Skip to content

Instantly share code, notes, and snippets.

@stack72
Last active June 19, 2026 19:25
Show Gist options
  • Select an option

  • Save stack72/180de03c7f5be89af66ab979355c1892 to your computer and use it in GitHub Desktop.

Select an option

Save stack72/180de03c7f5be89af66ab979355c1892 to your computer and use it in GitHub Desktop.

CVE Research Report

Date: June 19, 2026 Lookback window: 1 day CVEs evaluated: 1742 CVEs in window: 69 (69 new)

Sources: NVD: 40 | GitHub: 80 | CISA KEV: 1623

Summary

Classification Count Reported
Vendor Products 45 summary only
Open-Source Libraries 22 22 (see below)
Web App / CMS Plugins 2 summary only

Monitor

Worth tracking but may not need a dedicated extension yet.

Network-AI (NEW)

CVE CVE-2026-48814
Published June 19, 2026
Severity CRITICAL (9.1)
Classification Open-Source Libraries
Source GitHub Advisory
Affected npm / network-ai
Actionability 4.4/10 — Monitor
Impact ░░░░░ 0/3
Scannable ███░░ 2/3
Remediation ███░░ 2/3

Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests

Why: dependency scanning can detect this; credential rotation may be needed

https://github.com/Jovancoding/Network-AI/security/advisories/GHSA-r78r-rwrf-rjwp

Crawl4AI (NEW)

CVE GHSA-GHSA-r253-r9jw-qg44
Published June 18, 2026
Severity CRITICAL (10)
Classification Open-Source Libraries
Source GitHub Advisory
Categories rce
Affected pip / crawl4ai
Actionability 4.4/10 — Monitor
Impact ███░░ 2/3
Scannable ███░░ 2/3
Remediation ░░░░░ 0/3

Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args

Why: dependency scanning can detect this; remote code execution

https://github.com/unclecode/crawl4ai/security/advisories/GHSA-r253-r9jw-qg44

Crawl4AI (NEW)

CVE GHSA-GHSA-2jq4-q6vv-4cp3
Published June 18, 2026
Severity CRITICAL (9.6)
Classification Open-Source Libraries
Source GitHub Advisory
Categories rce
Affected pip / crawl4ai
Actionability 4.4/10 — Monitor
Impact ███░░ 2/3
Scannable ███░░ 2/3
Remediation ░░░░░ 0/3

Crawl4AI: Arbitrary file write (path traversal) in crawler downloads can lead to RCE

Why: dependency scanning can detect this; remote code execution

https://github.com/unclecode/crawl4ai/security/advisories/GHSA-2jq4-q6vv-4cp3

@acastellon/auth (NEW)

CVE GHSA-GHSA-gfj5-979r-92pw
Published June 18, 2026
Severity CRITICAL (9)
Classification Open-Source Libraries
Source GitHub Advisory
Categories auth-bypass
Affected npm / @acastellon/auth
Actionability 4.4/10 — Monitor
Impact ░░░░░ 0/3
Scannable ███░░ 2/3
Remediation ███░░ 2/3

@acastellon/auth: Authentication bypass via spoofable headers in validateToken()

Why: dependency scanning can detect this; credential rotation may be needed

https://github.com/antonio-castellon/module-auth/security/advisories/GHSA-gfj5-979r-92pw

netlicensing-mcp (NEW)

CVE GHSA-GHSA-hxpf-9xvq-wph8
Published June 18, 2026
Severity CRITICAL (9.6)
Classification Open-Source Libraries
Source GitHub Advisory
Affected pip / netlicensing-mcp
Actionability 5.5/10 — Monitor
Impact ██░░░ 1/3
Scannable ███░░ 2/3
Remediation ███░░ 2/3

netlicensing-mcp: REST Path Traversal Bypasses Token Redaction

Why: dependency scanning can detect this; credential rotation may be needed

https://github.com/Labs64/NetLicensing-MCP/security/advisories/GHSA-hxpf-9xvq-wph8


Relevant Patch Items

These are in categories you care about (supply-chain, infrastructure, open-source libraries, or actively exploited) but don't need special tooling.

  • DotVVM (NEW) — Open-Source Libraries — CRITICAL (9) — June 19, 2026 DotVVM: Missing authorization in AuthorizeActionFilter

  • Tilt (NEW) — Open-Source Libraries — CRITICAL (9) — June 19, 2026 Tilt: Missing authentication on the network-exposed Tilt HUD server

  • Network-AI (NEW) — Open-Source Libraries — CRITICAL (9.9) — June 19, 2026 Network-AI: Improper Neutralization of Special Elements used in an OS Command

  • npm/gemini-mcp-tool (NEW) — Open-Source Libraries — CRITICAL (9.8) — June 18, 2026 gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)

  • OpenTofu (NEW) — Open-Source Libraries — HIGH (7.5) — June 19, 2026 OpenTofu: Possible arbitrary file read during certain git operations via a maliciously crafted URL

  • Agentic-Flow (NEW) — Open-Source Libraries — HIGH (8.8) — June 19, 2026 Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSync

  • ouroboros-ai (NEW) — Open-Source Libraries — HIGH (7.5) — June 19, 2026 ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys

  • nuget/DotVVM (NEW) — Open-Source Libraries — HIGH (7.5) — June 19, 2026 ReDoS in DotVVM routing

  • agent-coderag (NEW) — Open-Source Libraries — HIGH (8.6) — June 19, 2026 agent-coderag: Gradle Wrapper Execution During Dependency Discovery Enables Arbitrary Code Execution

  • parse-server (NEW) — Open-Source Libraries — HIGH (7.5) — June 19, 2026 parse-server: Denial of service via exponential-time processing of deeply nested query operators

  • pip/bedrock-agentcore (NEW) — Open-Source Libraries — HIGH (7.3) — June 19, 2026 Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()

  • maven/com.cedarpolicy:cedar-java (NEW) — Open-Source Libraries — HIGH (8.8) — June 19, 2026 CedarJava has policy injection vulnerability

  • maven/com.cedarpolicy:cedar-java (NEW) — Open-Source Libraries — HIGH (8.8) — June 19, 2026 CedarJava has type confusion vulnerability

  • npm/undici (NEW) — Open-Source Libraries — HIGH (7.5) — June 19, 2026 undici WebSocket client vulnerable to denial of service via fragment count bypass

  • npm/undici (NEW) — Open-Source Libraries — HIGH (7.5) — June 19, 2026 undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse

  • Tilt (NEW) — Open-Source Libraries — HIGH (7.5) — June 19, 2026 Tilt: Cross-site WebSocket hijacking of the Tilt HUD stream

  • Tilt (NEW) — Open-Source Libraries — HIGH (7.5) — June 19, 2026 Tilt: Unauthenticated pprof debug endpoints on the Tilt HUD server


Other

47 additional CVEs in vendor products and web app plugins — standard patching, no action needed.

Severity Count
Critical 20
High 27
Classification Count
Vendor Products 45
Web App / CMS Plugins 2

Scoring Methodology

Each CVE is classified (supply-chain, infrastructure, open-source library, vendor product, web app) and scored on three dimensions (0-3 each):

  • Impact: How many systems/users are affected?
  • Scannable: Can exposure be detected programmatically?
  • Remediation: Are there steps beyond just updating?

Total score (0-10) determines the recommendation:

  • 7+ = Extension candidate — build a swamp scanner
  • 4-6 = Monitor — track, but standard patching may suffice
  • <4 = Patch only — update and move on

Vendor product bugs and web app plugin vulns are summarised unless actively exploited (CISA KEV).

Sources: NVD, GitHub Advisory DB, CISA Known Exploited Vulnerabilities

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment