<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:volotat:anagnorisis:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3avolotatanagnorisis/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 24 Sep 2026 18:47:35 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3avolotatanagnorisis/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Remote Access Vulnerability in Anagnorisis Socket.IO Interface</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-97231/</link><pubDate>Thu, 24 Sep 2026 18:47:35 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-97231/</guid><description>A missing authentication flaw in the Socket.IO Connect Interface of volotat Anagnorisis allows remote attackers to bypass security controls via the app.py component.</description><content:encoded><![CDATA[<p>CVE-2026-97231 describes a critical security flaw in the volotat Anagnorisis application, specifically affecting versions up to 0.3.1 and 0.4.0. The vulnerability resides within the Socket.IO Connect Interface defined in the app.py file. Analysis indicates that the component fails to properly implement authentication for Socket.IO connections, which allows remote, unauthenticated actors to interact with the interface. Since the application is designed to handle potentially sensitive data or control logic via Socket.IO, this flaw provides a vector for unauthorized access or execution of administrative commands without requiring valid credentials. Public exploits for this vulnerability are currently available, increasing the risk of exploitation. The vendor has not provided a patch or response to reports regarding this issue, leaving current deployments in a vulnerable state.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows remote attackers to bypass authentication entirely, gaining unauthorized access to the application's interface. Depending on the specific functionality exposed via the Socket.IO component, this could lead to information disclosure, unauthorized data modification, or service disruption for organizations relying on Anagnorisis.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the identification of all internet-facing instances of Anagnorisis within the environment. Since no vendor patch is currently available, network-level access controls should be implemented to restrict access to the Socket.IO endpoint to trusted IP addresses. Monitor web and application server logs for abnormal or unauthorized WebSocket handshake requests targeting the affected interface.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>authentication-bypass</category><category>remote-access</category></item></channel></rss>