Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-88939

Опубликовано: 10 сент. 2026
Источник: nvd
CVSS3: 8.3
EPSS Низкий

Описание

knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project directory and obtain write access capabilities.

EPSS

Процентиль: 19%
0.00268
Низкий

8.3 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 8.3
github
13 дней назад

knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project directory and obtain write access capabilities.

EPSS

Процентиль: 19%
0.00268
Низкий

8.3 High

CVSS3

Дефекты

CWE-863