PatchSiren

Jeebase CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Jeebase CVE published 2026-10-05

CVE-2026-105180

A vulnerability was determined in Jeebase 0.0.1, affecting the function updateUser of the file /user/update/info of the component UserService. This could lead to dynamically-determined object attributes if a manipulation of the argument user/tempUser is executed. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early [truncated]