VYPR

nightingale

by Ccfos

CVEs (2)

  • CVE-2026-85692MedSep 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Nightingale (n9e), as of commit 8362cbe (main branch, confirmed 2026-08-27), contains a server-side request forgery vulnerability in the isPublicIP function in aiagent/tools/http.go, the SSRF guard for the http_fetch AI-agent tool. The function only unwraps standard IPv4-mapped…

  • CVE-2026-58167MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.00

    Nightingale (n9e) before 9.0.0-beta.2 exposes full datasource configurations, including plaintext database passwords, HTTP bearer tokens, HTTP basic-auth passwords, and mTLS client keys, to any authenticated low-privilege (Standard role) user through POST…