NEWSkillSec — elevating AI Skills security from malware detection to capability auditingSkillSecLearn more →
← Back to Intel Center
SECURITY INTEL · DAILY
Link copiedRSS

2026-07-14 Daily Security Intelligence

12 itemsTop severity 10.0 (Critical)CSSA 1 · CVE 2 · Poisoning 9

CSSA Exclusive Early Warning1

CSSA Exclusive Early Warning10.0 Critical

Envoy Gateway Route Hijacking and Directory Traversal via Unescaped Path Variable Injection

The flaw originates in the mcp_json_rest_bridge extension filter, where the substitution logic for simple template variables during upstream request path construction does not percent-encode slashes and dots. The rewritten path is written directly into the upstream protocol headers, bypassing secondary normalization checks. Because the pre-processing path sanitization stage only applies to the original request line, an unauthenticated downstream client can inject relative path sequences through JSON tool call parameters, triggering routing cache invalidation and forcing the routing table to re-match. An attacker can exploit this to break out of predefined access boundaries, bypass upstream routing rules, or induce backend services to resolve unintended directory structures. Network nodes deploying this component are exposed to risks of business logic tampering and sensitive resource disclosure.

Component
Envoy is a high-performance edge and service mesh proxy written in C++ that uses a plugin-based filter chain architecture to handle network traffic. I…
Type
Path Traversal (CWE-22)
Repo
Remediation
  • To address this type of path traversal vulnerability, strict character allowlist validation should be enforced at the path concatenation stage. Template variables without explicitly declared wildcards should be subject to single-segment matching rules, and special delimiters and consecutive dots must be escaped or blocked. Additionally, standardized normalization logic must be introduced before the final path assignment, combined with a defense-in-depth strategy to reject request payloads containing illegal traversal sequences.

CVE Intelligence2

CVE-2026-59515CVSS 9.3 Critical2026-07-13

Sergey AIWU ai-copilot-content-generator SQL Injection Leading to Blind SQL Injection

In Sergey AIWU ai-copilot-content-generator version 1.5.4 and earlier, the SQL command processing module improperly neutralizes special elements, resulting in an SQL injection (CWE-89) security vulnerability. An attacker can craft malicious input to trigger blind SQL injection, thereby illegally accessing or manipulating the backend database and threatening data confidentiality and system integrity. This vulnerability affects all AIWU users who have not updated to a version beyond 1.5.4. The attack can be launched remotely over the network, requires no user interaction, has low exploit complexity, and can result in high confidentiality impact.

Component
Sergey AIWU ai-copilot-content-generator is an AI-assisted content generation tool that supports content creation and management via API or user interface.
Risks
  • Data Breach: Attackers can use blind SQL injection techniques to incrementally infer and extract sensitive information from the database, such as user credentials and business data.
  • Remote Code Execution Risk: Under certain configurations, SQL injection may further escalate into remote code execution, resulting in full compromise of the server.
  • No User Interaction Required: Attackers only need to send specially crafted requests over the network to trigger the vulnerability, requiring no additional action from the target user.
Source
Remediation
  • Immediately upgrade ai-copilot-content-generator to a secure version beyond 1.5.4to a secure version beyond 1.5.4
  • Enforce strict parameterized queries or prepared statement handling for all user input
  • Deploy a Web Application Firewall (WAF) to intercept common SQL injection attack patterns
CVE-2026-41041CVSS 9.1 Critical2026-07-13

Apache Gravitino URL Path Injection Vulnerability Leading to Sensitive Information Disclosure and Data Tampering

In Apache Gravitino versions prior to 1.2.1, the core service contains a URL path injection (CWE-177) security flaw due to improper URL encoding of user-supplied identifiers. An attacker can craft malicious requests containing special characters to bypass path validation mechanisms and directly access or manipulate unintended system resources. Apache Gravitino is susceptible to path traversal when handling metadata management requests, which can be triggered remotely without authentication, resulting in high-confidentiality data disclosure and system integrity compromise. This vulnerability affects all Apache Gravitino instances running versions from 1.0.0 up to but not including 1.2.1. Exploitation requires only that an attacker send a specially crafted request over the network, with no user interaction required and full remote controllability.

Component
Apache Gravitino is an open-source metadata management platform designed to provide unified metadata management, data governance, and catalog services for data lakes and big data ecosystems.
Risks
  • Sensitive data disclosure: Attackers can exploit path injection to read sensitive configuration files or metadata on the server, exposing confidential information (Confidentiality: High)
  • Data integrity compromise: Attackers may inject malicious paths to modify critical metadata or configurations, disrupting the normal operation of downstream data services (Integrity: High)
  • Remote interaction-free attack: The vulnerability can be exploited directly over the network (Attack Vector: Network) with low exploitation complexity (Attack Complexity: Low) and requires no user interaction to trigger
Source
Remediation
  • Immediately upgrade Apache Gravitino to version 1.2.1 or later to remediate this vulnerabilityersion 1.2.1 or later to remediate this vulnerability
  • Deploy a Web Application Firewall (WAF) at the application layer to intercept requests containing abnormal URL encoding or path traversal patterns
  • Enforce strict allowlist validation and URL encoding normalization on all user-supplied identifiers

Package Poisoning9

Package Poisoningnpm2026-07-14

cktool-core@1.0.1 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
108c862921ecd5eb172f10038b6c1f1d
Package Poisoningnpm2026-07-14

font-huge@2.5.3 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
14e0793da6850a4a1db56b2ebd6e03b5
Package Poisoningnpm2026-07-14

gamified-trading-system@3.1.0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
c6088e4409ffb1648506c300189cb49e
Package Poisoningnpm2026-07-14

node-fsagent@1.2.1 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
8b19c01524bd148547bc1782dd7414fa
Package Poisoningnpm2026-07-14

lusha-iam-widgets@1.5.2 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
849554c57c5cb1ac8b5d68c5c5e71652
Package Poisoningnpm2026-07-14

abi-encode@1.0.1 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
56dc47f244208441031fea1020a99218
Package Poisoningnpm2026-07-14

eth-wallet-helpers@1.0.0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
4c165e3589393f246b2e8072c01da400
Package Poisoningnpm2026-07-14

harpoon-package@1.2.0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
b6bf38596c085b3b3782c41224552fbe
Package Poisoningnpm2026-07-14

web-pop@2.3.5 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
50591b79c574736041de5b14878d7ef5