Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/hkuds/DeepTutor

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-51881: n/aCVE-2026-51881
0

deeptutor version 1.4.0 contains a code injection vulnerability in the ExecTool.execute function. This flaw allows a remote attacker to execute arbitrary shell commands on the service environment via the live tutorbot WebSocket interface. No patch or remediation information is currently available.

Join the discussion
CVE-2026-51880: n/aCVE-2026-51880
0

deeptutor version 1.4.0 has a path traversal vulnerability in the EditFileTool.execute function. This flaw allows a remote attacker, via the live tutorbot WebSocket interface, to write or modify files at arbitrary absolute paths outside the intended bot workspace.

Join the discussion
CVE-2026-51879: n/aCVE-2026-51879
0

deeptutor version 1.4.0 has an authorization bypass vulnerability in the TutorBotManager.write_bot_file function. This flaw allows a remote attacker to enumerate bot IDs and overwrite whitelisted control files of other bots via the HTTP tutorbot file route.

Join the discussion
CVE-2026-51878: n/aCVE-2026-51878
0

deeptutor version 1.4.0 has an authorization bypass vulnerability in the TurnRuntimeManager.regenerate_last_turn function. This flaw allows a remote attacker to use a user-controlled object identifier to enumerate or obtain another user's session_id and trigger regeneration on that session. No CVSS score is available for this vulnerability.

Join the discussion
CVE-2026-51876: n/aCVE-2026-51876
0

DeepTutor 1.4.0 contains an authorization bypass vulnerability in the book confirmation flow. An unauthenticated or unauthorized caller can reuse a publicly exposed book_id to submit a confirm-proposal request for an existing book, causing unauthorized overwrites of persisted metadata and spine content.

Join the discussion

DeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to invoke unrestricted MCP tools due to the allowed_mcp_tools function returning None instead of a denied result when mcp_tools is omitted from a user's grant in deeptutor/multi_user/tool_access.py. Attackers or prompt-injected content acting within a user session can enumerate and invoke any configured MCP tool, including filesystem, shell, and browser servers, gaining unauthorized access to sensitive deployment resources.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Package: pkg:github/hkuds/DeepTutor
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses