NEWSkillSec — elevating AI Skills security from malware detection to capability auditingSkillSecLearn more →
← Back to Intel Center
SECURITY INTEL · DAILY
Link copiedRSS

2026-07-10 ~ 07-12 Daily Security Intelligence

20 itemsTop severity 10.0 (Critical)CSSA 1 · CVE 2 · Poisoning 17

CSSA Exclusive Early Warning1

CSSA Exclusive Early Warning10.0 Critical

elizaOS Authentication Mechanism Flaws Enable Remote Unauthorized Access to Sensitive Endpoints Leading to Data Exposure

This vulnerability stems from fragmented internal role definitions and broken permission validation logic. The HTTP gateway layer relies solely on a single boolean value for binary allow/deny decisions, lacking fine-grained role-based tiered interception. An attacker can craft malicious network requests to directly bypass the central authentication module, exploiting wallet signing routes marked as publicly accessible and static shared token mechanisms to launch replay attacks or cross-origin credential theft. Combined with administrator entity identifiers derived through implicit loopback trust inference, unauthorized parties can laterally traverse high-risk interfaces including configuration management, key storage, and fund operations, resulting in illegal reading and tampering of core business data and a complete collapse of the system's trust boundary.

Component
elizaOS is a distributed collaboration platform designed for intelligent agent interaction and enterprise application integration. Its architecture em…
Type
Improper Authorization (CWE-285)
Repo
Remediation
  • It is recommended to refactor a unified role enumeration and permission mapping table, enforce role-based access control policies at the API gateway layer, remove public exposure markings from non-essential interfaces, replace static shared credentials with dynamic tokens incorporating anti-replay mechanisms, strictly restrict the cross-origin resource sharing whitelist and disable credential passthrough, and establish an explicit initialization process for administrator binding along with full-chain audit logging.

CVE Intelligence2

CVE-2026-59726CVSS 10.0 Critical2026-07-10

Ruflo Default Deployment MCP Endpoint Unauthenticated Vulnerability Leading to Remote Code Execution

Prior to Ruflo version 3.16.3, the default docker-compose deployment exposes the MCP bridge POST /mcp and POST /mcp/:group endpoints without any authentication, resulting in an OS command injection (CWE-78) security flaw. An unauthenticated remote attacker can invoke tools/call to execute terminal_execute, thereby gaining shell access within the bridge container, reading provider API keys, and poisoning the AgentDB learning storage schema. This vulnerability has been fixed in version 3.16.3.

Component
Ruflo is an agent meta-harness for Claude Code and Codex, designed to orchestrate and manage AI agent workflows.
Risks
  • Full container control: An attacker can gain shell access within the bridge container and execute arbitrary commands
  • Sensitive information disclosure: An attacker can read provider API keys, resulting in credential leakage
  • Data integrity compromise: An attacker can poison the AgentDB learning storage schema, affecting the learning and behavioral logic of the agent system
  • Unauthenticated remote attack: An attacker can launch attacks over the network without any authentication, making exploitation extremely low-effort
Source
Remediation
  • Immediately upgrade Ruflo to version 3.16.3 or higher to version 3.16.3 or higher
  • Enforce strict authentication mechanisms on the MCP bridge endpoints
  • Restrict command execution privileges within the container to avoid directly exposing the terminal_execute functionality
CVE-2026-55615CVSS 9.8 Critical2026-07-10

Langroid Neo4jChatAgent Prompt Injection Vulnerability Leading to Remote Code Execution

Prior to Langroid version 0.65.5, the Neo4jChatAgent module contains a prompt injection (CWE-74) security flaw due to the lack of validation on LLM-generated Cypher queries, a statement-type allowlist, and a disable option. An attacker can influence prompts through direct user input or indirect content read by the agent via RAG, thereby crafting malicious Cypher queries. This vulnerability allows an attacker to read or destroy all graph data; if APOC or dbms.security procedures are enabled on the server, the attacker can also achieve operating system command execution and filesystem access. This vulnerability belongs to the same flaw class as CVE-2026-25879, but the previous fix did not cover the neo4j module. This vulnerability affects all Langroid users who have not updated to 0.65.5. An attacker only needs to induce the target application to process controlled prompt input to exploit the vulnerability, potentially resulting in data exfiltration, data destruction, or full server compromise.

Component
Langroid is a framework for building applications powered by large language models (LLMs), supporting multiple backend integrations including the Neo4j graph database.
Risks
  • Complete data exfiltration or destruction: An attacker can read or destroy all graph data in the Neo4j database
  • Remote Code Execution (RCE): When APOC or dbms.security procedures are enabled on the server, an attacker can execute arbitrary operating system commands and access the filesystem
  • No complex interaction required: Through prompt injection techniques, an attacker can exploit logical flaws in the LLM agent without traditional authentication
Source
Remediation
  • Immediately upgrade Langroid to version 0.65.5 or later to obtain the official fixsion 0.65.5 or later to obtain the official fix
  • Disable unnecessary APOC or dbms.security procedures on the Neo4j server to reduce the attack surface
  • Implement strict input validation and output filtering mechanisms to prevent prompt injection attacks

Package Poisoning17

Package Poisoningnpm2026-07-10

cookie-parser-js@1.4.9 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
8392158ac64e9bbe8a6526a30c03c521
Package Poisoningnpm2026-07-10

vite-pwa-config@1.1.2 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
9d87f21c1487a0d86587b899cdc0cf8e
Package Poisoningnpm2026-07-10

fury_frontend-andes-ui@99.9.5 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
93acd3510c40ef5484add9ebd4be457f
Package Poisoningnpm2026-07-10

guest-app-ui@99.0.0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
672ba9506983bc169cd6227e51f47e89
Package Poisoningnpm2026-07-10

fastify-addone@5.1.0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
79f2cac3e3e826401eae5271b03302c5
Package Poisoningnpm2026-07-10

polipoli-pak@1.0.2 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
36a03f6da83c61286291ada600feae35
Package Poisoningnpm2026-07-10

px8my@1.0.32 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
ca7bc8dabe496f72fc1d60b7f2cce508
Package Poisoningnpm2026-07-11

theta-sdk-js@1.2.16 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
dea37d8bdb0dfbbda4984f8c0634aa6f
Package Poisoningnpm2026-07-11

notifier-funcs@1.3.4 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
56c250ee524b8ea05450359a7d0384aa
Package Poisoningnpm2026-07-11

notify-utilities@1.3.5 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
b646c45207d704fa7124be116cada4be
Package Poisoningnpm2026-07-11

rollup-packages-polyfill-core@0.13.7 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
75c9b657561195b21d361d5de6ae370c
Package Poisoningnpm2026-07-11

sidecar-mcp@1.0.2 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
f2ea7533dd34943be0b94a8513a4e8bc
Package Poisoningnpm2026-07-11

type-atob@3.3.7 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
e4a4e01d07fd9f1278c1b7f2904d1d91
Package Poisoningnpm2026-07-11

auth-next-gen@1.7.2 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
8d25a920582b47f7f2650112220f9c12
Package Poisoningnpm2026-07-12

google-caja-bower@1000.80.20 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
2679f102ec9cc25ffa1e26636b8a6d29
Package Poisoningnpm2026-07-12

jscrambler@8.16.0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
0d33aa6debfa0314edce54f609a29b6e
Package Poisoningnpm2026-07-12

tinymask-js@1.0.2 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
d74ded908646790fac7cb210734ce280