What happened
NVD published CVE-2026-57443 on 2026-09-25; fixed by commit ca833795. A niche single-author AI-governance/evaluation framework with an unauthenticated API operation.
Why it matters
Low-blast-radius but AI-relevant: an AI evaluation/governance server whose API surface is reachable unauthenticated. Sites running the AetherBrowser component should upgrade and confirm no internet exposure of the API.
Attack vector
POST /api/ops/check-email is exposed with no authentication in scripts/aetherbrowser/api_server.py, allowing any remote attacker to invoke the operation without credentials.
Mitigation
Update to 4.2.1+ (commit ca833795e01eab060e92572e5f667c0c136b8c1e) and restrict access to the API server.