Vulnerability  ·  2026-09-27

SCBE-AETHERMOORE AI governance framework: unauthenticated check-email API endpoint (CVE-2026-57443)

VulnerabilityMedium impactGlobalCVE-2026-57443
NVD published CVE-2026-57443 on 2026-09-25; fixed by commit ca833795. A niche single-author AI-governance/evaluation framework with an unauthenticated API operation.
Low-blast-radius but AI-relevant: an AI evaluation/governance server whose API surface is reachable unauthenticated. Sites running the AetherBrowser component should upgrade and confirm no internet exposure of the API.
POST /api/ops/check-email is exposed with no authentication in scripts/aetherbrowser/api_server.py, allowing any remote attacker to invoke the operation without credentials.
Update to 4.2.1+ (commit ca833795e01eab060e92572e5f667c0c136b8c1e) and restrict access to the API server.
NVD - CVE-2026-57443
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →