Tag
Flask-Reuploaded Extension Denylist Bypass via Case-Folding Asymmetry
3 TTPs 1 CVEAn incomplete fix for CVE-2026-27641 in Flask-Reuploaded versions up to and including 1.5.0 allows attackers to bypass extension denylists through case-folding asymmetry, enabling the upload of malicious files with dangerous extensions (e.g., shell.PHP) that can lead to remote code execution on case-insensitive execution environments.
Serena Agent Unauthenticated RCE via DNS Rebinding (CVE-2026-49471)
1 rule 6 TTPs 1 CVE 1 IOCAn unspecified attacker can achieve remote code execution in Serena agent versions prior to 1.5.2 by leveraging an unauthenticated Flask dashboard, DNS rebinding, and memory poisoning, enabling persistent attacker-controlled command execution.
changedetection.io Authentication Bypass via Flask Decorator Misordering
2 rules 4 TTPs 1 IOCchangedetection.io is vulnerable to authentication bypass due to incorrect decorator ordering in Flask routes, allowing unauthenticated access to backup functionalities and potentially leading to data exfiltration of sensitive information.