PatchSiren

QingYunA CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW QingYunA CVE published 2026-10-11

CVE-2026-108723

CVE-2026-108723 is a link following vulnerability in the am CLI code block src= embedding of answer-me-with-html through 0.5.0. The vulnerability allows attackers to embed readable external files into generated HTML by shipping a repository with a symlink pointing outside the checkout. This issue can lead to potential unauthorized file disclosure. Defenders should assess exposure and verify affected versi [truncated]