Copilot
35 exploits
Active since Feb 2025
langroid < 0.53.15 - Code Injection via TableChatAgent pandas eval()
CVSS 9.8
langroid < 0.53.15 - Remote Code Execution via LanceDocChatAgent QueryPlan.dataframe_calc
CVSS 9.8
kotaemon <= 0.10.6 - Path Traversal and Arbitrary File Read via Unvalidated File Path
CVSS 6.5
Lara Translate MCP Server <0.0.11 - Command Injection
CVSS 7.5
Gitpod < main-gha.33628 - Authenticated OAuth Token Exposure via Bitbucket Redirect Flow
CVSS 6.5
SillyTavern < 1.13.4 - DNS Rebinding via Host Whitelist Bypass
CVSS 9.6
koa 2.16.2-2.16.3 and 3.0.1-3.0.3 - Open Redirect via Referer Header Manipulation
CVSS 4.3
TinaCMS < 3.1.1 - Remote Code Execution via Gray-Matter Markdown Processing
CVSS 8.8
RustFS 1.0.0-alpha.13-1.0.0-alpha.77 - Denial of Service via Malformed gRPC GetMetrics Request
CVSS 4.0
NavigaTUM < 2026-02-03 - Unauthenticated Path Traversal and Arbitrary File Write via Propose Edits Endpoint
CVSS 7.5