NEWSkillSec — elevating AI Skills security from malware detection to capability auditingSkillSecLearn more →
← Back to Intel Center
SECURITY INTEL · DAILY
Link copiedRSS

2026-07-07 Daily Security Intelligence

4 itemsTop severity 10.0 (Critical)CSSA 1 · CVE 2 · Poisoning 1

CSSA Exclusive Early Warning1

CSSA Exclusive Early Warning9.9 Critical

Dolibarr user clone endpoint parameter tampering leading to privilege escalation and complete system takeover

This flaw stems from the user clone endpoint failing to perform dynamic authorization checks on the target object, allowing an attacker with only basic clone permission to craft a malicious network request. By directly tampering with the identifier parameter in the request payload, the caller bypasses front-end interface restrictions and session-level anti-replay token validation, forcing the backend data replication logic to execute. This operation maps the configuration of a protected high-privilege account entirely onto a new instance, causing the initially low-privilege identity to inherit all system administration policies. Affected environments face amplified lateral movement risk, and the attack chain achieves global configuration tampering, bulk export of sensitive data and disruption of core business processes without additional interaction.

Component
Dolibarr is an open-source integrated ERP and CRM platform. Its architecture uses a modular design and builds backend services on PHP and a relational…
Type
Authorization Bypass Through User-Controlled Key (CWE-639)
Repo
Remediation
  • It is recommended that the development team implement strict object-level access control and introduce secondary authorization checks on target entities at the business logic layer. Hardcoded interception rules should be established for high-risk account identifiers, ensuring sensitive operations execute only in privileged contexts. Security tokens should also be hash-bound to scope parameters, and a complete audit logging module deployed to trace anomalous data change trajectories.

CVE Intelligence2

CVE-2026-57572CVSS 10.0 Critical2026-07-07

Crawl4AI Docker API Argument Injection Leading to Arbitrary Command Execution

In Crawl4AI prior to version 0.9.0, the Docker API server contains an argument injection (CWE-88) security flaw. The API has no authentication enabled by default and accepts the browser_config.extra_args parameter supplied in requests, which is passed directly into Chromium's launch arguments. An attacker can inject Chromium launch switches and, combined with the --no-zygote parameter to replace the subprocess launch command, cause Chromium to fork or exec attacker-controlled commands as the container runtime user. Because no authentication is required, a single request can lead to arbitrary command execution. The vulnerability affects all Crawl4AI users who have not updated to 0.9.0, particularly deployments exposing the Docker API service. An attacker needs no user interaction and can execute arbitrary code remotely with a crafted request, gaining full control of the container environment.

Component
Crawl4AI is an open-source web crawler and scraping tool for large language models (LLMs), designed to provide LLM-friendly data collection services.
Risks
  • Complete system control: An attacker can execute arbitrary code inside the container, and depending on container runtime user privileges, install programs, view/modify/delete data or create new accounts with full privileges
  • Unauthenticated remote attack: Because the Docker API has no authentication enabled by default, an attacker can launch the attack without any credentials
  • Container escape risk: With improper container configuration, an attacker may use this vulnerability to escape to the host and threaten the entire infrastructure
Source
Remediation
  • Immediately upgrade Crawl4AI to version 0.9.0 or later
  • Enable authentication for the Docker API and restrict access permissions
  • Apply strict allowlist validation or filtering to the incoming browser_config.extra_args parameter
CVE-2026-42341CVSS 9.8 Critical2026-07-07

FOSSBilling Unauthenticated Payment Bypass Leading to Account Credit Tampering

In FOSSBilling versions 0.6.0 through 0.7.2, the IPN callback endpoint lacks authentication for a critical function (CWE-306), resulting in an unauthenticated payment bypass. When the Custom payment adapter is enabled, an attacker can send a single carefully crafted HTTP request to mark any unpaid invoice as paid and credit the associated customer account, without making an actual payment. The vulnerability affects all FOSSBilling users who have not updated to 0.8.0. An attacker can trigger it remotely without authentication, directly bypassing business logic and undermining the integrity of financial data.

Component
FOSSBilling is a free open-source billing and client management system widely used to manage invoices, payments and customer accounts.
Risks
  • Financial loss and fraud: An attacker can mark unpaid invoices as paid, causing revenue loss for the service provider
  • Account credit tampering: An attacker can arbitrarily increase customer account credit, undermining the fairness and accuracy of the billing system
  • Unauthenticated remote attack: An attacker needs no credentials and can exploit the vulnerability simply by crafting a specific HTTP request, with no user interaction
Source
Remediation
  • Immediately upgrade FOSSBilling to version 0.8.0 or later to fix the vulnerability
  • If an immediate upgrade is not possible, disable the Custom payment gateway (if not actively used)
  • Restrict access to /ipn.php at the web server level (for example through an IP allowlist), noting that this may interfere with legitimate payment callback handling

Package Poisoning1

Package Poisoningnpm2026-07-07

zluri-ad-connector@9.9.9 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
994041160386b84249e0fb118491e345