← Pavan Nallamothu

CVEs and Security Advisories

Twelve CVEs discovered and responsibly disclosed by Pavan Nallamothu, with fixes and credits from Apple, CISA, the NSA, and open-source projects including yt-dlp, AutoGPT, and BlueprintUE. Each entry links to the authoritative cve.org record and, where applicable, the GitHub Security Advisory.

CVE-2026-43763Medium 5.5

Apple macOS (Apple Type Services)

Sandbox file-read via a permissions issue in Apple Type Services, fixed across macOS Tahoe, Sequoia, and Sonoma.

CVE-2026-63013High 8.8

NationalSecurityAgency/skills-service

Privilege escalation via unauthorized admin-group assignment.

CVE-2026-63014Medium 4.3

NationalSecurityAgency/skills-service

Cross-project IDOR in the validateCopy endpoint.

CVE-2026-63177High 7.1

cisagov/Malcolm

Authorization bypass via a URI-normalization differential in the RBAC layer.

CVE-2026-63134Medium 5.4

cisagov/Malcolm

Directory traversal in archive extraction (guard/sink mismatch on directory entries).

CVE-2026-63133Medium 6.5

cisagov/Malcolm

Inode-exhaustion denial of service in archive extraction.

CVE-2026-33234Medium 5.0

Significant-Gravitas/AutoGPT

SSRF via a user-controlled SMTP server, bypassing the IP blocklist.

CVE-2026-50023High 8.3

yt-dlp/yt-dlp

Dangerous file-type creation via a filename-sanitization bypass (executable-shortcut injection).

CVE-2026-40588High 8.1

blueprintue/blueprintue-self-hosted-edition

Authenticated password change does not verify the current password (account takeover).

CVE-2026-40587Medium 6.5

blueprintue/blueprintue-self-hosted-edition

Active sessions are not invalidated after a password change or reset.

CVE-2026-40586High 7.5

blueprintue/blueprintue-self-hosted-edition

Missing brute-force protection on login.

CVE-2026-40585High 7.4

blueprintue/blueprintue-self-hosted-edition

Password-reset tokens have no expiry window.