PatchSiren

QWED-AI CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH QWED-AI CVE published 2026-08-25

CVE-2026-55585

CVE-2026-55585 is a high-severity vulnerability in QWED's open-source AI verification infrastructure, allowing arbitrary Python code execution in the API server process. The issue, fixed in version 5.1.2, enables attackers to read or write files, modify data, execute operating system commands, terminate the service, and compromise other tenants in a shared deployment.

CRITICAL QWED-AI CVE published 2026-08-25

CVE-2026-55546

CVE-2026-55546 is a critical vulnerability in the QWED-MCP library, which is a deterministic verification gateway for MCP. The vulnerability exists in the verify_math_expression() function, where an attacker can pass untrusted input to execute arbitrary operating-system commands, read or modify accessible data, exfiltrate process secrets, or reach internal services.