Kira Security Research

Zero-days found by Kira.
Patched in the open.

Every vulnerability below was discovered by Kira, confirmed exploitable, responsibly disclosed to the affected maintainers, and patched.

Discovered by Kira Exploit verified Publicly disclosed and patched
Subscribe via RSS
CVE Disclosure CVE-2026-50160

One unauthenticated HTTP request.
Full server compromise.

Mass assignment on Hoppscotch's onboarding endpoint allowed injection of JWT_SECRET and SESSION_SECRET, enabling complete token forgery without any credentials.

CWE-915 Mass Assignment ≤ v2026.4.1 Self-hosted
Read full report
CVSS Score 10.0
Critical
CVSS v3.1
CVE

Ghost

Medium · Apr 2026

Webhook Delivery Fires Against Internal Network Addresses, Exposing Cloud Metadata

CVSS 5.5 · CWE-918 · CVE-2026-53945 · GHSA-ch52-px8q-f22j ↗

Read full report

NLTK

High · Aug 2026

User-Supplied Regex Passed to Python re Engine with No Timeout, One Pattern Hangs the Entire Process

CVSS 8.7 (v4) · CWE-1333 · CVE-2026-80205 ↗ · GHSA-rrv8-h7p8-rx55 ↗

Read full report
Vulnerabilities

Cognithor

Critical · Apr 2026

Any Visitor Could Steal Every API Key, Zero Authentication Required

CVSS 9.8 · CWE-306

Read full report

LiteLLM

Critical · Apr 2026

Org Admin Elevates Any User to Proxy Admin Across All Tenants in a Single Request

CVSS 9.0 · CWE-862 · CWE-269

Read full report

Microsoft

VibeVoice

High · Apr 2026

Malicious Checkpoint File Executes Arbitrary Code Before the App Loads

CVSS 7.8 · CWE-502

Read full report

Onyx AI

High · Jun 2026

Hardcoded Default Credential on Impersonation Endpoint Exposes Any Tenant in Enterprise Deployments

CVSS 8.7 · CWE-798 · No advisory published

Read full report

Redash

Medium · Apr 2026

Three Query Runners Reach Internal Services, Returning Response Bodies to the API Caller

CVSS 6.8 · CWE-918

Read full report

Want Kira on your codebase?

See what’s actually exploitable before attackers do.

Start scanning →