HIGH8.3PyPI
GHSA-37h2-6p4f-mp3q· CVE-2026-49471, PYSEC-2026-3061Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
Modified: 7/13/2026
package
pkg:pypi/serena-agent
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
Modified: 7/13/2026
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
Modified: 7/13/2026