PatchSiren

Jane-xiaoer CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Jane-xiaoer CVE published 2026-08-09

CVE-2026-19335

CVE-2026-19335 debrief: A path traversal vulnerability was found in the skill-vision-control project, affecting versions up to 1.3.0. The vulnerability exists in the getSkillVersionsDir function of the src/svc/utils/config.ts file. This issue allows a local attacker to manipulate file paths, potentially leading to unauthorized access or data exposure. The project was informed early but has not yet respond [truncated]