PatchSiren

lock-upme CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM lock-upme CVE published 2026-08-09

CVE-2026-19354

The CVE-2026-19354 vulnerability is a SQL injection issue in the IN Clause Handler of the controllers/messages/message.go file in lock-upme OPMS up to version 831440f37a92c1568f2e071d5233bc873a9d8b09. This vulnerability allows for remote attacks and has a CVSS score of 5.3, classified as MEDIUM severity. Security teams should review the official CVE record and assess the potential impact on their systems. [truncated]