Security Advisories
Real-world vulnerabilities discovered and responsibly disclosed by turingpoint in widely used open-source and enterprise software.
Security Research
Published Advisories
turingpoint conducts active security research on widely used open-source and enterprise software. Many of these vulnerabilities surface directly during penetration tests for our clients. The following findings were identified by us, disclosed to the vendors through coordinated disclosure, and published as CVEs once a patch became available. Security research made in Germany.
Sort by:
Product
CVE
Vulnerability
CVSS
Advisory
- OpenReplayCVE-2026-55880Cross-user IDOR: logged-in user deletes/modifies other users' private notes and dashboard widgets (missing `user_id` check)7.1 · High
- OpenReplayCVE-2026-57230Authenticated ClickHouse SQL injection in session search (filter `name` + stored metadata key without escaping) → cross-project data access5.4 · Medium
- trigger.devCVE-2026-73659Cross-tenant object-store access via path traversal in the packet presign routes8.1 · High
- NocoBaseCVE-2026-79915Stored XSS via an SVG document uploaded as `.xml` in the file manager, served inline as `text/xml` (the nginx and Koa allowlists miss `.xml`), that exfiltrates the JWT from `localStorage`7.6 · High
- NocoBaseCVE-2026-52887Unauthenticated SQL injection in `/api/myInAppChannels:list` ($lt filter) leading to PG-superuser RCE10.0 · Critical
- TriliumCVE-2026-53580Arbitrary file disclosure and OOM crash via a `file://` URL in a note image `src` (`downloadImage()` passes the path unvalidated to `fs.readFile()`)8.1 · High
- MastodonCVE-2026-50129Persistent federated DoS via unhandled `NoMethodError` in `MATH_TRANSFORMER`7.5 · High
- HoppscotchCVE-2026-59721Admin RCE via insufficiently validated `MAILER_SMTP_URL`: nodemailer activates SendmailTransport and runs commands as root inside the container7.2 · High
- BudibaseCVE-2026-54350Anonymous NoSQL operator injection via published PUBLIC queries (unescaped parameters in JSON body)10.0 · Critical
- BudibaseCVE-2026-54352Arbitrary file read by a workspace builder via a symlink in a PWA zip (`/data/.env` → JWT forgery → global admin)9.6 · Critical
- Frigatenot requestedRTSP credential leak via a user-shared nginx proxy cache6.5 · Medium
- DokployCVE-2026-72868Command injection as host root by a member role via `destination.testConnection` (unescaped S3 fields in an `rclone` shell command plus a skipped permission check)9.9 · Critical
- NocoDBCVE-2026-47387Stored XSS via a form view's `redirect_url` → account takeover8.7 · High
- CasdoorCVE-2026-52352Stored XSS via uploaded SVG files served from the public `/files` path (no `nosniff`, no CSP, no `Content-Disposition`) → privilege escalation to administrator8.7 · High
- HeadplaneCVE-2026-46484Path traversal + RBAC bypass in `renameNode`8.1 · High
- authentikCVE-2026-42849Reflected XSS in the SFE AutosubmitStage via OAuth2 redirect_uri/state9.3 · Critical
- Argo CDCVE-2026-45738Stored XSS via the link.argocd.argoproj.io/* annotation7.3 · High
- ILIASCVE-2026-52351Blind SQL injection in the MyStaff lists via `_table_nav` (whitelist bypass)9.3 · Critical
- Chamilo LMSCVE-2026-45143Student-to-admin stored XSS in private messages via `v-html`9.0 · Critical
- Chamilo LMSCVE-2026-45144Pre-auth stored XSS on the public profile page `/user/{username}` via six unfiltered profile fields (`{% autoescape false %}`)8.9 · High
