Vulnerability
Published 2026-10-11
Verified 2026-10-11

VulnCheck batch (11 Oct): Agnai's self-host setup ships a fixed admin password and public JWT signing secret (CVSS 9.4), Vearch vector database lets read-only users write data and grant themselves more rights (8.8), Easy!Appointments lets anyone take over bookings; AI-agent tools LlamaFarm, OpenAgents, MCP Kotlin SDK, mistral.rs and pinclaw also affected; no fixed releases listed

VulnCheck published about 50 CVEs on 11 October 2026 (CVE-2026-108710 to CVE-2026-108760), many in self-hosted AI and agent tooling. The worst is CVE-2026-108753 in Agnai (the open-source AI chat and roleplay app) through 1.0.555: its self-host Docker Compose file sets a fixed administrator password and a publicly known JWT signing secret, so anyone who can reach a deployment built from it can log in as admin, or sign their own token with admin rights, then impersonate users, reset passwords and change server settings (CVSS 3.1 9.4; 4.0 9.3). CVE-2026-108746 in the Vearch vector database 3.5.2 to 3.5.9 ignores read-only or no-access levels stored in a role, so a logged-in non-root user can insert and delete documents or call PUT /roles to give their own role write access, working toward cluster admin (8.8). CVE-2026-108758 in Easy!Appointments through 1.6.0 lets an unauthenticated attacker rewrite any appointment by guessing its sequential id and reassign it to their own customer record (8.2); a fix was committed to the main branch in June but is not in a tagged release yet. CVE-2026-108740 in GoatCounter web analytics through 2.7.0 lets a read-only user make themselves an admin (8.3), and CVE-2026-108718 in Rill 0.77.0 to 0.90.5 issues non-expiring API tokens to any newly registered OAuth client without asking the user, so one click on a crafted link hands over the user's full access (8.1). In AI-agent tooling: LlamaFarm through 0.0.34 binds its API, which needs no login, to all network interfaces, exposing stored model-provider API keys (CVE-2026-108760, 7.6); the OpenAgents Workspace backend lists every workspace, including an unmasked API key and creator emails, to anyone (CVE-2026-108739, 7.5); the MCP Kotlin SDK through 0.15.0 can be knocked over by WebSocket frames that announce near-2 GiB payloads (CVE-2026-108714, 7.5); mistral.rs 0.9.0 to 0.9.4 lets sandboxed or prompt-injected code read and overwrite files outside its sandbox through symlinks (CVE-2026-108759); and the pinclaw OpenClaw channel plugin through 0.3.0 accepts unauthenticated messages on a port open to the network, letting attackers inject instructions into the user's agent session (CVE-2026-108757). Lower-rated bugs hit JupyterHub, SuiteCRM, GLPI, LibreNMS, phpIPAM, Frappe HR and CRM, CloudBeaver, Traccar and others. The records list affected versions only and name no fixed releases. No exploitation has been reported. Primary: CVE records from VulnCheck as CNA.

Product
Agnai; Vearch; Easy!Appointments; GoatCounter; Rill; LlamaFarm; OpenAgents Workspace; MCP Kotlin SDK; mistral.rs; pinclaw (OpenClaw plugin); plus JupyterHub, SuiteCRM, GLPI, LibreNMS, phpIPAM, Frappe HR/CRM, CloudBeaver, Traccar and others
Versions
Agnai through 1.0.555; Vearch 3.5.2 to 3.5.9; Easy!Appointments through 1.6.0; GoatCounter through 2.7.0; Rill 0.77.0 to 0.90.5; LlamaFarm through 0.0.34; OpenAgents Workspace through launcher-v1.0.17; MCP Kotlin SDK through 0.15.0; mistral.rs 0.9.0 to 0.9.4; pinclaw through 0.3.0
CVSS
Agnai CVE-2026-108753 9.4 (CVSS 3.1) / 9.3 (4.0); Vearch 8.8; GoatCounter 8.3; Easy!Appointments 8.2; Rill 8.1; LlamaFarm 7.6; OpenAgents 7.5; MCP Kotlin SDK 7.5 (CVSS 3.1, VulnCheck)
Exploited in Australia?
unknown
Patch to
No fixed releases are listed. Agnai self-hosters: change the admin password and JWT secret from the compose defaults now, then sign out all sessions. Easy!Appointments: apply main-branch commit 09c6fb3 or keep booking pages behind access control until a release ships. Vearch, GoatCounter, Rill: limit accounts to trusted users and watch for role or token changes. LlamaFarm, OpenAgents, pinclaw: bind to localhost or firewall the ports, and rotate any stored model-provider API keys. Run mistral.rs code execution only on trusted input, and put MCP Kotlin SDK WebSocket servers behind a proxy that caps frame size

Primary: CVE.org — CVE-2026-108753 Agnai through 1.0.555 hard-coded credentials in self-host Docker Compose (VulnCheck CNA, published 11 Oct 2026) · Vendor: VulnCheck advisory — Agnai through 1.0.555 hard-coded credentials in self-host Docker Compose · CVE: CVE-2026-108710, CVE-2026-108760, CVE-2026-108753, CVE-2026-108746, CVE-2026-108758, CVE-2026-108740, CVE-2026-108718, CVE-2026-108739, CVE-2026-108714, CVE-2026-108759, CVE-2026-108757 · VulnCheck advisory — Vearch 3.5.2 to 3.5.9 incorrect authorization (CVE-2026-108746); wire: cve.report 11 Oct

tech ai