Summary
The CVE-backed portion covers rsync hostname ACL bypass, AutoGPT session hijacking, Keycloak authorization failure, OpenClaw cross-origin WebSocket hijacking, Avahi denial of service, and local-file-inclusion flaws in E2nest and Fonoster.
ZeroPath also publicly uses CVE-2024-48946 for Monaco. Its Wall of Fame and
zero-day archive associate the ID with pickle-deserialization RCE, while its
“How ZeroPath Works” article associates the same reserved ID with unauthorized
Redis access. No published CVE record currently resolves that conflict. The
Monaco report remains documented here as reserved context but is deliberately
absent from the cveId field and the global unique-CVE total.
Attribution boundary
The seven counted vulnerabilities have independent public records. The statement that ZeroPath’s AI-native workflow discovered them comes from ZeroPath, so the cluster is labeled self-reported. The reserved Monaco claim is not treated as independently corroborated. Direct Linux credits are kept in a separate two-CVE kernel entry.
References
- ZeroPath Wall of Fame
- ZeroPath: AutoGPT session hijacking
- AutoGPT advisory GHSA-q58p-v9r9-7gqj
- CVE record: CVE-2026-43617
- CVE record: CVE-2026-28458
- Reserved CVE record: CVE-2024-48946
- ZeroPath: How ZeroPath Works
- ZeroPath zero-day archive
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.