{"schema_version":1,"title":"HKUDS vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 31 vulnerabilities in HKUDS: 4 in the last 7 days and 16 in the last 90 days, 4 of them critical and 0 exploited in the wild. The most recent, CVE-2026-85740, was published on 22 September 2026. 4 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/hkuds","json_url":"https://junglewise.ai/threats/vendors/hkuds.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/hkuds","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":13,"all_time":31,"critical":4,"exploited":0,"last_7_days":4,"last_30_days":9,"last_90_days":16,"last_365_days":31},"latest":[{"cve":"CVE-2026-85740","cvss":7.1,"epss":0.0022,"slug":"cve-2026-85740-lightrag-ssrf-via-ipv6-transition-address-bypass-in-markdown","title":"LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, _validated_addresses in lightrag/parser/markdown/parser.py","severity":"high","exploited":false,"published_at":"2026-09-22T17:17:27.52+00:00","url":"https://junglewise.ai/threats/cve-2026-85740-lightrag-ssrf-via-ipv6-transition-address-bypass-in-markdown"},{"cve":"CVE-2026-85734","cvss":9.1,"epss":0.0036,"slug":"cve-2026-85734-lightrag-hku-login-endpoint-missing-rate-limiting-enables-brute","title":"LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the POST /login endpoint in lightrag/api/lightrag_server.p","severity":"critical","exploited":false,"published_at":"2026-09-22T17:17:27.367+00:00","url":"https://junglewise.ai/threats/cve-2026-85734-lightrag-hku-login-endpoint-missing-rate-limiting-enables-brute"},{"cve":"CVE-2026-85725","cvss":5.9,"epss":0.0036,"slug":"cve-2026-85725-lightrag-plaintext-password-timing-attack-vulnerability","title":"LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, verify_password in lightrag/api/passwords.py compares plai","severity":"medium","exploited":false,"published_at":"2026-09-22T17:17:27.203+00:00","url":"https://junglewise.ai/threats/cve-2026-85725-lightrag-plaintext-password-timing-attack-vulnerability"},{"cve":"CVE-2026-85709","cvss":5.3,"epss":0.0039,"slug":"cve-2026-85709-lightrag-api-sensitive-information-exposure-in-error-responses","title":"LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Python exception text","severity":"medium","exploited":false,"published_at":"2026-09-22T17:17:27.02+00:00","url":"https://junglewise.ai/threats/cve-2026-85709-lightrag-api-sensitive-information-exposure-in-error-responses"},{"cve":"CVE-2026-92576","cvss":8.6,"epss":0.0045,"slug":"cve-2026-92576-hkuds-nanobot-server-side-request-forgery-in-webfetchtool","title":"HKUDS nanobot server-side request forgery in WebFetchTool","severity":"high","exploited":false,"published_at":"2026-09-16T22:18:27.757+00:00","url":"https://junglewise.ai/threats/cve-2026-92576-hkuds-nanobot-server-side-request-forgery-in-webfetchtool"},{"cve":"CVE-2026-90809","cvss":7.3,"epss":0.0056,"slug":"cve-2026-90809-hkuds-nanobot-argument-injection-in-shell-command-execution","title":"HKUDS nanobot argument injection in shell command execution","severity":"high","exploited":false,"published_at":"2026-09-14T19:18:11.29+00:00","url":"https://junglewise.ai/threats/cve-2026-90809-hkuds-nanobot-argument-injection-in-shell-command-execution"},{"cve":"CVE-2026-90808","cvss":6.3,"epss":0.0041,"slug":"cve-2026-90808-hkuds-nanobot-incomplete-blacklist-in-shell-command-execution","title":"HKUDS nanobot incomplete blacklist in shell command execution","severity":"medium","exploited":false,"published_at":"2026-09-14T19:18:10.7+00:00","url":"https://junglewise.ai/threats/cve-2026-90808-hkuds-nanobot-incomplete-blacklist-in-shell-command-execution"},{"cve":"CVE-2026-86124","cvss":9.8,"epss":0.0098,"slug":"cve-2026-86124-autoagent-unauthenticated-remote-code-execution-in-tcp-server","title":"AutoAgent unauthenticated remote code execution in TCP server","severity":"critical","exploited":false,"published_at":"2026-09-05T10:16:43.9+00:00","url":"https://junglewise.ai/threats/cve-2026-86124-autoagent-unauthenticated-remote-code-execution-in-tcp-server"},{"cve":"CVE-2026-85030","cvss":3.7,"epss":0.0046,"slug":"cve-2026-85030-hkuds-ai-trader-business-logic-error-in-selfregister-api","title":"HKUDS AI-Trader business logic error in selfRegister API","severity":"low","exploited":false,"published_at":"2026-09-03T13:06:19.59+00:00","url":"https://junglewise.ai/threats/cve-2026-85030-hkuds-ai-trader-business-logic-error-in-selfregister-api"},{"cve":"CVE-2026-61740","cvss":4,"epss":0.0066,"slug":"cve-2026-61740-hkuds-lightrag-authentication-bypass-in-api-key-only-mode","title":"HKUDS LightRAG authentication bypass in API-key-only mode","severity":"critical","exploited":false,"published_at":"2026-07-15T15:16:48.35+00:00","url":"https://junglewise.ai/threats/cve-2026-61740-hkuds-lightrag-authentication-bypass-in-api-key-only-mode"},{"cve":"CVE-2026-61736","cvss":9.3,"epss":0.0142,"slug":"cve-2026-61736-hkuds-lightrag-permissive-cors-policy-in-api-server","title":"HKUDS LightRAG permissive CORS policy in API server","severity":"critical","exploited":false,"published_at":"2026-07-15T15:16:48.217+00:00","url":"https://junglewise.ai/threats/cve-2026-61736-hkuds-lightrag-permissive-cors-policy-in-api-server"},{"cve":"CVE-2026-58173","cvss":6.5,"slug":"cve-2026-58173-hkuds-vibe-trading-path-traversal-in-persistent-memory-storage","title":"HKUDS Vibe-Trading path traversal in persistent memory storage","severity":"medium","exploited":false,"published_at":"2026-06-30T17:16:24.447+00:00","url":"https://junglewise.ai/threats/cve-2026-58173-hkuds-vibe-trading-path-traversal-in-persistent-memory-storage"},{"cve":"CVE-2026-58171","cvss":4.2,"slug":"cve-2026-58171-hkuds-vibe-trading-path-traversal-in-swarm-run-identifier","title":"HKUDS Vibe-Trading path traversal in swarm run identifier","severity":"medium","exploited":false,"published_at":"2026-06-30T17:16:24.18+00:00","url":"https://junglewise.ai/threats/cve-2026-58171-hkuds-vibe-trading-path-traversal-in-swarm-run-identifier"},{"cve":"CVE-2026-58170","cvss":8.3,"slug":"cve-2026-58170-hkuds-vibe-trading-path-traversal-in-mandate-proposal-identifier","title":"HKUDS Vibe-Trading path traversal in mandate proposal identifier","severity":"high","exploited":false,"published_at":"2026-06-30T17:16:24.057+00:00","url":"https://junglewise.ai/threats/cve-2026-58170-hkuds-vibe-trading-path-traversal-in-mandate-proposal-identifier"},{"cve":"CVE-2026-58169","cvss":7.5,"slug":"cve-2026-58169-hkuds-vibe-trading-auth-bypass-and-rce-via-dns-rebinding","title":"HKUDS Vibe-Trading auth bypass and RCE via DNS rebinding","severity":"high","exploited":false,"published_at":"2026-06-30T17:16:23.907+00:00","url":"https://junglewise.ai/threats/cve-2026-58169-hkuds-vibe-trading-auth-bypass-and-rce-via-dns-rebinding"},{"cve":"CVE-2026-58168","cvss":8.8,"slug":"cve-2026-58168-hkuds-deeptutor-authorization-bypass-in-mcp-tool-access","title":"HKUDS DeepTutor authorization bypass in MCP tool access","severity":"high","exploited":false,"published_at":"2026-06-30T17:16:23.753+00:00","url":"https://junglewise.ai/threats/cve-2026-58168-hkuds-deeptutor-authorization-bypass-in-mcp-tool-access"},{"cve":"CVE-2026-56696","cvss":5.4,"epss":0.0037,"slug":"cve-2026-56696-hkuds-openharness-prompt-injection-via-slash-commands","title":"HKUDS OpenHarness prompt injection via slash commands","severity":"medium","exploited":false,"published_at":"2026-06-23T16:17:06.297+00:00","url":"https://junglewise.ai/threats/cve-2026-56696-hkuds-openharness-prompt-injection-via-slash-commands"},{"cve":"CVE-2026-56695","cvss":6.5,"epss":0.004,"slug":"cve-2026-56695-hkuds-openharness-missing-authorization-in-ohmo-gateway-slash","title":"HKUDS OpenHarness missing authorization in ohmo gateway slash commands","severity":"medium","exploited":false,"published_at":"2026-06-23T16:17:06.17+00:00","url":"https://junglewise.ai/threats/cve-2026-56695-hkuds-openharness-missing-authorization-in-ohmo-gateway-slash"},{"cve":"CVE-2026-48716","cvss":8.7,"slug":"cve-2026-48716-hkuds-nanobot-path-traversal-in-whatsapp-bridge","title":"HKUDS nanobot path traversal in WhatsApp bridge","severity":"high","exploited":false,"published_at":"2026-06-18T20:16:13.85+00:00","url":"https://junglewise.ai/threats/cve-2026-48716-hkuds-nanobot-path-traversal-in-whatsapp-bridge"},{"cve":"CVE-2026-12203","cvss":5.3,"slug":"cve-2026-12203-hkuds-ai-trader-information-disclosure-in-research-export","title":"HKUDS AI-Trader information disclosure in Research Export","severity":"medium","exploited":false,"published_at":"2026-06-15T02:16:12.1+00:00","url":"https://junglewise.ai/threats/cve-2026-12203-hkuds-ai-trader-information-disclosure-in-research-export"},{"cve":"CVE-2026-49140","cvss":4.3,"slug":"cve-2026-49140-hkuds-nanobot-denial-of-service-in-matrix-media-download-handler","title":"HKUDS Nanobot denial of service in Matrix media download handler","severity":"medium","exploited":false,"published_at":"2026-06-01T21:16:47.07+00:00","url":"https://junglewise.ai/threats/cve-2026-49140-hkuds-nanobot-denial-of-service-in-matrix-media-download-handler"},{"cve":"CVE-2026-49139","cvss":7,"slug":"cve-2026-49139-hkuds-nanobot-ssrf-and-token-disclosure-in-microsoft-teams","title":"HKUDS Nanobot SSRF and token disclosure in Microsoft Teams channel","severity":"info","exploited":false,"published_at":"2026-06-01T21:16:46.913+00:00","url":"https://junglewise.ai/threats/cve-2026-49139-hkuds-nanobot-ssrf-and-token-disclosure-in-microsoft-teams"},{"cve":"CVE-2026-49138","cvss":5,"epss":0.0049,"slug":"cve-2026-49138-hkuds-nanobot-ssrf-in-web-fetch-tool-via-redirect-following","title":"HKUDS Nanobot SSRF in web_fetch tool via redirect following","severity":"medium","exploited":false,"published_at":"2026-06-01T21:16:46.76+00:00","url":"https://junglewise.ai/threats/cve-2026-49138-hkuds-nanobot-ssrf-in-web-fetch-tool-via-redirect-following"},{"cve":"CVE-2026-32847","cvss":7.5,"slug":"cve-2026-32847-hkuds-deepcode-path-traversal-in-spa-catch-all-route","title":"HKUDS DeepCode path traversal in SPA catch-all route","severity":"high","exploited":false,"published_at":"2026-05-28T20:16:22.613+00:00","url":"https://junglewise.ai/threats/cve-2026-32847-hkuds-deepcode-path-traversal-in-spa-catch-all-route"},{"cve":"CVE-2026-40516","cvss":8.3,"epss":0.0018,"slug":"cve-2026-40516-hkuds-openharness-ssrf-in-web-fetch-and-web-search-tools","title":"HKUDS OpenHarness SSRF in web_fetch and web_search tools","severity":"high","exploited":false,"published_at":"2026-04-17T17:17:09.327+00:00","url":"https://junglewise.ai/threats/cve-2026-40516-hkuds-openharness-ssrf-in-web-fetch-and-web-search-tools"}],"vendor":{"hub":true,"name":"HKUDS","slug":"hkuds","homepage":"https://hkuds.github.io/","description":"The Data Science Lab at the University of Hong Kong.","url":"https://junglewise.ai/threats/vendors/hkuds"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":2,"exploited":0,"vulnerabilities":2},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":1,"exploited":0,"vulnerabilities":2},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-09-21","critical":1,"exploited":0,"vulnerabilities":4}],"most_severe":[{"cve":"CVE-2026-86124","cvss":9.8,"epss":0.0098,"slug":"cve-2026-86124-autoagent-unauthenticated-remote-code-execution-in-tcp-server","title":"AutoAgent unauthenticated remote code execution in TCP server","severity":"critical","exploited":false,"published_at":"2026-09-05T10:16:43.9+00:00","url":"https://junglewise.ai/threats/cve-2026-86124-autoagent-unauthenticated-remote-code-execution-in-tcp-server"},{"cve":"CVE-2026-61736","cvss":9.3,"epss":0.0142,"slug":"cve-2026-61736-hkuds-lightrag-permissive-cors-policy-in-api-server","title":"HKUDS LightRAG permissive CORS policy in API server","severity":"critical","exploited":false,"published_at":"2026-07-15T15:16:48.217+00:00","url":"https://junglewise.ai/threats/cve-2026-61736-hkuds-lightrag-permissive-cors-policy-in-api-server"},{"cve":"CVE-2026-85734","cvss":9.1,"epss":0.0036,"slug":"cve-2026-85734-lightrag-hku-login-endpoint-missing-rate-limiting-enables-brute","title":"LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the POST /login endpoint in lightrag/api/lightrag_server.p","severity":"critical","exploited":false,"published_at":"2026-09-22T17:17:27.367+00:00","url":"https://junglewise.ai/threats/cve-2026-85734-lightrag-hku-login-endpoint-missing-rate-limiting-enables-brute"},{"cve":"CVE-2026-61740","cvss":4,"epss":0.0066,"slug":"cve-2026-61740-hkuds-lightrag-authentication-bypass-in-api-key-only-mode","title":"HKUDS LightRAG authentication bypass in API-key-only mode","severity":"critical","exploited":false,"published_at":"2026-07-15T15:16:48.35+00:00","url":"https://junglewise.ai/threats/cve-2026-61740-hkuds-lightrag-authentication-bypass-in-api-key-only-mode"},{"cve":"CVE-2026-40502","cvss":8.8,"epss":0.0169,"slug":"cve-2026-40502-hkuds-openharness-command-injection-in-gateway-handler","title":"HKUDS OpenHarness command injection in gateway handler","severity":"high","exploited":false,"published_at":"2026-04-16T01:16:11.25+00:00","url":"https://junglewise.ai/threats/cve-2026-40502-hkuds-openharness-command-injection-in-gateway-handler"},{"cve":"CVE-2026-58168","cvss":8.8,"slug":"cve-2026-58168-hkuds-deeptutor-authorization-bypass-in-mcp-tool-access","title":"HKUDS DeepTutor authorization bypass in MCP tool access","severity":"high","exploited":false,"published_at":"2026-06-30T17:16:23.753+00:00","url":"https://junglewise.ai/threats/cve-2026-58168-hkuds-deeptutor-authorization-bypass-in-mcp-tool-access"},{"cve":"CVE-2026-48716","cvss":8.7,"slug":"cve-2026-48716-hkuds-nanobot-path-traversal-in-whatsapp-bridge","title":"HKUDS nanobot path traversal in WhatsApp bridge","severity":"high","exploited":false,"published_at":"2026-06-18T20:16:13.85+00:00","url":"https://junglewise.ai/threats/cve-2026-48716-hkuds-nanobot-path-traversal-in-whatsapp-bridge"},{"cve":"CVE-2026-92576","cvss":8.6,"epss":0.0045,"slug":"cve-2026-92576-hkuds-nanobot-server-side-request-forgery-in-webfetchtool","title":"HKUDS nanobot server-side request forgery in WebFetchTool","severity":"high","exploited":false,"published_at":"2026-09-16T22:18:27.757+00:00","url":"https://junglewise.ai/threats/cve-2026-92576-hkuds-nanobot-server-side-request-forgery-in-webfetchtool"},{"cve":"CVE-2026-40516","cvss":8.3,"epss":0.0018,"slug":"cve-2026-40516-hkuds-openharness-ssrf-in-web-fetch-and-web-search-tools","title":"HKUDS OpenHarness SSRF in web_fetch and web_search tools","severity":"high","exploited":false,"published_at":"2026-04-17T17:17:09.327+00:00","url":"https://junglewise.ai/threats/cve-2026-40516-hkuds-openharness-ssrf-in-web-fetch-and-web-search-tools"},{"cve":"CVE-2026-58170","cvss":8.3,"slug":"cve-2026-58170-hkuds-vibe-trading-path-traversal-in-mandate-proposal-identifier","title":"HKUDS Vibe-Trading path traversal in mandate proposal identifier","severity":"high","exploited":false,"published_at":"2026-06-30T17:16:24.057+00:00","url":"https://junglewise.ai/threats/cve-2026-58170-hkuds-vibe-trading-path-traversal-in-mandate-proposal-identifier"}],"generated_at":"2026-09-26T10:07:00.179841+00:00","technologies":[{"name":"HKUDS LightRAG","slug":"lightrag","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/lightrag"},{"name":"HKUDS Nanobot","slug":"nanobot","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/nanobot"},{"name":"HKUDS OpenHarness","slug":"openharness","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/openharness"},{"name":"HKUDS Vibe-Trading","slug":"vibe-trading","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/vibe-trading"}]}