VYPR

Wanwu

by UnicomAI

CVEs (4)

  • CVE-2026-108853HigOct 11, 2026
    risk 0.46cvss 8.1epss —

    UnicomAI Wanwu before 0.6.3 contains an insecure direct object reference vulnerability that allows authenticated low-privileged users to delete other tenants' agent or RAG applications by supplying their appId. Attackers can send requests to DELETE /v1/appspace/app with guessed…

  • CVE-2026-108855MedOct 11, 2026
    risk 0.35cvss 5.4epss —

    UnicomAI Wanwu through 0.6.5 contains a missing authorization vulnerability that allows any authenticated enabled user to revoke other users' AppKeys for arbitrary apps via the unpublish endpoint. Attackers can supply a target appId and appType from the exploration marketplace…

  • CVE-2026-108854MedOct 11, 2026
    risk 0.28cvss 5.4epss —

    Wanwu before 0.6.3 contains an insecure direct object reference vulnerability that allows any authenticated enabled user to delete other users' legacy AppKeys by supplying a numeric apiId. Attackers can iterate sequential key IDs against DELETE /v1/appspace/app/key to revoke…

  • CVE-2026-108856MedOct 11, 2026
    risk 0.27cvss 4.2epss —

    UnicomAI Wanwu through 0.6.5 contains an authorization bypass vulnerability that allows authenticated users to mint AppKeys bound to other users' MCP servers via POST /v1/appspace/app/key. Attackers supplying a victim's MCP server UUID with appType mcpserver can open MCP…