References https://www.twcert.org.tw/tw/cp-132-10620-527f1-1.html https://www.twcert.org.tw/newepaper/cp-151-10620-527f1-3.html https://www.appsecure.security/vulnerability-database/cve-2026-0853/ https://www.twcert.org.tw/tw/lp-132-1-3-20.html https://www.twcert.org.tw/newepaper/lp-151-3-2-20.html https://www.openinfosec.com/zh/shareArticle/content/1693
Related VulnerabilitiesPoCflowise-chatflows-exposure: Flowise AI - Unauthenticated Chatflows API ExposurePoClangflow-api-exposure: Langflow - Unauthenticated API ExposurePoCCVE-2026-42221: Nginx UI <= 2.3.7 - Unauthenticated Installer ExposurePoCgrafana-loki-api-exposure: Grafana Loki - Unauthenticated API AccessPoCvictoriametrics-vmagent-api-exposure: VictoriaMetrics vmagent - Unauthenticated Targets ExposurePoCmaven-settings-xml-exposure: Apache Maven settings.xml Credentials - ExposurePoCnuget-config-exposure: NuGet.config Package Source Credentials - ExposurePoCpypirc-credentials-exposure: Python .pypirc Credentials - ExposurePoCfastly-debug-headers: Fastly CDN Debug Headers ExposurePoCclaude-code-agents: Claude Code Subagent Configuration - ExposurePoCclaude-settings-exposure: Claude Code Project Settings ExposurePoCCVE-2026-59801: 9Router - Unauthenticated LLM Provider API ExposurePoCprodigy-panel: Prodigy Annotation Tool - Unauthenticated Exposure