Hinotobi
31 exploits
Active since Apr 2026
Vibe-Trading < 0.1.10 - Path Traversal in Proposal Identifier Allows Forging Live Trading Mandates
CVSS 8.3
Vibe-Trading < 0.1.10 - Path Traversal via Swarm Run Identifier
CVSS 4.2
CodexBar < 0.33.0 Credential Leakage via HTTP Redirect
CVSS 5.3
Summarize < 0.17.0 Disk Exhaustion via Uncapped Media Download
CVSS 4.3
Summarize < 0.17.0 SSRF via podcast:transcript URL fetch
CVSS 7.4
Hermes WebUI < 0.51.270 Resource Exhaustion via passkey/options
CVSS 5.3
CodexBar < 0.32.0 - Cleartext Transmission of Sensitive Information via HTTP Redirect
CVSS 5.9
CodexBar < 0.32.0 - Privilege Escalation via CLI Installer Temporary File Race Condition
CVSS 7.1
CodexBar < 0.32.0 - Insecure Temporary File Handling in Notarization Workflow
CVSS 7.1
Summarize < 0.15.1 Path Traversal via slidesDir Parameter
CVSS 7.1
Summarize < 0.15.1 Browser Extension Missing Authorization via Content Script
CVSS 6.1
Summarize < 0.15.1 Unapproved Browser Automation Execution
CVSS 5.4
Summarize < 0.15.1 Unauthorized Daemon Request via Untrusted Events
CVSS 7.4
Summarize < 0.15.1 Insecure File Permissions Information Disclosure
CVSS 5.5
Crabbox < v0.12.0 Authentication Bypass via Header Spoofing
CVSS 8.8
Crabbox < v0.12.0 Privilege Escalation via Agent Ticket Endpoints
CVSS 8.1
Crabbox < v0.12.0 Environment Variable Information Disclosure
CVSS 9.1
Summarize Insecure Daemon Configuration File Permissions
CVSS 6.1
Crabbox < 0.9.0 Authentication Bypass via Admin Claim Injection
CVSS 8.8
Crabbox < 0.9.0 Path Traversal via Islo Provider Workspace Resolution
CVSS 7.1
FastGPT: Stored MCP tool URL SSRF in FastGPT workflow execution
CVSS 6.3
AgentFlow Local Web API Content-Type Validation Bypass
CVSS 4.4
radare2 < 6.1.4 Project Notes Path Traversal via Symlink
CVSS 6.6
HKUDS OpenHarness Plugin Management Command Exposure
CVSS 8.8
HKUDS OpenHarness Insecure Default Remote Channel Allowlist
CVSS 8.2