EILMELDUNGEN LIVE
🕵️ SicherheitslückenMy Life, AI and the Future of LiveOverflow(23.08.2026 um 19:53 Uhr)
⚠️ Malware / Trojaner / VirenHow North Korean Hackers end up in your Network(24.08.2026 um 20:30 Uhr)
🔧 AI Nachrichten Sam Altman needs to put up or shut up about AI hacking(28.08.2026 um 16:25 Uhr)
⚠️ Malware / Trojaner / VirenUndetected Steam Malware: Sent by Viewer(28.08.2026 um 21:00 Uhr)
🎥 PodcastsBHIS - Talkin' Bout [infosec] News 2026-08-31(28.08.2026 um 17:13 Uhr)
🔧 AI Nachrichten Evernote 11.30.6(24.08.2026 um 17:14 Uhr)
🎥 Podcasts#121 Warum NIS 2 die Produktion verändert(24.08.2026 um 08:00 Uhr)
🕵️ SicherheitslückenMy Life, AI and the Future of LiveOverflow(23.08.2026 um 19:53 Uhr)
⚠️ Malware / Trojaner / VirenHow North Korean Hackers end up in your Network(24.08.2026 um 20:30 Uhr)
🔧 AI Nachrichten Sam Altman needs to put up or shut up about AI hacking(28.08.2026 um 16:25 Uhr)
⚠️ Malware / Trojaner / VirenUndetected Steam Malware: Sent by Viewer(28.08.2026 um 21:00 Uhr)
🎥 PodcastsBHIS - Talkin' Bout [infosec] News 2026-08-31(28.08.2026 um 17:13 Uhr)
🔧 AI Nachrichten Evernote 11.30.6(24.08.2026 um 17:14 Uhr)
🎥 Podcasts#121 Warum NIS 2 die Produktion verändert(24.08.2026 um 08:00 Uhr)

10 🕛 kürzlich 1 Min Lesezeit 8 Leser online ️ CVE-RADAR
0

CVE-2026-58500 | appium MCP up to 1.85.9 Locator Generator UI createLocatorGeneratorUI text/content-desc/resource-id/locator selector cross site scripting

Cyber Threat & Vulnerability Dossier CVSS 7.5 HIGH EPSS 30.6%
CVE-2026-58500
ANGRIPPSVEKTOR
🌐 Netzwerk (Remote)
AUTHENTIFIZIERUNG
🔓 Keine Authentifizierung nötig
SCHADENSPROFIL
RCE / Vollzugriff / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-94: Code Injection
Handlungsempfehlung: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
️ Im CVE-Radar öffnen
↗ Quelle (VulDB Updates)
🗣️ Stimme:

A vulnerability, which was classified as problematic, has been found in appium MCP up to 1.85.9. Affected by this vulnerability is the function createLocatorGeneratorUI of the component Locator Generator UI. This manipulation of the argument text/content-desc/resource-id/locator selector causes cross site scripting. The identification of this...

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf vuldb.com.
↗ Original-Artikel auf vuldb.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
117 Fachleser & IT-Security Experten haben diesen Report heute geteilt
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Community-Einschätzung (Live): 48 Stimmen
🟢 Gering: 45% 🟡 Beobachten: 35% 🔴 Akut: 20%

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 51%
🟡 In Evaluierung 31%
🟢 Keine Auswirkung 13%
Spannende Innovation 5%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
AI Agents Escaped the Evaluation Environment
1 Quelle
OpenAI's lawsuit delays cause more harm every day, says Apple
1 Quelle
My Life, AI and the Future of LiveOverflow