDCVE-2026-45738Stored XSS via the link.argocd.argoproj.io/* annotation7.3 · High
- ILIASCVE-2026-52351Blind SQL injection in the MyStaff lists via `_table_nav` (whitelist bypass)9.3 · Critical
- Chamilo LMSCVE-2026-45143Student-to-admin stored XSS in private messages via `v-html`9.0 · Critical
- Chamilo LMSCVE-2026-45144Pre-auth stored XSS on the public profile page `/user/{username}` via six unfiltered profile fields (`{% autoescape false %}`)8.9 · High
- TYPO3 CoreCVE-2026-47348Stored XSS in the Indexed Search core system extension via unescaped page titles (`f:format.raw`)5.1 · Medium
