AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-29T14:16:38.480Z and has not been modified since then. The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. This vulnerability allows an attacker to impersonate any Apple-linked account by setting alg=HS256 and signin [truncated]
CVE-2026-77067 is a Server-Side Request Forgery (SSRF) vulnerability in the omnivore-app/omnivore package. An authenticated user can make the server send repeated attacker-shaped requests to internal endpoints, including link-local metadata addresses, due to a lack of address validation in the setWebhookResolver function. This vulnerability allows for potential requests to link-local metadata addresses an [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-20T11:16:22.100Z and has not been modified since then. The NVD entry is currently 5.3 MEDIUM. The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to axios.get(url, rssParserConfig()) with no address validation. An authenticated user can [truncated]