Vulnerabilities
Summary — last 7 days
New vulnerabilities2,721▲ 17 vs. last week
Critical / high1,459▲ 351 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)72▼ 458 vs. last week
6 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.3) | 0.21% | — | Arc53 DocsgptAI | 9/14/2026 | 9/23/2026 | DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provider account emails by acting as window.opener during OAuth authorization, then use tokens to disconnect victims' cloud… | |
| Deferred | Critical (9.8) | 1.0% | — | Arc53 DocsgptAI | 9/4/2026 | 9/8/2026 | In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionality renders user-supplied prompt data using Jinja templates without input sanitization or sandboxing. An unauthenticated attacker can inject… | |
| Deferred | Low (1.3) | 0.13% | — | Arc53 DocsgptAI | 6/28/2026 | 6/29/2026 | A flaw has been found in arc53 DocsGPT up to 0.18.0. The affected element is the function encrypt_credentials of the file application/security/encryption.py of the component Credential Storage. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The… | |
| Modified | Critical (10) | 1.5% | — | Arc53 Docsgpt | 4/29/2026 | 6/17/2026 | DocsGPT is a GPT-powered chat for documentation. From version 0.15.0 to before version 0.16.0, an attacker accessing both the official DocsGPT website or any local and public deployment, can craft a malicious payload bypassing the "MCP test" behavior to achieve arbitrary remote code execution (RCE). This issue has… | |
| Deferred | Critical (9.3) | 17% | — | Arc53 DocsgptAI | 2/20/2025 | 6/17/2026 | A vulnerability, that could result in Remote Code Execution (RCE), has been found in DocsGPT. Due to improper parsing of JSON data using eval() an unauthorized attacker could send arbitrary Python code to be executed via /api/remote endpoint.. This issue affects DocsGPT: from 0.8.1 through 0.12.0. | |
| Deferred | Medium (5.3) | 0.57% | — | Arc53 DocsgptAI | 4/16/2024 | 6/17/2026 | DocsGPT is a GPT-powered chat for documentation. DocsGPT is vulnerable to unauthenticated limited file write in routes.py. This vulnerability is fixed in 0.8.1. |