Skip to content
Threat Feed

Tag

Injection

79 briefs RSS
medium advisory

Multiple Cross-Site Scripting Vulnerabilities in jQuery

Multiple vulnerabilities in the jQuery library allow remote, anonymous attackers to conduct Cross-Site Scripting (XSS) attacks by injecting malicious scripts into victim browser sessions.

jQuery web-security xss injection
1t
critical threat

SQL Injection in Hongjing e-HR /servlet/codesettree

Hongjing e-HR versions prior to 8.2 are vulnerable to unauthenticated SQL injection via the categories parameter in the /servlet/codesettree endpoint, allowing remote attackers to extract sensitive database content.

exploited e-HR web-application injection vurnerability
1r 1t 1c
critical advisory

Eval Injection in XWiki Rendering XML

An evaluation injection vulnerability in xwiki-rendering-xml allows authenticated users to achieve remote code execution by injecting script macros into HTML macro output.

xwiki-rendering-xml injection rce web-vulnerability
2t 1c
critical advisory

Remote Code Execution in jsonpath-plus via CVE-2025-1302

CVE-2025-1302 is a critical remote code execution vulnerability in the jsonpath-plus library, exploitable via malicious JSONPath expressions injected through query parameters.

jsonpath-plus remote-code-execution injection web-application library-vulnerability
1r 2t 1c
critical advisory

Protocol Desynchronization and Frame Injection in RabbitMQ amqp091-go

A critical integer overflow vulnerability in the amqp091-go parser causes protocol desynchronization, allowing remote attackers to inject arbitrary AMQP frames into the network stream.

amqp091-go data-integrity serialization-vulnerability protocol-corruption denial-of-service memory-exhaustion amqp vulnerability credential-exposure +2
5t 1c
high advisory

Authorization Bypass in SigNoz Trace-Funnel Analytics

SigNoz versions 0.88.0 through 0.141.0 contain an authorization bypass vulnerability allowing unauthenticated remote attackers to query sensitive trace analytics via the trace-funnel endpoint.

SigNoz +2 authorization-bypass api-security observability sql-injection vulnerability web-application webserver injection
2r 1t 1c updated
critical advisory

Multi-tenant Isolation Bypass in djust via WebSocket/SSE

A vulnerability in djust caused multi-tenant isolation to fail open on WebSocket and SSE paths, allowing unauthorized cross-tenant data disclosure due to improper tenant context propagation.

djust +1 web-application mass-assignment cve-2026-61598 remote-code-execution information-disclosure cve-2026-61590 idor broken-access-control +5
6t 1c updated
high advisory

Stored XSS in Amundsen Frontend

Amundsen frontend versions through 4.3.0 allow Stored Cross-Site Scripting via unsanitized rendering of metadata descriptions, enabling arbitrary JavaScript execution in victim browsers.

Amundsen frontend web-security xss injection
2t 1c
high advisory

MoguBlog XML External Entity Injection in WeChat Callback

MoguBlog versions through 6.2 are vulnerable to unauthenticated XML External Entity (XXE) injection via the WeChat callback handler, allowing arbitrary file read and outbound SSRF.

MoguBlog web-vulnerability xxe injection
1r 2t 1c
medium advisory

XXE Vulnerability in IBM webMethods Integration Server

IBM webMethods Integration Server 11.1 is vulnerable to an XML External Entity (XXE) injection flaw that allows unauthenticated attackers to exfiltrate sensitive files or trigger denial of service via memory exhaustion.

webMethods Integration Server web-vulnerability xxe injection
1t 1c
high advisory

Attribute Injection in @xmldom/xmldom via Element.setAttribute

The @xmldom/xmldom library fails to validate attribute names during the use of Element.setAttribute, allowing attackers to inject malicious attributes into serialized XML output leading to potential XSS.

@xmldom/xmldom +1 xss injection vulnerability web-application
1t 1c
high advisory

xmldom requireWellFormed Serialization Bypass

The xmldom serializer fails to properly validate element and attribute names when the requireWellFormed option is enabled, allowing attackers to inject arbitrary markup via line-terminated strings.

xmldom +3 injection xss library-vulnerability
2t 1c
high advisory

XML Injection Vulnerability in @xmldom/xmldom via Processing Instruction Targets

The @xmldom/xmldom library fails to validate the target parameter in createProcessingInstruction, enabling attackers to break out of XML processing instructions and inject arbitrary content when serializing with the requireWellFormed flag.

@xmldom/xmldom +2 injection xss xxe vulnerability
1t 1c
critical advisory

Remote Command Injection and DoS in Predis via CRLF Smuggling

Predis versions 3.0.0-RC1 through 3.2.0 are vulnerable to CRLF smuggling in pipeline operations on aggregate connections, enabling remote command injection on cluster configurations or denial-of-service on replication setups.

Predis redis injection php
1t 1c
high advisory

Cross-Site Scripting Vulnerability in AVideo YPTSocket Plugin

An unauthenticated XSS vulnerability in the AVideo YPTSocket plugin allows attackers to execute arbitrary JavaScript in victim browsers via crafted websocket callback messages.

AVideo +3 web-application xss injection web-security access-control pii-leak account-takeover authentication-bypass +1
9t 1c updated
critical advisory

Unauthenticated Hook Injection in The Post Grid and Gutenberg Blocks Plugin

The Post Grid and Gutenberg Blocks - ComboBlocks plugin for WordPress contains an unauthenticated hook injection vulnerability in versions 2.2.32 to 2.3.1 that allows remote attackers to execute arbitrary actions via hook functions.

The Post Grid and Gutenberg Blocks – ComboBlocks wordpress cve web-application injection
1t 1c
high advisory

Remote Code Execution in LaVague via Indirect Prompt Injection

LaVague version 0.2.35 contains a remote code execution vulnerability in the PythonFromMarkdownExtractor.extract_as_object function, allowing attackers to execute arbitrary code via indirect prompt injection.

LaVague remote-code-execution injection ai-security supply-chain
1t 1c
high advisory

Unauthenticated SSRF in Openpanel Site Checker

Openpanel versions before 2.3.0 are vulnerable to an unauthenticated server-side request forgery (SSRF) flaw in the /tools/site-checker endpoint that allows internal network probing and cloud metadata access.

Openpanel +2 web-vulnerability ssrf reconnaissance remote-code-execution injection privilege-escalation web-application cve-2026-88891 +3
1r 8t 1c updated
high advisory

Unauthenticated Remote Code Execution in Claude Code Studio

An unauthenticated OS command injection vulnerability in the Claude Code Studio HTTP server allows remote attackers to execute arbitrary code via drive-by web requests or local network access.

claude-code-templates remote-code-execution injection express nodejs
1r 2t 1c
high advisory

SQL Injection in Doctor Appointment System 1.0

An SQL injection vulnerability in the email parameter of the patient_login.php file allows unauthenticated remote attackers to execute arbitrary SQL commands in Doctor Appointment System 1.0.

Doctor Appointment System web-vulnerability sqli vulnerability-management injection cve-2026-85403
2r 1t 1c
high advisory

CVE-2026-85388 SQL Injection in Worklenz

Authenticated attackers can exploit improper validation of the sort-field parameter in Worklenz <= 3.0.0 to perform blind SQL injection against PostgreSQL backends.

Worklenz sqli web-vulnerability injection
1t 2c
medium advisory

CVE-2026-66362: Injection Vulnerability in NGINX Gateway Fabric

An injection vulnerability in the NGINX Gateway Fabric configuration generator allows authenticated users to inject arbitrary NGINX directives into the configuration when using NGINX Plus as the data plane.

NGINX Gateway Fabric vulnerability kubernetes ingress injection
1t 1c
high advisory

Stored XSS Vulnerability in Bludit CMS

Bludit CMS version 3.22.0 contains a stored XSS vulnerability in its SVG upload process, allowing attackers to execute arbitrary JavaScript via malicious XML processing instructions.

Bludit CMS +1 webapps xss injection
2r 4t updated
high threat

SQL Injection in CubeCart 6.7.4

An authenticated SQL injection vulnerability in CubeCart 6.7.4 allows administrative users to execute arbitrary SQL commands due to improper sanitization of the download_expire parameter.

exploited CubeCart +1 webapps sqli cube-cart xss injection cve-2026-54644
2r 3t
medium advisory

Multiple Vulnerabilities in MariaDB Connectors

Multiple vulnerabilities in MariaDB Connector libraries enable remote, unauthenticated attackers to perform SQL injection, bypass security controls, and manipulate sensitive database content.

MariaDB Connectors vulnerability database injection
1t 3c
critical advisory

WWBN AVideo SSRF Filter Bypass via NAT64 Hex Encoding

WWBN AVideo is vulnerable to a Server-Side Request Forgery (SSRF) bypass in the isSSRFSafeURL function due to improper normalization of hex-encoded NAT64 addresses.

AVideo +7 credential-access web-application authentication-bypass web-application-vulnerability path-traversal reconnaissance web-vulnerability csrf +13
7r 15t 1c updated
critical advisory

Remote Code Execution in IBM Langflow OSS via A2A Endpoint

IBM Langflow OSS versions 1.0.0 through 1.11.1 contain an unauthenticated remote code execution vulnerability in the A2A public endpoint.

Langflow OSS +4 remote-code-execution vulnerability webserver web-application security-scanner-bypass cve-2026-76059 rce cloud-security +2
1r 8t 1c updated
high advisory

Log Injection Vulnerability in @logtape/syslog

The @logtape/syslog library is vulnerable to syslog injection via unescaped control characters and unvalidated structured data keys, allowing attackers to forge log records in downstream systems.

@logtape/syslog injection cve-2026-54511
1c
critical advisory

Unauthenticated Remote Code Execution in senaite.core

An unauthenticated remote code execution vulnerability in senaite.core allows attackers to execute arbitrary Python code via a two-request chain leveraging missing authorization and unsafe eval() usage in the JSON API.

senaite.core remote-code-execution injection web-application senaite
1r 1t
high advisory

Cross-Site Scripting Vulnerability in Plate Media Embed Renderer

A vulnerability in the Plate @platejs/media package allows attackers to bypass URL sanitization and achieve Cross-Site Scripting (XSS) by embedding malicious JavaScript URIs in media documents (CVE-2026-55596).

@platejs/media xss injection web-application cve-2026-55596
1t 1c
critical advisory

Remote Code Execution in qwed-mcp via Unsafe SymPy Input

The qwed-mcp library v0.2.0 is vulnerable to arbitrary remote code execution because it passes unsanitized input to SymPy's parse_expr function, allowing attackers to execute arbitrary system commands via Python code injection.

qwed-mcp remote-code-execution python injection supply-chain
1r 1t
critical advisory

Multiple Sanitization Bypass Vulnerabilities in justhtml Library

The justhtml library before version 1.15.0 contains multiple vulnerabilities in URL sanitization, HTML serialization, and Markdown passthrough that allow attackers to inject malicious HTML and JavaScript.

justhtml +2 xss injection library-vulnerability
3t 1c
high advisory

Remote Code Injection in chenhg5 cc-connect

An unauthenticated remote code injection vulnerability in the Authenticate function of chenhg5 cc-connect (up to 1.4.1) allows attackers to execute arbitrary code via the exec parameter.

cc-connect vulnerability remote-code-execution injection web-application
1r 2t 1c
high advisory

Command Injection in Cockpit CMS FFmpeg Integration

Cockpit CMS versions 2.14.0 and prior are vulnerable to authenticated command injection via malicious filenames processed by the FFmpeg integration.

Cockpit CMS web-application-vulnerability remote-code-execution injection cockpit-cms
1r 1t 1c
high advisory

Privilege Escalation via IDOR in CamaleonCMS

CamaleonCMS versions 2.9.2 and earlier are vulnerable to privilege escalation via an IDOR parameter confusion flaw in the UsersController, allowing authenticated attackers to overwrite arbitrary user credentials.

CamaleonCMS web-application xss injection
1r 3t 1c updated
high advisory

Unauthenticated Arbitrary File Write in AVideo

An unauthenticated arbitrary file write vulnerability (CVE-2026-72748) in the AVideo aVideoEncoderChunk.json.php endpoint allows remote attackers to upload arbitrary content to the server, potentially leading to remote code execution.

AVideo web-vulnerability rce file-write cve-2026-72748 web-application xss injection
2r 3t 1c
high advisory

RovoBlast Parameter-to-Prompt Injection Vulnerability in Atlassian Rovo

A parameter-to-prompt (P2P) injection vulnerability in Atlassian Rovo allowed unauthorized attackers to seed malicious instructions into enterprise AI sessions to exfiltrate data from connected Jira, Confluence, and SharePoint environments.

Rovo +4 ai-security data-exfiltration injection
2t
high advisory

GitPython Command Injection via Unsafe Git Option Guard Bypass

A bypass of the GitPython safety guard allows arbitrary OS command execution via token smuggling when using single-character keyword arguments with split_single_char_options=False.

GitPython +1 execution library-vulnerability command-injection remote-code-execution injection supply-chain
2t 1c updated
medium advisory

Cross-Site Scripting Vulnerability in jsoup Library

A vulnerability in the jsoup library allows a remote attacker to execute arbitrary scripts in the context of a user's browser via Cross-Site Scripting (XSS).

jsoup web-security xss injection
1t 1c updated
high advisory

SQL Injection in Shandong Hoteam PDM Product Data Management System

Shandong Hoteam PDM Product Data Management System versions 8.3.10 and earlier contain a SQL injection vulnerability in the GetStoredClassByFilter function that allows remote, unauthenticated attackers to execute arbitrary SQL commands.

PDM Product Data Management System injection sql-injection cve-2026-18854
1r 1t 1c
high advisory

OS Command Injection in Lenovo XClarity Orchestrator

Lenovo XClarity Orchestrator (LXCO) versions prior to 2.2.0 contain an OS command injection vulnerability (CVE-2026-16793) allowing authenticated attackers to execute arbitrary commands with high privileges.

XClarity Orchestrator cve rce injection enterprise-management
1t 1c
critical advisory

Flowise Unauthenticated RCE via Environment Variable Bypass

Flowise v3.1.2 and earlier are vulnerable to unauthenticated remote code execution because the CVE-2025-8943 patch relies on an incomplete environment variable blocklist, allowing attackers to inject configuration variables that force arbitrary package installation.

Flowise +6 rce injection cve-2026-69263 python-injection authentication-bypass oauth cve-2026-70478 web-vulnerability +7
6r 11t 8c 2i updated
high advisory

GitPython Argument Injection in IndexFile and TagReference

GitPython fails to sanitize keyword arguments passed to git commands, allowing attackers to perform arbitrary file overwrites and unauthorized file reads.

GitPython injection python supply-chain
1t
high advisory

Path Traversal and Query Injection in hashi-vault-js

The hashi-vault-js library is vulnerable to path traversal and query injection due to insufficient URI encoding, potentially allowing attackers to redirect administrative Vault requests if untrusted input is passed to the library.

hashi-vault-js web-application injection path-traversal npm cve-2026-55100
1c
critical advisory

Unauthenticated Remote Access to Phoenix Contact CHARX SEC MQTT Broker

A critical vulnerability (CVE-2026-44090) in Phoenix Contact CHARX SEC controllers allows unauthenticated remote attackers to gain full device control by bypassing authentication on the MQTT broker.

CHARX SEC-3150 +7 industrial-control-systems mqtt cve-2026-44091 ics cve injection authentication-bypass cve-2026-44100 +14
2r 5t 12c
high advisory

Public Exploit for Apache Camel CVE-2026-49098 Improper Input Validation

A public exploit has been released for CVE-2026-49098, an improper input validation vulnerability in Apache Camel's 'camel-kafka' component, which allows an attacker to perform message-header injection by supplying 'kafka.OVERRIDE_TOPIC' in HTTP headers, enabling cross-topic message injection and integrity compromise of sensitive Kafka topics.

Apache Camel +2 apache-camel vulnerability kafka injection
1t 1c
medium advisory

NGINX Ingress Controller Injection Vulnerability via CRDs/Annotations (CVE-2026-55723)

An injection vulnerability exists in the NGINX Ingress Controller when configured with Custom Resource Definitions (CRDs) or Ingress annotations. An authenticated attacker with write permissions to these CRDs or annotations via the Kubernetes API can craft values to inject arbitrary NGINX configuration directives. This can lead to creating or deleting files and disabling services, affecting the control plane without exposing the data plane.

NGINX Ingress Controller kubernetes vulnerability injection webserver cve
2t 1c
critical advisory

Wazuh Manager Vulnerability CVE-2026-56699 Allows NDJSON Injection

Wazuh Manager versions prior to 5.0.0-beta3 are critically vulnerable to an injection flaw, CVE-2026-56699 (CWE-74), enabling enrolled agents to inject arbitrary NDJSON operations into OpenSearch bulk requests, leading to data integrity compromise and defense evasion.

Wazuh Manager vulnerability injection SIEM Wazuh
2t 1c
high advisory

NousResearch hermes-agent <= 0.12.0 Code Injection Vulnerability (CVE-2026-10221)

NousResearch hermes-agent up to version 0.12.0 is vulnerable to code injection in the _compress_context function of the run_agent.py file, allowing remote exploitation.

hermes-agent injection code injection cve-2026-10221
2r 1t 1c
critical advisory

Amazon Redshift Python Driver Remote Code Execution via eval() Injection (CVE-2026-8838)

The amazon-redshift-python-driver versions 2.1.13 and earlier is vulnerable to remote code execution (CVE-2026-8838) due to insufficient validation of server data during query result processing, potentially allowing a rogue server or man-in-the-middle to execute arbitrary code on the client.

redshift-connector rce redshift python injection
2r 1t 1c 1i
high threat

code-projects Project Management System SQL Injection Vulnerability (CVE-2026-9584)

A SQL injection vulnerability (CVE-2026-9584) exists in code-projects Project Management System 1.0 within the chk.php file of the Login component, allowing a remote attacker to execute arbitrary SQL commands.

Project Management System 1.0 sql-injection cve-2026-9584 web-application injection
2r 1t 1c
medium advisory

CVE-2026-3603: IBM Engineering Lifecycle Management XXE Vulnerability

IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 are vulnerable to XML external entity injection (XXE), allowing an authenticated attacker to expose sensitive information or consume memory resources.

Engineering Lifecycle Management 7.0.3 +2 cve xxe injection
2r 1t 1c
high advisory

NousResearch hermes-agent Injection Vulnerability (CVE-2026-9366)

A remote injection vulnerability exists in NousResearch hermes-agent 2026.4.23 within the _scan_context_content function of the agent/prompt_builder.py file, allowing attackers to inject malicious code.

hermes-agent cve injection
2r 1t 1c
high threat

JoomSport WordPress Plugin Vulnerable to Time-Based Blind SQL Injection (CVE-2026-6929)

The JoomSport plugin for WordPress is vulnerable to time-based blind SQL Injection (CVE-2026-6929) via the 'sortf' parameter in versions up to 5.7.7, allowing unauthenticated attackers to extract sensitive information from the database.

JoomSport – for Sports: Team & League, Football, Hockey & more plugin <= 5.7.7 sqli wordpress cve-2026-6929 joomsport injection
2r 1t 1c
high advisory

claude-code-cache-fix Local Code Execution via Python Injection (CVE-2026-45136)

A vulnerability exists in claude-code-cache-fix versions 3.5.0 and 3.5.1 where the `tools/quota-statusline.sh` script interpolates Claude Code's hook stdin payload directly into a Python triple-quoted string literal, allowing local code execution via Python triple-quote injection (CVE-2026-45136).

claude-code-cache-fix code-execution injection linux
2r 1t
high advisory

CVE-2026-41109: Improper Neutralization of Special Elements in GitHub Copilot and Visual Studio

CVE-2026-41109 describes an improper neutralization of special elements in output used by a downstream component ('injection') vulnerability in GitHub Copilot and Visual Studio, allowing an unauthorized attacker to bypass a security feature over a network.

GitHub Copilot +1 injection cve github visual studio
2r 1t 1c
high advisory

CVE-2026-33833: Azure Machine Learning Spoofing Vulnerability

CVE-2026-33833 describes an injection vulnerability in Azure Machine Learning that allows an unauthorized attacker to perform spoofing over a network.

Azure Machine Learning injection spoofing cloud
2r 1t 1c
high threat

AIWU WordPress Plugin Vulnerable to SQL Injection (CVE-2026-2993)

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to SQL Injection (CVE-2026-2993) in versions up to 1.4.17, allowing unauthenticated attackers to extract sensitive information from the database.

AI Chatbot & Workflow Automation by AIWU plugin for WordPress cve sqli wordpress injection
2r 1t 1c
high advisory

Kysely JSON-path Injection Vulnerability

A JSON-path traversal injection vulnerability exists in Kysely versions prior to 0.28.16, allowing attackers to traverse JSON sub-fields outside the intended scope, potentially leading to unauthorized read and write access to sensitive data in MySQL, PostgreSQL, and SQLite databases due to insufficient sanitization of JSON-path metacharacters in the `JSONPathBuilder.key()` and `.at()` functions.

MySQL +3 jsonpath injection kysely cwe-89 cwe-915 cwe-1284
2r 1t 1c
high advisory

Vvveb CMS XML External Entity Injection Vulnerability

Vvveb before 1.0.8.2 is vulnerable to XML external entity (XXE) injection in the admin import feature, allowing authenticated site administrators to read arbitrary files and modify database records, potentially leading to privilege escalation.

Vvveb +1 xxe vulnerability injection
2r 3t 1c
critical advisory

YAFNET Unauthenticated Stored XSS via User-Agent Header

YAFNET is vulnerable to an unauthenticated stored second-order XSS vulnerability in the admin event log, triggered by a reflected `User-Agent` header, allowing an attacker to execute arbitrary JavaScript in an administrator's session.

YAFNET.Core xss web-application injection
2r 2t
high advisory

OpenClaw Shell Wrapper Detection Bypass via Environment Variable Injection

OpenClaw versions before 2026.4.12 are vulnerable to environment variable injection, allowing attackers to bypass shell wrapper detection and manipulate execution semantics by modifying shell variables.

OpenClaw cve vulnerability injection
2r 1t 1c
critical advisory

HKUDS OpenHarness Remote Code Execution via /bridge Slash Command (CVE-2026-7551)

HKUDS OpenHarness contains a remote code execution vulnerability (CVE-2026-7551) in the /bridge slash command, allowing remote attackers to execute arbitrary operating system commands by injecting malicious commands via the /bridge spawn command, leading to unauthorized shell access and data exposure.

OpenHarness rce vulnerability injection
2r 1t 1c
high advisory

Dagster SQL Injection Vulnerability in Dynamic Partition Keys

A SQL injection vulnerability exists in Dagster's DuckDB, Snowflake, BigQuery, and DeltaLake I/O managers, where a user with 'Add Dynamic Partitions' permission can inject arbitrary SQL due to improper escaping of dynamic partition key values, leading to unauthorized data access or modification.

sqli dagster injection
2r 6t
high advisory

Simple IT Discussion Forum SQL Injection Vulnerability (CVE-2026-5827)

CVE-2026-5827 is a SQL injection vulnerability in code-projects Simple IT Discussion Forum 1.0, allowing remote attackers to execute arbitrary SQL commands by manipulating the 'content' argument in /question-function.php.

sqli web-application injection
2r 1t 1c
critical advisory

Vim Code Execution Vulnerability via Crafted Files (CVE-2026-34714)

Vim versions before 9.2.0272 allow code execution upon opening a specially crafted file due to %{expr} injection in tabpanel lacking P_MLE in the default configuration, potentially leading to arbitrary code execution.

cve-2026-34714 code-execution vim injection
2r 2t
high advisory

AWS SDK for PHP CloudFront Policy Document Injection via Special Characters

A vulnerability exists in the AWS SDK for PHP CloudFront signing utilities where special characters in input values are not properly handled when creating policy documents, potentially leading to unintended access restrictions, affecting versions 3.11.7 through 3.371.3.

aws cloudfront injection security
2r 1t 1i
high advisory

BadAML Injection Allows Arbitrary Code Execution in Confidential VMs

The BadAML injection attack allows arbitrary code execution in confidential VMs by exploiting the ACPI interface, enabling attackers with host control to execute malicious AML code within the guest.

badaml acpi injection confidential-computing
2r 1t
high advisory

Spring AI Redis Store TAG Injection Vulnerability (CVE-2026-22744)

CVE-2026-22744 is a code injection vulnerability in Spring AI's RedisFilterExpressionConverter which allows an attacker to inject arbitrary commands into RediSearch TAG blocks via unescaped user-controlled strings, affecting versions 1.0.0 before 1.0.5 and 1.1.0 before 1.1.4.

injection spring-ai redis
2r 1t
critical advisory

n8n Merge Node AlaSQL Injection Vulnerability

An authenticated user with workflow creation/modification permissions can exploit insufficient restrictions in the n8n Merge node's AlaSQL sandbox to achieve remote code execution by reading local files or executing commands on the n8n host.

n8n rce alaqsl injection
2r 1t
critical advisory

Dgraph Pre-Auth DQL Injection Vulnerability

A pre-authentication DQL injection vulnerability in Dgraph's `/mutate` endpoint, when ACL is disabled, allows attackers to exfiltrate the entire database by crafting a malicious `cond` field in an upsert mutation.

Dgraph dql-injection injection database-exfiltration
1r 1t
high advisory

gmaps-mcp Unauthenticated HTTP Transport Allows Unlimited Google Maps API Calls

The gmaps-mcp package allows unauthenticated access to Google Maps API calls when deployed with a blank MCP_API_KEY, potentially leading to significant financial costs for the operator; it also permits path injection attacks.

Places API +1 googlemaps unauthenticated-access api-abuse injection
2r 1i
high advisory

xmldom XML Node Injection via Comment Serialization

The xmldom library is vulnerable to XML node injection, allowing attackers to inject arbitrary XML nodes into serialized output by manipulating comment content; this is mitigated by using the `requireWellFormed` option in `serializeToString` after upgrading to version 0.8.13 or 0.9.10.

xmldom xml injection deserialization vulnerability
2r 1t
high advisory

Lemur LDAP Filter Injection Vulnerability

Lemur versions before 1.9.0 are vulnerable to LDAP filter injection, where an authenticated LDAP user can inject LDAP filter metacharacters through the username field to manipulate group membership queries and escalate their privileges to administrator.

Lemur ldap injection privilege-escalation
2r 1t
critical advisory

Vendure Shop API Unauthenticated SQL Injection Vulnerability (CVE-2026-40887)

An unauthenticated SQL injection vulnerability (CVE-2026-40887) exists in the Vendure Shop API affecting PostgreSQL, MySQL/MariaDB, and SQLite databases, where a user-controlled query string parameter is directly interpolated into a raw SQL expression, potentially leading to arbitrary code execution.

Vendure sqli cve-2026-40887 web-application injection
2r 1t 1c
critical advisory

NocoBase SQL Injection via Recursive Eager Loading

NocoBase versions 2.0.32 and earlier are vulnerable to SQL injection due to string concatenation in the `queryParentSQL()` function, allowing attackers with record creation permissions to inject arbitrary SQL and potentially extract sensitive information or execute commands.

NocoBase sqli cve-2026-41640 injection
2r 4t
high advisory

fast-xml-builder Vulnerability Allows Attribute Injection

The fast-xml-builder library allows attribute injection when handling attribute values containing quotes, leading to potential execution of arbitrary code.

fast-xml-builder xml injection xss cve-2026-44665
2r 1t
critical advisory

Tekton Pipeline Git Resolver Git Argument Injection Vulnerability

The Tekton Pipeline Git Resolver is vulnerable to git argument injection due to the unsanitized `revision` parameter in the `git fetch` command, allowing remote code execution on the resolver pod and cluster-wide secret exfiltration.

Tekton Pipelines tekton git injection rce secret-exfiltration kubernetes
2r 3t
high advisory

PromtEngineer localGPT LLM Prompt Handler Injection Vulnerability (CVE-2026-5002)

A remote code injection vulnerability (CVE-2026-5002) exists in PromtEngineer localGPT versions up to commit 4d41c7d1713b16b216d8e062e51a5dd88b20b054, allowing attackers to execute arbitrary code by manipulating the LLM Prompt Handler component via the _route_using_overviews function in backend/server.py.

localGPT injection llm cve-2026-5002 webserver
2r 1t