Found in the wild

We ran zerotrail on a bunch of open-source projects. Everything below was surfaced by the engine and responsibly disclosed — each row links to its own advisory.

30 advisories published · 21 projects hardened · 6 awaiting disclosure · 9.6 highest CVSS

n8n-io/n8nMedium · Jun 22, 2026Anonymous MCP OAuth DCR: rogue-client redirect URI + unenforced scope contract fixed with a redirect-URI allowlist and consent-screen trust checkPR-24739triggerdotdev/trigger.devHigh · CVSS 7.7 · Jul 21, 2026Cross-tenant SQL injection in the TSQL query compiler (POST /api/v1/query) via unsanitized window-function nameGHSA-9q4r-4842-93vwtriggerdotdev/trigger.devHigh · CVSS 7.1 · Jul 9, 2026Missing authentication in run-replay action allows cross-organization task execution (IDOR)GHSA-pp95-gc86-jq6qlightdash/lightdashMedium · CVSS 6.4 · Aug 13, 2026SSRF via unvalidated Google Chat and Microsoft Teams webhook URLs in scheduled deliveriesGHSA-r263-56q3-8v3vhatchet-dev/hatchetMedium · CVSS 6.4 · Jun 30, 2026Cross-tenant write and DoS via Dispatcher gRPCCVE-2026-54746hatchet-dev/hatchetMedium · CVSS 5.3 · May 6, 2026Cross-tenant information disclosure in listTasksByDAGIdsCVE-2026-42572Mintplex-Labs/anything-llmMedium · CVSS 5.4 · Apr 15, 2026Stored DOM XSS via prompt-injected chart captionCVE-2026-41318
mindsdb/mindsdbHigh · PENDINGCoordinated — reported and accepted, awaiting publication.
entire.io/entire.ioHigh · PENDINGCoordinated — reported and accepted, awaiting publication.
ueberdosis/tiptapMedium · Apr 27, 2026Stored XSS in @tiptap/static-renderer — missing HTML escaping in serializeAttrsToHTMLString() and text-node renderingPR-7772
cline/clineHigh · PENDINGCoordinated — reported and accepted, awaiting publication.
maplibre/martinHigh · CVSS 7.5 · Aug 17, 2026Out-of-gamut CIE color in the static-overlay body panics the renderer and permanently kills the render worker poolGHSA-6774-6cqw-f586maplibre/martinMedium · CVSS 5.3 · Aug 17, 2026Unbounded id repetition in sprite, font, tiles amplifies server work for a byte-identical responseGHSA-5x5g-6p4c-jqfhBudibase/budibaseHigh · CVSS 8.1 · Aug 14, 2026Missing authorization on license management endpoints allows any authenticated user to delete licenseGHSA-4wr8-5c3p-rjcrheymrun/heymHigh · CVSS 8.8 · Jul 21, 2026Command execution via POST /api/mcp/fetch-tools stdio transport: supplied command is spawned before MCP validationGHSA-378x-q589-34mvreadest/readestHigh · CVSS 7.2 · Jul 17, 2026Unauthenticated SSRF in the /api/kosync proxy via an incomplete isLanAddress host filterGHSA-j57j-w9ph-xxmcheymrun/heymHigh · CVSS 8.8 · Jul 11, 2026Unsandboxed skill code execution: skills run via a local backend subprocess without the Docker isolation that Python tools mandateGHSA-hcv7-mg77-pg73heymrun/heymHigh · CVSS 7.1 · Jul 5, 2026SSRF via /api/mcp/fetch-tools reaches local and private URLs (SSE and streamable-HTTP transports)GHSA-jjvx-3wfc-p8hqweechat/weechatHigh · CVSS 7.5 · Jul 5, 2026Pre-auth memory leak in the relay-api handshake enables unauthenticated DoSGHSA-wmpc-m6g9-fwj8heymrun/heymHigh · CVSS 8.1 · Jul 4, 2026Missing role gate in team-member management lets any member alter the roster and reach shared credentialsGHSA-vxpw-x7j7-8723heymrun/heymMedium · CVSS 6.5 · Jul 4, 2026Horizontal IDOR: template get-by-id skips the visibility check the list path enforcesGHSA-5748-x76g-v68mlogto-io/logtoMedium · CVSS 6.1 · Jul 1, 2026XSS via unescaped RelayState in the SAML auto-submit formCVE-2026-54714mockoon/mockoonHigh · CVSS 8.8 · Jun 22, 2026Unauthenticated admin API + wildcard CORS enables secret theftGHSA-rqx4-3f6q-3x2vparse-community/parse-serverHigh · CVSS 8.7 · Jun 19, 2026Denial of service via deeply nested query operatorsGHSA-cgxm-vr2f-6fj8readest/readestCritical · CVSS 9.3 · Jun 18, 2026Unauthenticated SSRF with CORS bypass in the OPDS proxyGHSA-5g3f-mq2c-j65vbaptisteArno/typebot.ioCritical · CVSS 9.3 · May 24, 2026Unauthenticated arbitrary S3 object write via unsanitized filenameCVE-2026-48768ghostfolio/ghostfolioMedium · CVSS 6.5 · May 21, 2026Stripe subscription bypassCVE-2026-47127tambo-ai/tamboMedium · CVSS 5.4 · May 20, 2026SSRF in the URL validator (LLM, agent, and MCP URLs)GHSA-h669-rqwq-f598Budibase/budibaseHigh · CVSS 7.7 · May 15, 2026SSRF bypass via HTTP redirect in the REST datasourceCVE-2026-45715argos-ci/argosCritical · CVSS 9.3 · May 11, 2026Anonymous cross-tenant build injection and status spoofingGHSA-jw2w-wr3r-jp8wopenreplay/openreplayMedium · May 8, 2026Cross-tenant IDOR on feature-flag and assist-stats routesCVE-2026-45297siyuan-note/siyuanCritical · CVSS 9.6 · Mar 31, 2026Cross-origin RCE via permissive CORS and snippet injectionCVE-2026-34449dgtlmoon/changedetection.ioHigh · Mar 27, 2026Environment variable disclosure via the jq env builtinCVE-2026-33981
misoTTS/misoTTSCritical · PENDINGCoordinated — reported and accepted, awaiting publication.
FlowiseAI/flowiseHigh · PENDINGCoordinated — reported and accepted, awaiting publication.
tolgee/tolgee-platformMedium · PENDINGCoordinated — reported and accepted, awaiting publication.