tag
Cors
High
Sliver C2 MCP Server Unauthenticated CORS/Preflight Bypass (CVE-2026-34227)
CVE-2026-34227 (GHSA-6fpf-248c-m7wm)·
Sliver C2 framework — MCP (Model Context Protocol) server interface
unpatched
High
Realtime Collaboration Platform — CORS Misconfiguration Leading to Authenticated Data Exposure (CVE-2026-27579)
CVE-2026-27579 (GHSA-qh5m-p8jh-hx88)·
realtime-collaboration-platform (karnop), backed by Appwrite
unpatched
High
OpenCode Unauthenticated Local HTTP Server -> Remote Code Execution (CVE-2026-22812)
CVE-2026-22812 (GHSA-vxw4-wv6m-9hhh)·
OpenCode (AI developer/coding agent tool) local HTTP server
patched
Critical
Nhost Local MCP Server Unauthenticated CORS Bypass Leading to Full Project Takeover (CVE-2026-34200)
CVE-2026-34200 (GHSA-6c5x-3h35-vvw2)·
Nhost CLI local MCP server (nhost mcp start)
unpatched