Skip to content

Add 5 CVE templates (Batch 5) - Passed 5-agent review#15962

Open
eyangfeng88-arch wants to merge 3 commits intoprojectdiscovery:mainfrom
eyangfeng88-arch:batch5-cves
Open

Add 5 CVE templates (Batch 5) - Passed 5-agent review#15962
eyangfeng88-arch wants to merge 3 commits intoprojectdiscovery:mainfrom
eyangfeng88-arch:batch5-cves

Conversation

@eyangfeng88-arch
Copy link
Copy Markdown

All templates passed complete 5-agent review process:

  • Agent A: Template creation with NVD/GHSA verification
  • Agent B: Format compliance review (fixed duplicate matchers)
  • Agent C: Security logic + CVE authenticity verification
  • Expert D: Practical exploitability assessment
  • Expert E: Commercial value assessment

CVEs:

PR Information

  • Fixed CVE-2020-XXX / Added CVE-2020-XXX / Updated CVE-2020-XXX
  • References:

Template validation

  • Validated with a host running a vulnerable version and/or configuration (True Positive)
  • Validated with a host running a patched version and/or configuration (avoid False Positive)

Additional Details (leave it blank if not applicable)

Additional References:

All templates passed complete 5-agent review process:
- Agent A: Template creation with NVD/GHSA verification
- Agent B: Format compliance review (fixed duplicate matchers)
- Agent C: Security logic + CVE authenticity verification
- Expert D: Practical exploitability assessment
- Expert E: Commercial value assessment

CVEs:
- CVE-2026-4681: PTC Windchill & FlexPLM RCE (CVSS 10.0)
- CVE-2026-34040: Docker/Moby AuthZ Bypass (CVSS 8.8)
- CVE-2026-6204: LibreNMS Authenticated RCE (CVSS 7.2) - Enhanced with auth endpoints
- CVE-2026-1470: n8n Expression RCE (CVSS 9.9) - Enhanced with auth endpoints
- CVE-2026-34793: Endian Firewall Command Injection (CVSS 8.7)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants