CVE-2026-29872Disclosure(theunwindai / awesome_llm_apps)

LOWCVSS 8.2 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-01-19). The affected Streamlit-based GitHub MCP Agent stores user-supplied API tokens in process-wide environment variables using os.environ without proper session isolation. Because Streamlit serves multiple concurrent users from a single Python process, credentials provided by one user remain accessible to subsequent unauthenticated users. An attacker can exploit this issue to retrieve sensitive information such as GitHub Personal Access Tokens or LLM API keys, potentially leading to unauthorized access to private resources and financial abuse.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-284CWE-522

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • awesome_llm_apps

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-31)
  • 3 total mentions across 2 days

Affected systems

Products
awesome_llm_apps

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-30: 1Mentions · 2026-03-31: 2Technical Details · 2026-03-30: 1Technical Details · 2026-03-31: 203-3003-31
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-301
Disclosure1
2026-03-312
Disclosure2
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-29872 A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-01-19). The affec… https://www.cve.org/CVERecord?id=CVE-2026-29872

    Post summary

    The text reports CVE-2026-29872 as a cross‑session information disclosure in the awesome‑llm‑apps project, yet it includes no PoC, exploit, patch, or evidence of active exploitation.

    00010332
    57.6K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-29872 A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-01-19). The affec… https://www.cve.org/CVERecord?id=CVE-2026-29872 ----- Traducción: CVE-2026-29872 Exi… http://infoflow.cloud`

    Post summary

    The post announces a newly disclosed CVE‑2026‑29872, outlining a cross‑session information disclosure flaw identified in a specific commit of the awesome‑llm‑apps project. No exploitation details, patches, or PoC are provided.

    0000053
    65 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-29872 - High A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-01-19). The affected Streamlit-based GitHu... https://www.thehackerwire.com/vulnerability/CVE-2026-29872/ https://t.co/GB3uch8BvY

    Post summary

    A new CVE-2026-29872 exposing cross‑session information disclosure in awesome‑llm‑apps was announced with technical details and a commit reference, but no exploit, PoC, or patch information is provided.

    0000059
    158 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptheunwindaiawesome_llm_apps2026-01-19--

Explore more