[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-86259":6},{"stargazers_count":4,"fetched_at":5},7,"2026-09-07T05:55:14.258Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":50,"aliases":51,"duplicate_of":9,"upstream":52,"downstream":53,"duplicates":54,"related":55,"reserved_at":9,"published_at":56,"modified_at":56,"state":57,"summary":58,"references_raw":65,"kevs":97,"epss":9,"epss_history":98,"metrics":99,"affected":113},"CVE-2026-86259","OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url header or baseUrl parameter to access sensitive cloud credentials and metadata.",null,[11,40],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-306","Missing Authentication for Critical Function","The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.","weakness","Draft","Base","High",[20,24,28,32,36],{"id":21,"name":22,"techniques":23},"CAPEC-12","Choosing Message Identifier",[],{"id":25,"name":26,"techniques":27},"CAPEC-166","Force the System to Reset Values",[],{"id":29,"name":30,"techniques":31},"CAPEC-216","Communication Channel Manipulation",[],{"id":33,"name":34,"techniques":35},"CAPEC-36","Using Unpublished Interfaces or Functionality",[],{"id":37,"name":38,"techniques":39},"CAPEC-62","Cross Site Request Forgery",[],{"_key":41,"id":41,"name":42,"description":43,"type":15,"status":44,"abstraction":17,"likelihood_of_exploit":9,"capec":45},"CWE-918","Server-Side Request Forgery (SSRF)","The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.","Incomplete",[46],{"id":47,"name":48,"techniques":49},"CAPEC-664","Server Side Request Forgery",[],[],[],[],[],[],[],"2026-09-06T12:37:50.155Z","Received",{"cisa_kev":59,"cisa_ransomware":59,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":60,"severity_score":61,"severity_version":62,"severity_source":63,"severity_vector":64,"severity_status":57},false,"critical",9,"v4.0","cve.org","CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N",[66,72,77,81,87,92],{"url":67,"sources":68,"tags":70},"https://github.com/THU-MAIC/OpenMAIC/security/advisories/GHSA-9m7h-vh2h-rc3w",[63,69],"nvd",[71],"Vendor Advisory",{"url":73,"sources":74,"tags":75},"https://github.com/THU-MAIC/OpenMAIC/blob/v1.0.0/middleware.ts#L60-L63",[63,69],[76],"Technical Description",{"url":78,"sources":79,"tags":80},"https://github.com/THU-MAIC/OpenMAIC/blob/v1.0.0/app/api/generate/image/route.ts#L73-L78",[63,69],[76],{"url":82,"sources":83,"tags":84},"https://github.com/THU-MAIC/OpenMAIC/releases/tag/v1.0.1",[63,69],[85,86],"Patch","Release Notes",{"url":88,"sources":89,"tags":90},"https://github.com/THU-MAIC/OpenMAIC",[63,69],[91],"Product",{"url":93,"sources":94,"tags":95},"https://www.vulncheck.com/advisories/openmaic-before-1.0.1-ssrf-via-environment-gated-url-validation",[63,69],[96],"Third Party Advisory",[],[],[100,109],{"source":63,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":101,"cvss_v4_0":107},{"baseScore":102,"baseSeverity":103,"vectorString":104,"impactScore":105,"exploitabilityScore":106},7.5,"HIGH","CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N",7.8,5.6,{"baseScore":61,"baseSeverity":108,"vectorString":64,"impactScore":9,"exploitabilityScore":9},"CRITICAL",{"source":69,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":110,"cvss_v4_0":111},{"baseScore":102,"baseSeverity":103,"vectorString":104,"impactScore":105,"exploitabilityScore":106},{"baseScore":61,"baseSeverity":108,"vectorString":112,"impactScore":9,"exploitabilityScore":9},"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",[114],{"ecosystem":9,"name":115,"vendor":116,"product":117,"cpe_part":118,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":119},"OpenMAIC","thu-maic","openmaic","a",[120],{"version":121,"is_range":122,"range_type":63,"version_start":9,"version_start_type":9,"version_end":123,"version_end_type":124,"fixed_in":9},"\u003C 1.0.1",true,"1.0.1","excluding"]