Skip to content
Threat Feed

July 2026 (30)

high advisory

Incomplete Package Integrity Verification in Chainguard apko and melange Allows Data Section Substitution

A critical vulnerability, CVE-2026-54174, in Chainguard's apko and melange packages allows attackers to substitute arbitrary file contents within packages due to incomplete integrity verification, potentially leading to remote code execution.

apko +1 supply-chain package-manager integrity-bypass remote-code-execution defense-evasion
2t
critical advisory

TSDProxy Internal Authentication Token Vulnerability Leading to Management API Escalation

A critical vulnerability in TSDProxy allows its internal per-process authentication token to be unconditionally forwarded to proxied backend services when `identityHeaders` is enabled, enabling an attacker with code execution on a co-located backend to replay the token to the local TSDProxy management API (port 8080) and bypass authentication, leading to full management API control.

tsdproxy < 1.4.4-0.20260603142855-434819b4421e vulnerability privilege-escalation authentication-bypass tsdproxy go
1r 4t 1i
critical advisory

miniOrange WordPress Plugin Authentication Bypass via OTP Weakness

An authentication bypass vulnerability (CVE-2026-12761) in the miniOrange Social Login and Register WordPress plugin, affecting versions up to 7.7.0, allows unauthenticated attackers to trigger an OTP email to an arbitrary admin's address, offline crack the weak OTP from a leaked hash, and gain full administrator access by logging in as the target user.

miniOrange Social Login and Register web authentication-bypass wordpress cve account-takeover plugin
4t 1c
high advisory

Clauster Dashboard Unauthenticated Access Vulnerability

A Clauster instance deployed on a non-loopback address can be accessed unauthenticated, even if password protection is configured, due to auth.enabled defaulting to false. This allows an attacker with network access to gain full control of the dashboard, including listing projects, spawning remote-control bridges, editing files, reading logs, and cloning repositories, ultimately leading to remote code execution in project directories.

Clauster misconfiguration remote-code-execution vulnerability web-application
2t 1i
critical advisory

Unauthenticated PHP Object Injection in PrestaShop ps_facetedsearch Leads to RCE

An unauthenticated PHP Object Injection vulnerability, tracked as CVE-2026-54159, affects the PrestaShop ps_facetedsearch module versions 3.0.0 through 4.0.3, allowing attackers to craft malicious serialized PHP objects in URL parameters that, upon deserialization, result in arbitrary file writes and remote code execution on the server.

ps_facetedsearch php-object-injection rce webshell prestashop cve web-exploitation
1r 3t
high advisory

RustDesk Authorization Bypass via Session Scope Enforcement Failure (CVE-2026-57850)

An authorization vulnerability exists in RustDesk before version 1.4.9 where the server-side fails to properly enforce connection scope for authenticated peers, allowing an attacker, having been granted a limited session type, to inject control messages typically reserved for a full Remote session and gain unauthorized observation and control over the host.

RustDesk < 1.4.9 vulnerability authorization-bypass remote-access
1t 1c
high advisory

SafeInstall CLI Guard Bypass Vulnerability Allows Unauthorized Package Execution

A vulnerability in SafeInstall CLI through version 0.10.1 allows attackers to bypass its agent guard and execute unauthorized package installation or registry-provided scaffolding commands, potentially compromising developer environments.

safeinstall-cli vulnerability supply-chain developer-tools defense-evasion
2t
high advisory

SiYuan Stored XSS via Malicious Bazaar Package README

A stored Cross-Site Scripting (XSS) vulnerability, CVE-2026-54070, affects SiYuan versions up to 3.6.5, allowing a malicious third-party package author to embed JavaScript in package READMEs via an incomplete HTML sanitizer's blocklist, which executes in an Administrator's authenticated browser session upon viewing and interacting with the crafted README in the Bazaar marketplace, leading to API token theft and potential full workspace control.

siyuan-note/siyuan +2 xss web-vulnerability code-execution credential-theft si-yuan
5t 1c
critical advisory

BabelDOC Arbitrary Code Execution via CMap Pickle Deserialization

An arbitrary code execution vulnerability exists in BabelDOC's vendored PDF parser (`babeldoc/pdfminer/cmapdb.py`) due to insecure deserialization of untrusted pickle data, allowing an attacker to craft a PDF with a specially encoded '/Encoding' name containing an absolute path that bypasses directory restrictions, leading to deserialization and execution of a malicious '.pickle.gz' file on the local filesystem with the privileges of the BabelDOC process.

BabelDOC <= 0.6.2 code-execution deserialization pdf python path-traversal python linux windows
2t
high advisory

NotrinosERP Authenticated Arbitrary File Upload Leads to Remote Code Execution

An authenticated user with the 'SA_EMPLOYEE' permission in NotrinosERP can upload arbitrary files, including PHP web shells, through the HRM employee 'Documents' tab, leading to remote code execution due to a lack of extension, MIME, or content validation.

NotrinosERP web-application remote-code-execution file-upload php notrinos
1r 3t
critical advisory

SiYuan Unauthenticated Admin API Access via Chrome Extension Allowlist

A critical vulnerability (CVE-2026-54069) in SiYuan Note kernel's HTTP server allows any Chrome/Chromium browser extension to gain unauthenticated RoleAdministrator access, enabling data exfiltration, stored XSS injection, and configuration tampering for SiYuan desktop users, including via compromised legitimate extensions.

SiYuan Note +1 web-vulnerability privilege-escalation data-exfiltration xss supply-chain desktop-application chrome-extension siyuan
1r 6t 1c 1i
high advisory

FileBrowser Authentication Bypass via Forged Proxy Authentication Header

An unauthenticated attacker can impersonate any user, including administrators, or automatically create new user accounts in FileBrowser by forging the `X-Remote-User` HTTP header when the server is configured for proxy authentication and is directly reachable, leading to full administrative control and unauthorized access to data.

FileBrowser authentication-bypass web-vulnerability privilege-escalation file-browser account-creation
1r 3t
critical threat

Malicious 'exploration' Rust Crate Downloads and Executes Remote Payload

A malicious Rust crate named 'exploration' was published to crates.io on 2026-06-02, containing a method that attempted to download and execute a payload from a remote site, and was removed within an hour with no evidence of actual usage.

exploited exploration supply-chain rust malicious-package remote-code-execution cwe-506
2t
critical advisory

File Browser Pre-Authentication Command Injection via Authentication Hook (CVE-2026-54088)

The Hook Authentication feature in File Browser (versions up to 2.63.5) is vulnerable to a pre-authentication command injection flaw (CVE-2026-54088), allowing an unauthenticated remote attacker to execute arbitrary OS commands by injecting shell metacharacters into login fields during `os.Expand` operations, leading to critical Remote Code Execution (RCE) without valid credentials.

File Browser command-injection rce web-application
1r 2t 1c
critical advisory

CVE-2026-5801 - SQL Injection Leading to Command Line Execution in Semtek SEM-PMP

An SQL injection vulnerability, tracked as CVE-2026-5801, has been identified in Semtek Informatics Software Consulting Trade Ltd. Co. SEM-PMP versions through 23042026, allowing unauthenticated attackers to achieve command line execution on the underlying system with a critical CVSS v3.1 score of 9.8.

SEM-PMP sql-injection rce vulnerability web-application
1r 2t 1c 1i
high advisory

SiYuan Path Traversal Vulnerability (CVE-2026-54066) via Double URL Encoding

An incomplete fix for CVE-2026-41894 in SiYuan's 'publish mode' allows unauthenticated remote attackers to perform path traversal by double URL-encoding '..' segments in requests to the '/assets/*path' route, leading to the read of arbitrary files within the 'WorkspaceDir'.

siyuan kernel path-traversal vulnerability web-vulnerability arbitrary-file-read
1r 3t 2c 1i
medium advisory

Excelize Unbounded Row Index Allocation Denial-of-Service Vulnerability

An unbounded row index allocation vulnerability (CWE-770) exists in the `checkSheet()` function of the `github.com/xuri/excelize/v2` library, allowing an unauthenticated attacker to craft a malicious XLSX file with a specially crafted row index value that triggers an out-of-memory error or runtime panic, leading to a denial-of-service condition in Go applications processing untrusted spreadsheets.

excelize v2 vulnerability denial-of-service golang xlsx library cwe-770
1t
critical advisory

Authorizer Unvalidated Redirect Vulnerability Allows OAuth2 Token Theft

An unvalidated redirect vulnerability, CVE-2026-54072, in the Authorizer `/authorize` endpoint allows an unauthenticated attacker to steal OAuth2 access, ID, and refresh tokens by crafting a malicious URL with an attacker-controlled `redirect_uri` to which the application redirects a logged-in user, exposing their tokens.

authorizer oauth vulnerability redirect token-theft web ghsa
1r 2t 1i
high advisory

Authorization Bypass Vulnerability in Teracity TeraMIS (CVE-2026-6212)

A critical authorization bypass vulnerability (CVE-2026-6212) in Teracity Software Technologies Inc. TeraMIS, affecting versions V03.26.01.14 through 30.04.2026, allows an attacker to achieve Privilege Abuse by manipulating user-controlled keys.

TeraMIS authorization-bypass privilege-escalation vulnerability
1t 1c
high advisory

Dify MyScale Backend SQL Injection Vulnerability (CVE-2026-61461)

A high-severity SQL injection vulnerability, CVE-2026-61461, exists in the MyScale vector store backend of Dify versions prior to 1.16.0-rc1, allowing attackers with low privileges to execute arbitrary SQL commands via unsanitized search parameters, leading to unauthorized data manipulation in the underlying ClickHouse database.

Dify sql-injection web-vulnerability clickhouse
1r 4t 1c
high advisory

Krayin CRM Insecure Direct Object Reference Vulnerability (CVE-2026-61460)

An Insecure Direct Object Reference (IDOR) vulnerability, CVE-2026-61460, in Krayin CRM through version 2.2.3 allows authenticated users to modify, update, or delete records owned by other users by exploiting missing record-level ownership validation in various controllers, leading to unauthorized data manipulation.

Krayin CRM +1 idor crm web-application vulnerability
3t 1c
high advisory

HestiaCP Authenticated OS Command Injection via DNS Record Types (CVE-2025-30007)

An authenticated OS command injection vulnerability, CVE-2025-30007, in HestiaCP before version 1.9.5 allows low-privilege users to execute arbitrary commands as root by injecting a single-quote character into unvalidated DNS record types, leading to full root code execution on the underlying host.

HestiaCP < 1.9.5 vulnerability command-injection privilege-escalation linux hestiacp
2t 1c
critical advisory

CVE-2026-61459 - Argument Injection in MCP Server Kubernetes Structured Tools Leads to Cluster Compromise

An argument injection vulnerability, CVE-2026-61459, in MCP Server Kubernetes versions prior to 3.9.0 within structured tools like kubectl_get, kubectl_describe, and kubectl_delete allows attackers to bypass the assertNoDangerousFlags security check by injecting parameters with leading dashes to redirect kubectl commands to an attacker-controlled API server, enabling the exfiltration of the operator's bearer token and leading to full Kubernetes cluster compromise.

Kubernetes < 3.9.0 kubernetes cloud argument-injection vulnerability cve
4t 1c
critical advisory

Critical SQL Injection Vulnerability in Adam Retail Automation MobilMen 20T

A critical SQL injection vulnerability, tracked as CVE-2026-2397 with a CVSS v3.1 score of 9.8, affects Adam Retail Automation Ltd.'s MobilMen 20T software, allowing remote attackers to execute arbitrary SQL commands due to improper neutralization of special elements in input, potentially leading to unauthorized data access or system compromise.

MobilMen 20T sql-injection vulnerability cve data-exfiltration
2t 1c
high advisory

Simple Machines Forum Authorization Bypass Vulnerability

An authorization bypass vulnerability, CVE-2026-39903, exists in Simple Machines Forum versions 2.1 prior to 2.1.8 and 3.0 prior to 3.0 Alpha 5, allowing a low-privileged, authenticated user to exploit a single-character operator error in 'Sources/Actions/AttachmentApprove.php' to bypass permission checks, enabling them to approve, reject, or delete any pending attachments across boards, circumvent moderation queues for their own uploads, and enumerate or delete other users' pending attachments without the required 'approve_posts' permission.

Simple Machines Forum 2.1 +1 authorization-bypass web-application cve
1t 1c
high advisory

CVE-2026-2398: Authorization Bypass Leads to Privilege Escalation in Adam Retail Automation MobilMen 20T

An authorization bypass vulnerability, identified as CVE-2026-2398, exists in Adam Retail Automation Ltd.'s MobilMen 20T software, affecting versions from v3 through 10072026, allowing an attacker to achieve privilege escalation by manipulating user-controlled keys.

MobilMen 20T authorization-bypass privilege-escalation vulnerability CVE
1t 1c
high advisory

Arbitrary Post Creation and Stored XSS in Squirrly SEO Plugin for WordPress

An arbitrary post creation and stored cross-site scripting (XSS) vulnerability exists in The SEO Plugin by Squirrly SEO for WordPress, affecting versions up to and including 14.0.0. This flaw, caused by an API token leak and insufficient input sanitization/output escaping, allows unauthenticated attackers to create arbitrary posts. If the Advanced Custom Fields plugin is also installed, attackers can inject arbitrary web scripts into pages that execute when a user accesses an injected page, leading to potential client-side compromise.

The SEO Plugin by Squirrly SEO +1 wordpress plugin-vulnerability xss arbitrary-post-creation
1r 3t 1c
critical threat

CVE-2026-56291: Balbooa Forms Unrestricted File Upload Vulnerability Leading to RCE

A critical unrestricted file upload vulnerability, CVE-2026-56291, in Balbooa Forms allows an unauthenticated attacker to upload executable files, potentially leading to arbitrary code execution on the server.

exploited Forms vulnerability web-vulnerability rce file-upload cisa-kev
1r 2t 1c
critical advisory

Arbitrary XML Schema Definition Processing in guardrails-detectors Leads to SSRF and Local File Read

A flaw in the 'file_type' content detector of 'guardrails-detectors' allows a remote attacker to provide an arbitrary XML Schema Definition (XSD) string, leading to server-side request forgery (SSRF) and local file reads, potentially exposing sensitive information such as cloud provider credentials or granting access to internal network services.

guardrails-detectors vulnerability ssrf local-file-read info-disclosure guardrails
3t 1c
medium advisory

CPU DoS Vulnerability in libp2p gossipsub

A critical vulnerability in the `@libp2p/gossipsub` library allows an unauthenticated attacker to cause a CPU-based Denial of Service by sending oversized IHAVE and IWANT control messages, which are synchronously processed, leading to Node.js event loop exhaustion and service disruption.

@libp2p/gossipsub denial-of-service cpu-exhaustion javascript nodejs library-vulnerability
1t