Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/noctedefensor/LudusMCP

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

NocteDefensor LudusMCP version 1.0.24 contains a server-side request forgery (SSRF) vulnerability in the read_range_config component, specifically in the src/tools/rangeConfig.ts file. The vulnerability arises from manipulation of the 'Source' argument, which can be exploited remotely. The project has been informed but has not yet responded or issued a fix. The CVSS score is 6.3, indicating a medium severity impact.

Join the discussion

CVE-2026-19367 is a server-side request forgery (SSRF) vulnerability found in NocteDefensor LudusMCP version 1.0.24. It involves manipulation of the Source argument in the file src/tools/rangeConfig.ts within the read_range_config component. The vulnerability can be exploited remotely. The vendor has been informed but has not yet responded or issued a fix. The CVSS 4.0 base score is 5.3, indicating medium severity.

Join the discussion

A flaw has been found in NocteDefensor LudusMCP up to 1.0.24. Affected is an unknown function of the file src/tools/insertCredsRangeConfig.ts of the component insert_creds_range_config. Executing a manipulation of the argument configPath/outputPath can lead to path traversal. The attack is restricted to local execution. The project was informed of the problem early through an issue report but has not responded yet.

Join the discussion

A vulnerability was detected in NocteDefensor LudusMCP up to 1.0.24. This affects the function executeArbitraryCommand/executeCommand of the file src/ludusMCP/cliWrapper.ts of the component ludus_cli_execute. Performing a manipulation of the argument command/args results in command injection. The attack needs to be approached locally. The project was informed of the problem early through an issue report but has not responded yet.

Join the discussion

CVE-2026-19046 is a path traversal vulnerability in NocteDefensor LudusMCP affecting versions up to 1.0.24. The flaw exists in an unknown function within the src/tools/ludusEnvironmentGuidesSearch.ts file, specifically in the ludus_environment_guides_search component. Exploitation requires local access and involves manipulation of the guide_name argument to perform path traversal. The vendor has not yet responded or issued a fix for this vulnerability.

Join the discussion

CVE-2026-19045 is a command injection vulnerability in NocteDefensor LudusMCP affecting versions up to 1.0.24. The flaw exists in the function SecretDialog.showSecretDialog within src/utils/secretDialog.ts, specifically in the get_credential_from_user component. This vulnerability allows an attacker with local access to manipulate the Description argument to execute arbitrary commands. The issue was reported early to the project, but no response or fix has been provided yet.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Package: pkg:github/noctedefensor/LudusMCP
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses