NEWSkillSec — elevating AI Skills security from malware detection to capability auditingSkillSecLearn more →
← Back to Intel Center
SECURITY INTEL · DAILY
Link copiedRSS

2026-07-09 Daily Security Intelligence

12 itemsTop severity 10.0 (Critical)CSSA 2 · CVE 1 · Poisoning 9

CSSA Exclusive Early Warning2

CSSA Exclusive Early Warning10.0 Critical

Kotaemon deserialization flaw leading to unauthenticated remote code execution and system compromise

The vulnerability arises because backend endpoints lack server-side access control and perform unsafe deserialization directly on untrusted input, dynamically instantiating arbitrary classes through reflection. An attacker can craft nested data structures that trigger process execution functions, reaching the target directly with an unauthenticated network request. This results in abuse of server process privileges and exposes the system to data theft and command-level takeover.

Component
Kotaemon is a large language model management platform built on the Gradio framework. Its core architecture uses a modular design and provides model c…
Type
Deserialization of Untrusted Data (CWE-502)
Repo
Remediation
  • It is recommended to build a trusted class loading allowlist, fully disable dynamic module import switches, place server-side authentication middleware in front of all external endpoints, and use strongly typed data validation to intercept maliciously constructed parameters.
CSSA Exclusive Early Warning10.0 Critical

nanobot DNS rebinding attack bypassing validation leading to server-side request forgery

This flaw stems from a time-of-check to time-of-use race window between the network request validation stage and the actual connection establishment stage. The security module resolves the domain name and compares IP attributes in advance but only returns a result, without binding the verified IP address to the subsequent communication path. The caller passes the original hostname directly to the asynchronous HTTP client, causing the underlying network library to perform a second DNS resolution when establishing the TCP connection. By controlling a malicious DNS response strategy, an attacker can return a public address during validation to pass the security check and then switch dynamically to a loopback address or cloud metadata endpoint at connection time, completely bypassing server-side request forgery protection. This attack chain is network-reachable and requires no credentials; affected environments face lateral movement into internal services, disclosure of cloud infrastructure configuration and tampering with backend business logic.

Component
nanobot is an agent framework for automated task orchestration. Its core architecture uses a modular design to support external network interaction an…
Type
Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367)
Repo
Remediation
  • It is recommended to adopt IP pinning, reusing the verified address directly to establish the connection after validation. Developers should encapsulate a custom transport layer that forcibly binds the resolution result and updates request headers accordingly. Strict state locking and context isolation policies should also be enforced to eliminate race conditions caused by secondary resolution.

CVE Intelligence1

CVE-2026-59873CVSS 9.8 Critical2026-07-09

node-tar Extraction Resource Exhaustion Leading to Denial of Service

In node-tar prior to version 7.5.19, the extraction and parsing paths (such as src/extract.ts) do not enforce hard limits on total decompressed data volume, entry count or compression ratio, resulting in uncontrolled resource allocation (CWE-770). An attacker can exhaust disk space and CPU resources with a carefully crafted small gzip bomb, rendering the service unavailable. node-tar contains a resource exhaustion vulnerability when handling maliciously crafted archives, which an attacker can trigger by supplying a crafted tar package, leading to remote denial of service or system resource depletion. The vulnerability affects all node-tar users who have not updated to 7.5.19, including a wide range of Node.js application deployments. An attacker only needs to induce the target application to process a crafted archive, typically causing resource exhaustion without complex interaction.

Component
node-tar is a tar archive manipulation library for Node.js, widely used for file packing and unpacking.
Risks
  • From standard user to administrator: If the victim runs a service depending on node-tar with administrative privileges, an attacker may cause system-level resource exhaustion
  • Complete system control: An attacker can exhaust disk space and CPU with this vulnerability, causing service disruption, failed data writes or system crashes
  • No user interaction required: Through drive-by compromise (T1189), a user only needs to visit a page or endpoint containing a malicious archive to trigger the vulnerability, with no additional interaction
Source
Remediation
  • Upgrade node-tar to version 7.5.19 or later
  • Perform secondary validation of archive size and compression ratio for uploaded or extracted files at the application layer
  • Restrict disk space quotas and CPU time for extraction operations

Package Poisoning9

Package Poisoningnpm2026-07-09

ag-charts-test@99.9.1 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
eb13c27a64e5f0bbe6046b824e2b59a1
Package Poisoningnpm2026-07-09

babel-eslint-parser-legacy@99.9.1 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
af72e92b8b725f909cc0fedcb0d710db
Package Poisoningnpm2026-07-09

chai-redirection@0.0.1 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
1a9eac1b6934fa2c4fe8931d481fdeab
Package Poisoningnpm2026-07-09

higherlogic-ocfe@99.9.1 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
ef927493cc95771dcefc6b8d8a1763e1
Package Poisoningnpm2026-07-09

luludawang-kit@0.0.1 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
5bc5b9efc3e895da0d640da401a26139
Package Poisoningnpm2026-07-09

searchresults@999.0.0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
1c334a3b1d15457e70eb95347a0a0fcf
Package Poisoningnpm2026-07-09

crypto-promiser@1.0.1 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
05da0c13291431256fd4cdb91c27bef1
Package Poisoningnpm2026-07-09

next-locomotive-init@1.0.4 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
6516e1e20798ea3b6d3b73adad510545
Package Poisoningnpm2026-07-09

none123s@0.1.7 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
89eea53d27b96daa6ff84f17e536b2e7