OpenBMB records
5 published records for vendor openbmb.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-265 Privilege Issues1
- CWE-285 Improper Authorization1
- CWE-287 Improper Authentication1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2024-2007No exploit | OpenBMB XAgent Privileged Mode sandboxopenbmb · xagent · CWE-265 | High8.8 | — | 0.3% | Mar 20, 2024 |
22Monitor | CVE-2026-4959No exploit | OpenBMB XAgent ShareServer WebSocket Endpoint share.py check_user missing authenticationopenbmb · xagent · CWE-287 | Medium5.5 | — | 0.8% | Mar 27, 2026 |
8Monitor | CVE-2025-6281No exploit | OpenBMB XAgent community path traversalopenbmb · xagent · CWE-22 | Low2.0 | — | 0.5% | Jun 19, 2025 |
8Monitor | CVE-2026-4957No exploit | OpenBMB XAgent API Key function_handler.py FunctionHandler.handle_tool_call log fileopenbmb · xagent · CWE-200 | Low2.0 | — | 0.5% | Mar 27, 2026 |
5Monitor | CVE-2026-4958No exploit | OpenBMB XAgent WebSocket Endpoint replayer.py ReplayServer.send_data authorizationopenbmb · xagent · CWE-285 | Low1.3 | — | 0.5% | Mar 27, 2026 |
- CVE-2024-200735Monitor
OpenBMB XAgent Privileged Mode sandbox
HighCVSS 8.8No exploitEPSS 0%openbmb · xagentMar 20, 2024
- CVE-2026-495922Monitor
OpenBMB XAgent ShareServer WebSocket Endpoint share.py check_user missing authentication
MediumCVSS 5.5No exploitEPSS 1%openbmb · xagentMar 27, 2026
- CVE-2025-62818Monitor
OpenBMB XAgent community path traversal
LowCVSS 2.0No exploitEPSS 1%openbmb · xagentJun 19, 2025
- CVE-2026-49578Monitor
OpenBMB XAgent API Key function_handler.py FunctionHandler.handle_tool_call log file
LowCVSS 2.0No exploitEPSS 0%openbmb · xagentMar 27, 2026
- CVE-2026-49585Monitor
OpenBMB XAgent WebSocket Endpoint replayer.py ReplayServer.send_data authorization
LowCVSS 1.3No exploitEPSS 1%openbmb · xagentMar 27, 2026