Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <5b46a9bc-2c3c-4e66-9602-3c7e3dfc8900@oracle.com>
Date: Sun, 19 Apr 2026 08:42:57 -0700
From: Alan Coopersmith <alan.coopersmith@...cle.com>
To: oss-security@...ts.openwall.com, Pico 🧬 <pico@...al.dev>
Subject: Re: [CVE REQUEST] terminal-controller-mcp: trivially
 bypassable command blocklist enables unrestricted RCE (CVSS 10.0)

On 4/19/26 06:06, Pico 🧬 wrote:
> I'm posting to seek CVE assignment and to alert users.

oss-security has not been used for CVE assignment requests since 2017:
https://www.openwall.com/lists/oss-security/2017/02/09/7

To request a CVE be assigned for open source software that's not covered
by a specific CNA you can submit a request to either MITRE or the Red Hat
open source CNA:

  - https://www.cve.org/ReportRequest/ReportRequestForNonCNAs
  - https://access.redhat.com/articles/red_hat_cve_program

(Though I've just noticed that the web page at
  https://oss-security.openwall.org/wiki/disclosure/cve is out of date and
  still tells people to mail here.  That should get fixed.)

-- 
         -Alan Coopersmith-                 alan.coopersmith@...cle.com
          Oracle Solaris Engineering - https://blogs.oracle.com/solaris

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.