AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T10:16:38.647Z and has not been modified since then. The vulnerability is a command injection vulnerability in the BOSH CLI tool on Windows in Cloud Foundry, allowing remote attackers to execute arbitrary shell commands. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. [truncated]
MEDIUMCloud Foundry FoundationCVE published 2026-05-27
A path traversal vulnerability in BOSH Director's local blobstore provider allows authenticated agents to read or delete arbitrary files on the director host. When processing long-running request responses (e.g., compile_package), the director passes agent-supplied blob identifiers unmodified to the local blobstore client. The LocalClient#object_file_path method constructs file paths via simple string con [truncated]