All CVEs — page 174 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
Authenticated users can modify their own account_role and account_id, and an authenticated non-member can read another tenant's knowledge-base chunks, potentially leading to unauthorized access and data modification.
The flaw allows local access to host services and other ToolHive-managed MCP proxies due to lack of network isolation, posing a high risk of data exposure and service disruption.