All vulnerabilities

CVE-2026-86045 · GHSA-cqr4-hcfp-m6m4

OpenOSINT: unauthenticated setup endpoint lets network attackers hijack AI backend traffic

criticalCVSS 10.0CWE-15CWE-306
Vendor
OpenOSINT
Package
openosint pip
Affected
<= 2.23.0
Disclosed
2026-08-24
Credit
Avishai Gonen
auth-bypassmcp