PatchSiren

ahujasid CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM ahujasid CVE published 2026-07-24

CVE-2026-66004

CVE-2026-66004 is a path traversal vulnerability in BlenderMCP's download_polyhaven_asset method. The vulnerability allows attackers to write arbitrary files by injecting traversal sequences in API response include keys. This could lead to persistent code execution via malicious paths like '../../.bashrc'. The CVE record was published on 2026-07-24T15:19:07.050Z and has not been modified since then. Defen [truncated]