VYPR

cua

by Trycua

CVEs (1)

  • CVE-2026-86121CriSep 5, 2026
    risk 0.57cvss 9.8epss

    Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to execute arbitrary commands. Attackers can reach TCP port 8000 to run shell commands…