PatchSiren

PerryTS CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL PerryTS CVE published 2026-06-16

CVE-2026-53776

CVE-2026-53776 is a critical vulnerability in Perry before version 0.5.1166. The vulnerability allows remote attackers to bypass token expiration by exploiting the unconditional setting of validate_exp = false in the verify_decode helper within the stdlib JWT verification path. This enables attackers in possession of a previously issued bearer token to present expired tokens to any jwt.verify() call and r [truncated]

HIGH PerryTS CVE published 2026-06-11

CVE-2026-53777

CVE-2026-53777 is a HIGH-severity path traversal vulnerability in Perry, a software that allows a malicious build server to write arbitrary content to any location writable by the running process. The vulnerability is caused by unsanitized path components in the artifact_name field of ArtifactReady WebSocket messages. Attackers controlling the server URL can deliver traversal payloads through the artifact [truncated]