Vulnerabilities

Summary — last 7 days

New vulnerabilities2,663▼ 380 vs. last week
Critical / high1,289▼ 36 vs. last week
New active exploitation (KEV)5▼ 3 vs. last week
Unscored (no CVSS)244▼ 274 vs. last week
–

1 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
Awaiting AnalysisHigh (7.8)0.19%—Google GenkitAI8/11/20268/26/2026
Genkit does not properly validate host request headers. Any host on the developer's network, and any website the developer visits (via DNS rebinding), can reach POST /api/runAction on the Dev UI server (default port 4000) and execute any registered Genkit action and read the result. Fixed on 2026-06-18.