Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2622▼ 226 respecto a la semana anterior
Críticas / altas1383▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Sin puntuar | 0.16% | — | DeeptutorAI | 1/10/2026 | 2/10/2026 | deeptutor 1.4.0 contains code injection in ExecTool.execute. Through the live tutorbot WebSocket interface, a remote caller can induce the tool layer to execute reviewer-chosen shell commands in the service environment. | |
| Aplazada | Sin puntuar | 0.14% | — | DeeptutorAI | 1/10/2026 | 2/10/2026 | deeptutor 1.4.0 contains a path traversal issue in EditFileTool.execute. Through the live tutorbot WebSocket interface, a remote caller can induce the tool layer to write or edit absolute paths outside the intended bot workspace. | |
| Aplazada | Sin puntuar | 0.15% | — | DeeptutorAI | 1/10/2026 | 2/10/2026 | deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in TutorBotManager.write_bot_file. A remote caller can enumerate bot IDs and overwrite another bot's whitelisted control files through the HTTP tutorbot file route. | |
| Aplazada | Sin puntuar | 0.15% | — | DeeptutorAI | 1/10/2026 | 2/10/2026 | deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in TurnRuntimeManager.regenerate_last_turn. A remote caller can enumerate or obtain a session_id and trigger regenerate on another user's session. | |
| Aplazada | Sin puntuar | 0.15% | — | DeeptutorAI | 1/10/2026 | 2/10/2026 | DeepTutor 1.4.0 contains an authorization bypass vulnerability in the book confirmation flow. An unauthenticated or unauthorized caller can reuse a publicly exposed book_id to submit a confirm-proposal request for an existing book, causing unauthorized overwrites of persisted metadata and spine content. | |
| Aplazada | Crítica (9.8) | 0.91% | — | DeeptutorAI | 30/9/2026 | 1/10/2026 | DeepTutor v1.4.0 is vulnerable to command execution in /tutorbot/agent/tools/shell.py:ExecTool.execute. | |
| Aplazada | Alta (7.7) | 0.60% | — | DeeptutorAI | 30/6/2026 | 14/7/2026 | DeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to invoke unrestricted MCP tools due to the allowed_mcp_tools function returning None instead of a denied result when mcp_tools is omitted from a user's grant in deeptutor/multi_user/tool_access.py. Attackers… |