GHSA-37h2-6p4f-mp3q
HIGHCVE-2026-49471Serena's built-in web dashboard exposes an unauthenticated Flask API on a fixed, predictable port (TCP 24282, hardcoded as 0x5EDA in constants.py). The server has no authentication, no CSRF protection, and no Host header validation. A DNS rebinding attack allows a malicious webpage to reach this API from any browser and write arbitrary content to the agent's persistent memory store — which the age
- Affected
- < 1.5.2
- Fixed in
- 1.5.2
- Weakness
- CWE-306
- Published
- 2026-07-08
- Source
- github