CVE-2026-53776 is a critical vulnerability in Perry before version 0.5.1166. The vulnerability allows remote attackers to bypass token expiration by exploiting the unconditional setting of validate_exp = false in the verify_decode helper within the stdlib JWT verification path. This enables attackers in possession of a previously issued bearer token to present expired tokens to any jwt.verify() call and r [truncated]
CVE-2026-53777 is a HIGH-severity path traversal vulnerability in Perry, a software that allows a malicious build server to write arbitrary content to any location writable by the running process. The vulnerability is caused by unsanitized path components in the artifact_name field of ArtifactReady WebSocket messages. Attackers controlling the server URL can deliver traversal payloads through the artifact [truncated]