CVE-2026-10144 is a command injection vulnerability in Rsbuild before version 2.0.9. The vulnerability allows attackers to execute arbitrary OS commands by supplying a crafted URL containing shell metacharacters to the server.open configuration on macOS. The openBrowser() function in packages/core/src/server/open.ts passes the URL through encodeURI() before interpolating it into a shell command executed v [truncated]
CVE-2026-59804 is a high-severity vulnerability in Midscene Bridge Server through 1.10.3. The vulnerability allows unauthenticated remote attackers to hijack active bridge sessions by opening a cross-origin WebSocket connection to the local Socket.IO server, which performs no Origin header validation and requires no authentication token. This allows attackers to connect from any web page visited by the vi [truncated]