NEWSkillSec — elevating AI Skills security from malware detection to capability auditingSkillSecLearn more →
← Back to Intel Center
SECURITY INTEL · DAILY
Link copiedRSS

2026-07-15 Daily Security Intelligence

9 itemsTop severity 10.0 (Critical)CSSA 1 · CVE 2 · Poisoning 6

CSSA Exclusive Early Warning1

CSSA Exclusive Early Warning10.0 Critical

Remote Code Execution via Deserialization of Unvalidated Data in the sglang Framework

This vulnerability stems from the message queue module directly invoking the built-in deserialization function to process raw byte streams when unpacking subscribed data, with no security boundary controls such as authentication, hash signatures, or format filtering applied to the communication channel. An attacker needs only to obtain the publish endpoint address of the target cluster to deliver a crafted malicious serialized payload over the network. Once the malicious data is received through the socket, it triggers the underlying interpreter to execute arbitrary system commands. This attack path has a low barrier to exploitation and is remotely exploitable. A successful intrusion would result in the hijacking of computational logic across all connected nodes, leading to cascading security consequences including service disruption, data exfiltration, and lateral movement.

Component
sglang is a high-performance inference and serving engine for large language models. Its core architecture is built on distributed computing and share…
Type
Deserialization of Untrusted Data (CWE-502)
Repo
Remediation
  • It is recommended to fully abandon unsafe deserialization protocols in favor of type-safe data formats. Mutual authentication and digital signature verification should be enforced at communication entry points, strict allowlists should be configured to block anomalous structures, and the runtime environment should be isolated according to the principle of least privilege to completely prevent the loading of malicious code.

CVE Intelligence2

CVE-2026-62422CVSS 10.0 Critical2026-07-14

YouTrack Authentication Bypass via Direct Database Access Leading to Administrator Privileges

Prior to JetBrains YouTrack versions 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, and 2024.2.148429, a vulnerability exists that allows authentication bypass and acquisition of administrator privileges through direct database access. This vulnerability is classified as Missing Authentication for Critical Function (CWE-306), enabling an unauthenticated attacker to directly access the database over the network and obtain the highest level of privileges. Because the attack vector is NETWORK with LOW complexity, requiring no user interaction (UI:N) and no privileges (PR:N), an attacker can fully compromise the affected system, resulting in severe impact to confidentiality, integrity, and availability. This vulnerability affects all YouTrack instances that have not been updated to the secure versions listed above; a successful exploit allows the attacker to completely take over the application server and its underlying data.

Component
JetBrains YouTrack is a powerful issue tracking and project management software widely used by software development teams for task management, bug tracking, and collaboration.
Risks
  • Complete System Control: By bypassing authentication and directly accessing the database, an attacker can obtain administrator privileges and fully control the YouTrack instance, including viewing all project data, modifying configurations, deleting data, or planting backdoors.
  • Data Breach and Tampering: Due to the high impact on confidentiality (HIGH) and integrity (HIGH), an attacker can steal sensitive project information and user credentials, or tamper with critical business data.
  • No User Interaction Required: The attacker does not need to trick a user into performing any action; simply sending a direct network request is sufficient to trigger the vulnerability, significantly lowering the barrier to exploitation.
Source
Remediation
  • Immediately upgrade JetBrains YouTrack to version 2026.1.13757 or later to remediate this vulnerability2026.1.13757 or later to remediate this vulnerability
  • Restrict direct network access to the YouTrack database port, ensuring the database is accessible only from the internal network or trusted application-layer services
  • Deploy a network intrusion detection system (IDS) to monitor for anomalous access attempts targeting the database port
CVE-2026-62390CVSS 9.8 Critical2026-07-14

Apache Kylin SQL Injection Vulnerability Leading to Remote Code Execution

Prior to Apache Kylin version 5.0.4, the backend API for refreshing the table catalog contains a SQL injection (CWE-89) security flaw due to improper neutralization of special elements in SQL commands. An attacker can inject SQL statements by crafting malicious requests, threatening the integrity and confidentiality of the backend database. Apache Kylin is vulnerable to injection in certain API call scenarios, which can be triggered remotely over the network, resulting in data leakage, tampering, or remote code execution. This vulnerability affects all Apache Kylin versions from 4.0.0 through 5.0.3. The vulnerability can be exploited remotely without user interaction or authentication, posing an extremely high risk.

Component
Apache Kylin is an open-source distributed analytics engine that provides a SQL query interface and multidimensional analytics (OLAP) capabilities on Hadoop/Spark, supporting extremely large-scale datasets.
Risks
  • From regular user to administrator: If the victim runs the Kylin service with administrator privileges, the attacker can obtain the same level of privileges
  • Full system control: An attacker can exploit this vulnerability to execute arbitrary code on the victim's system, and depending on user permissions, install programs, view/modify/delete data, or create new accounts with full privileges
  • No user interaction required: Via remote network requests (T1190), an attacker only needs to send a specially crafted API request to trigger the vulnerability without any additional interaction
Source
Remediation
  • Immediately upgrade Apache Kylin to version 5.0.4 or later to remediate this vulnerabilityersion 5.0.4 or later to remediate this vulnerability
  • Implement strict input validation and parameterized query mechanisms for backend APIs
  • Monitor anomalous SQL execution logs and database access behavior

Package Poisoning6

Package Poisoningnpm2026-07-15

chain-sdk-js@1.0.3 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
9c4f3a87ef9184d08c281dccf0a8272a
Package Poisoningnpm2026-07-15

assertion-utils-js@2.4.3 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
d9f31b77bef62ba94bfb2ac161c74627
Package Poisoningnpm2026-07-15

ethereum-lib-utils@1.3.7 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
b4b500d2a8c8341e344a7a8fb3a527f6
Package Poisoningnpm2026-07-15

postcss-selector-minify@2.0.0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
2c3f89fc0615ee4ad3d7385ff61d559c
Package Poisoningnpm2026-07-15

http-ws-listener@1.0.5 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
bc830ecdabf64d37a4e318224d5468fb
Package Poisoningpypi2026-07-15

tronwe@0.0.1 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
4bb2f0c91b2f00460a65f7c8a95e0474