PT-2026-24339 · Unknown · Coral-Server
Seafraf
·
Publicado
2026-03-10
·
Atualizado
2026-03-16
·
CVE-2026-30968
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Coral Server versions prior to 1.1.0
Description
Coral Server is an open collaboration infrastructure designed for communication, coordination, trust, and payments within The Internet of Agents. Before version 1.1.0, the Server Side Events (SSE) endpoint, specifically
/sse/v1/..., lacked robust validation to ensure connecting agents were authorized session participants. This could potentially allow for unauthorized message injection or observation.Recommendations
Update to version 1.1.0 or later.
Exploit
Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Coral-Server