PatchSiren

modu-ai CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM modu-ai CVE published 2026-10-11

CVE-2026-108751

CVE-2026-108751 is a vulnerability in MoAI-ADK through 3.1.2 that allows malicious repositories to overwrite files outside the project via a symlinked .moai-tmp staging path. This vulnerability has a medium severity and requires immediate attention from MoAI-ADK users and administrators. The vulnerability is caused by an improper link resolution in the moai init template deployer. Attackers can commit a s [truncated]