VYPR

AiSOC

by Beenuar

CVEs (3)

  • CVE-2026-103055HigSep 30, 2026
    risk 0.42cvss 7.5epss —

    AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verification in the realtime WebSocket and SSE service when the AISOC_REALTIME_JWT_SECRET environment variable is not set. Unauthenticated attackers can forge subscription tickets with arbitrary tenant…

  • CVE-2026-103053MedSep 30, 2026
    risk 0.28cvss 5.4epss —

    AiSOC versions 9.0.0 before 12.0.0 fail to enforce authentication on the response-action API endpoints when AISOC_DEV_MODE is enabled and AISOC_ACTIONS_SERVICE_TOKEN is empty in the default Docker Compose deployment. Unauthenticated attackers can list response-action…

  • CVE-2026-103057MedSep 30, 2026
    risk 0.21cvss 4.3epss —

    AiSOC versions 5.1.0 before 12.0.0 contain an authentication bypass vulnerability in the realtime service internal endpoints POST /internal/agent-event and POST /internal/push. Attackers can post arbitrary events with spoofed tenant identifiers to broadcast malicious content…