
The CVEs: - CVE-2026-25253: One-click RCE (CVSS 8.8) - CVE-2026-26322: SSRF in Gateway - CVE-2026-26329: Path traversal in uploads - Default bind to 0.0.0.0:18789 Any website could hijack a dev's agent. Zero interaction.
Post summary
The entry discloses several new CVEs with specific vulnerability types and a CVSS score, but does not provide any PoC, exploit code, or patch information.



