Security: oraios/serena
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Server-Side Template Injection (SSTI) in mode/context prompt rendering → RCE on project activation, bypassing `trusted_project_path_patterns`GHSA-pp25-4cg4-qcr9 published
Aug 9, 2026 by MischaPanchCritical -
Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCEGHSA-37h2-6p4f-mp3q published
Jul 1, 2026 by MischaPanchHigh
Learn more about advisories related to oraios/serena in the GitHub Advisory Database