NEWSkillSec — elevating AI Skills security from malware detection to capability auditingSkillSecLearn more →
← Back to Intel Center
SECURITY INTEL · DAILY
Link copiedRSS

2026-07-13 Daily Security Intelligence

12 itemsTop severity 10.0 (Critical)CSSA 1 · CVE 1 · Poisoning 10

CSSA Exclusive Early Warning1

CSSA Exclusive Early Warning10.0 Critical

browser-use domain restriction bypass via non-standard protocols leading to internal state disclosure and unauthorized navigation

An attacker can construct malicious links containing non-standard URI schemes such as javascript, file, chrome, or about, and exploit incomplete whitelist validation logic in the security watchdog module to achieve a bypass. The flaw originates from the input filtering mechanism blocking only specific data schemes while failing to cover all protocol types capable of triggering page navigation. When an automated agent visits a compromised page, cross-origin redirects or local file read operations are executed directly. The vulnerability is network-reachable and requires no additional user interaction to trigger; affected instances face risks including internal browser state disclosure, unauthorized access to sensitive paths, and failure of established domain isolation policies.

Component
browser-use is an AI agent framework for automated browser operations. The core system architecture employs modular task orchestration and low-level b…
Type
Incomplete List of Disallowed Inputs (CWE-184)
Repo
Remediation
  • It is recommended to replace the blacklist mechanism with a default-deny allowlist validation strategy, strictly limiting the set of permitted communication protocols and enforcing URI format validation. Developers should implement deep packet inspection and protocol header filtering at the routing resolution stage, combined with context-aware input sanitization functions to block unconventional redirect behavior.

CVE Intelligence1

CVE-2026-56271CVSS 9.8 Critical2026-07-12

Flowise JWT Default Hardcoded Key Leads to Authentication Bypass

In Flowise versions prior to 3.1.0 (affected versions are 3.0.13 and earlier), the enterprise edition Passport authentication middleware (packages/server/src/enterprise/middleware/passport/index.ts) contains a Use of Hard-coded Cryptographic Key (CWE-321) security flaw due to the use of weak hardcoded default JWT secrets ('auth_token', 'refresh_token') as well as default audience and issuer values ('AUDIENCE', 'ISSUER'). When the corresponding environment variables (JWT_AUTH_TOKEN_SECRET, JWT_REFRESH_TOKEN_SECRET, JWT_AUDIENCE, JWT_ISSUER) are not set, the application silently falls back to these publicly known default values, allowing attackers to forge valid JWTs and impersonate any user (including administrators), resulting in authentication bypass. This vulnerability affects all Flowise users who have not upgraded to 3.1.0, particularly deployments where the relevant environment variables are not properly configured. Attackers can remotely craft malicious requests over the network without any user interaction, using the known default secrets to generate valid tokens and thereby gain full control over system privileges.

Component
Flowise is an open-source low-code platform for building LLM (Large Language Model)-based applications, supporting rapid creation of AI agents and workflows through a drag-and-drop interface.
Risks
  • Privilege escalation from regular user to administrator: Attackers can exploit the default secrets to forge JWT tokens with administrator identity, directly escalating privileges to the highest level
  • Full system control: Attackers can impersonate any user (including administrators) to perform arbitrary operations, view, modify, or delete sensitive data, and even take control of the entire AI application's workflow configuration
  • Zero user interaction attack: Attackers only need to send a crafted HTTP request to the server to trigger the vulnerability, requiring no clicks or interaction from any victim
Source
Remediation
  • Immediately upgrade Flowise to version 3.1.0 or latere to version 3.1.0 or later
  • Ensure that the JWT_AUTH_TOKEN_SECRET, JWT_REFRESH_TOKEN_SECRET, JWT_AUDIENCE, and JWT_ISSUER environment variables are properly set in production environments using strong random strings
  • Regularly audit the codebase for other hardcoded sensitive credentials or default configurations

Package Poisoning10

Package Poisoningnpm2026-07-13

auto-debug-tool@1.0.3 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
2a023d6ed43df87753d63ebc068a7f38
Package Poisoningnpm2026-07-13

mcp-notes-server-poc-praetorian@0.1.0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
d5d85acc4a9b4343617a8dec46025d45
Package Poisoningnpm2026-07-13

babel-preset-lib-client@4.9.10 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
a67af11d76aabc7d79a4122607212699
Package Poisoningnpm2026-07-13

cold-debug-elevator@1.0.1 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
d4d37c7d52d72d76f24bfc37461043b7
Package Poisoningnpm2026-07-13

cookie-sign@2.3.5 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
d87220f19a42e583f59483792eb4aa05
Package Poisoningnpm2026-07-13

kuaishou@99.9.10 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
453062dbd03878b6e084fc2da348f0ae
Package Poisoningnpm2026-07-13

notifications-broadcast@99.9.1 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
7ba71ecd60091eb69892ff4939e07440
Package Poisoningnpm2026-07-13

path-addon-extend@1.0.7 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
c6fb1b0d2997bffdd24229caf0ef36b3
Package Poisoningnpm2026-07-13

sso-users-detection@99.9.1 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
216607df2c444cf7d578fe5046f1e193
Package Poisoningnpm2026-07-13

terminal-mascot@3.5.2 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
5a8acfa3269f7c3b2add28ca0421bd17