PatchSiren

FluxBuilder CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM FluxBuilder CVE published 2026-07-13

CVE-2026-57375

A Missing Authorization vulnerability in FluxBuilder MStore API mstore-api allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MStore API: from n/a through <= 4.18.4. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. Users of MStore API by FluxBuilder, especially those using versions up to 4.18.4, should be aware of this vulnerability a [truncated]

MEDIUM FluxBuilder CVE published 2026-06-17

CVE-2026-54817

CVE-2026-54817 is a medium-severity vulnerability in the MStore API, affecting versions from n/a to 4.18.4. This Authentication Bypass Using an Alternate Path or Channel vulnerability allows for password recovery exploitation. The issue was published on June 17, 2026, and last modified on the same day. Users of the MStore API should be aware of this vulnerability and take necessary actions to mitigate pot [truncated]