By vendor

Oraios-Ai vulnerabilities

Known CVEs affecting Oraios-Ai products, prioritized by severity, with SEC.co remediation and detection guidance.

1 published vulnerability

  • CVE-2026-49471HIGH 8.3

    Serena is a widely-used AI coding toolkit that includes a web dashboard for interacting with its semantic retrieval and code editing features. Before version 1.5.2, this dashboard ran an unprotected API server on a predictable port without authentication, CSRF defenses, or Host validation. An attacker can exploit this by crafting a malicious webpage; when a user visits it while Serena is running, the attacker's page can communicate directly with the local API via DNS rebinding and inject malicious commands into Serena's persistent memory. Because Serena autonomously reads and executes those commands—particularly through its shell command execution feature—the injected payload runs with the user's privileges. The attack requires only that the victim click a link; no special network position or prior compromise is needed.