Threats Tagged 'cve-2026-81101'
View all threats tagged with 'cve-2026-81101'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-81101'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-81101: Exposure of Sensitive Information to an Unauthorized Actor in Airtable airtable-mcp-cliCVE-2026-81101 0 The configure command accepted any endpoint URL and stored it beside the user's access token. ConfigureCommand.execute in src/cli.ts persisted the value given to its endpoint option into the user profile without passing it through createSafeUrl in src/config.ts, the helper that already restricted the environment-variable form of the same setting to the vendor's own hosts over HTTPS. Because the connect path in src/mcp.ts attaches the stored token as a bearer credential on every request to the configured endpoint, a user who was persuaded to run configure with an endpoint of the attacker's choosing sent their personal access token to that destination on each subsequent invocation. Version 0.2.5 applies the same helper to the option. Join the discussion | CVE Database V5 | 08/27/2026, 14:50:40 UTC Added: 08/27/2026, 16:54:10 UTC |
Showing 1 to 1 of 1 result