
CVE-2026-32722
Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata
educationpapers-researchpenetration-testing+3
1

Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

Fix prototype pollution vulnerability (CVE-2023-26136) for tough-cookie package