WhisperX tag archive

#CWE-287

This page collects WhisperX intelligence signals tagged #CWE-287. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (3)

The Lab · 2026-03-29 14:27:01 · GitHub Issues

1. Tailscale macOS XPC Service 'Downloader' Exposed: Missing Client Validation Allows Local App Access

A critical security flaw has been identified in the Tailscale macOS application, exposing an internal XPC service to any local program. The service, named "Downloader," lacks the mandatory `SMAuthorizedClients` validation, effectively removing the authentication barrier. This omission allows any application running on ...

The Lab · 2026-05-12 01:18:24 · Mastodon:mastodon.social:#infosec

2. Critical Hardcoded JWT Secret Exposes socfortress CoPilot to Full Admin Takeover via CVE-2026-42869

A critical authentication vulnerability has been identified in socfortress CoPilot, affecting all versions prior to 0.1.57. The flaw, tracked as CVE-2026-42869 and classified under CWE-287 (Improper Authentication), stems from a hardcoded JWT secret embedded within the software. This weakness allows remote attackers to...

The Lab · 2026-05-13 01:18:22 · Mastodon:mastodon.social:#infosec

3. CRITICAL CVE-2026-44547: Authentication Bypass Vulnerability in ChurchCRM Allows Low-Privilege Attackers to Compromise Data (CVSS 9.6)

A critical improper authentication vulnerability has been identified in ChurchCRM, an open-source church management software platform. Tracked as CVE-2026-44547 and classified as CWE-287, the flaw carries a CVSS score of 9.6, placing it in the critical severity range. The vulnerability affects versions 7.2.0 through 7....