Vendor
Jovancoding vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 16 vulnerabilities in Jovancoding: 0 in the last 7 days and 9 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-58484, was published on 20 July 2026. 1 technology has a page of its own.
- Last 7 days
- 0
- Last 90 days
- 9
- Critical, all time
- 2
- Exploited in the wild
- 0
About Jovancoding
A software developer and maintainer of open-source projects on GitHub.
Jovancoding technologies
Latest Jovancoding vulnerabilities
- CVE-2026-58484: Jovancoding Network-AI arbitrary file deletion in EnvironmentManagerhighCVSS 7.1EPSS 0.2%
- CVE-2026-58482: Jovancoding Network-AI missing authentication in ApprovalInboxmediumCVSS 5.9EPSS 0.2%
- CVE-2026-58481: Jovancoding Network-AI path traversal in AgentRuntime sandboxmediumCVSS 6.5EPSS 0.2%
- CVE-2026-58414: Jovancoding Network-AI symlink following in EnvironmentManager backupmediumCVSS 5.5EPSS 0.2%
- CVE-2026-58413: Jovancoding Network-AI path traversal in EnvironmentManagermediumCVSS 6.1EPSS 0.2%
- CVE-2026-54051: Jovancoding Network-AI OS command injection in agent sandboxcriticalCVSS 9.9EPSS 0.7%
- CVE-2026-46701: Jovancoding Network-AI unauthenticated tool invocation in MCP SSE serverhighCVSS 7.6EPSS 0.2%
- CVE-2026-64623: Jovancoding Network-AI signature verification bypass in APSAdapterhighCVSS 8.6
- CVE-2026-64622: Jovancoding Network-AI missing authorization in ApprovalInbox GET routeshighCVSS 7.5
- Jovancoding Network-AI path traversal in EnvironmentManager.restoremediumCVSS 6.1
- Jovancoding Network-AI link following in EnvironmentManager backupmediumCVSS 5.5
- Jovancoding Network-AI missing authentication in ApprovalInboxmediumCVSS 5.9
- Jovancoding Network-AI path traversal in AgentRuntime sandboxmediumCVSS 6.5
- Jovancoding Network-AI arbitrary file deletion in backup pruninghighCVSS 7.1
- CVE-2026-48814: Jovancoding Network-AI missing authentication in MCP SSE servercriticalCVSS 9.1EPSS 0.5%
- CVE-2026-42856: Jovancoding Network-AI missing authentication in MCP HTTP transporthighCVSS 4EPSS 0.5%
Most severe Jovancoding vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-54051: Jovancoding Network-AI OS command injection in agent sandboxcriticalCVSS 9.9EPSS 0.7%
- CVE-2026-48814: Jovancoding Network-AI missing authentication in MCP SSE servercriticalCVSS 9.1EPSS 0.5%
- CVE-2026-64623: Jovancoding Network-AI signature verification bypass in APSAdapterhighCVSS 8.6
- CVE-2026-46701: Jovancoding Network-AI unauthenticated tool invocation in MCP SSE serverhighCVSS 7.6EPSS 0.2%
- CVE-2026-64622: Jovancoding Network-AI missing authorization in ApprovalInbox GET routeshighCVSS 7.5
- CVE-2026-58484: Jovancoding Network-AI arbitrary file deletion in EnvironmentManagerhighCVSS 7.1EPSS 0.2%
- Jovancoding Network-AI arbitrary file deletion in backup pruninghighCVSS 7.1
- CVE-2026-42856: Jovancoding Network-AI missing authentication in MCP HTTP transporthighCVSS 4EPSS 0.5%
- CVE-2026-58481: Jovancoding Network-AI path traversal in AgentRuntime sandboxmediumCVSS 6.5EPSS 0.2%
- Jovancoding Network-AI path traversal in AgentRuntime sandboxmediumCVSS 6.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 9 | 1 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/jovancoding.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Jovancoding vulnerabilities", https://junglewise.ai/threats/vendors/jovancoding, 26 September 2026.