Lfprojects Vulnerabilities
Comprehensive security vulnerability database for Lfprojects products
5
0
3
0
Severity Distribution
| Description | Vendor / Product | Exploit Status | |||
|---|---|---|---|---|---|
| CVE-2026-27623 | 7.5 | An attacker with network access to the Valkey database can send a specially crafted request that causes the system to crash, disrupting service. This vulnerability affects versions 9.0.0 to 9.0.2, so it's crucial to upgrade to version 9.0.3 or ensure that only trusted users can access the system. | lfprojectsvalkey | Theoretical | about 1 month agoFeb 23, 2026 |
| CVE-2026-21863 | 7.5 | An attacker with access to the Valkey database's clusterbus port can send a specially crafted packet that may crash the system, disrupting service. To exploit this vulnerability, the attacker must already have access to the clusterbus, so it's crucial to restrict access with proper network controls. | lfprojectsvalkey | Theoretical | about 1 month agoFeb 23, 2026 |
| CVE-2025-67733 | 7.1 | This vulnerability allows a malicious user to inject harmful data into the responses sent to clients, which can corrupt or alter the information other users receive on the same connection. It affects specific versions of the Valkey database, and the issue arises from improper handling of errors in scripting commands. | lfprojectsvalkey | Exploit Available | about 1 month agoFeb 23, 2026 |
| CVE-2025-66416 | 7.6 | An attacker can exploit a flaw in the MCP Python SDK to send unauthorized requests to a local server running without authentication, potentially accessing sensitive resources or executing commands on behalf of the user. This vulnerability occurs only if the server is set up on localhost without proper security measures, making it critical to avoid running such servers without authentication. | lfprojectsmcp python sdk | Exploit Available | 4 months agoDec 2, 2025 |
| CVE-2025-66414 | 7.6 | An attacker can exploit this vulnerability to send unauthorized requests to a local MCP server running on a user's machine, potentially accessing sensitive resources or tools. This can happen if the server is running without authentication on localhost and does not have DNS rebinding protection enabled, which is a risky setup that should be avoided. | lfprojectsmcp typescript sdk | Exploit Available | 4 months agoDec 2, 2025 |
About Lfprojects Security
This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Lfprojects products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.
Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.