CVE-2026-63767CVSS 9.8 Critical2026-07-21
ktransformers Unauthenticated Pickle Deserialization Vulnerability Leading to Remote Code Execution
In ktransformers 0.6.3 and earlier, the SchedulerServer ZMQ ROUTER socket binds to all interfaces and lacks any authentication mechanism, resulting in an unauthenticated pickle deserialization (CWE-502) security flaw. An attacker can send a crafted pickle payload with an embedded malicious __reduce__ method to execute arbitrary shell commands as the server process. The vulnerability allows a remote attacker to take control of the server without authentication, threatening the confidentiality, integrity and availability of the system. It affects all ktransformers users who have not updated to the fixed version (commit def0f93). An attacker only needs to send a malicious packet to the exposed ZMQ port to exploit it, requiring no user interaction and allowing full remote control.
Component
ktransformers is an open-source Transformer model inference library designed to provide efficient distributed inference services, in which SchedulerServer handles task scheduling and communicates over ZMQ.
Risks
- Complete system control: An attacker can execute arbitrary code in the context of the server process, and depending on server privileges, install programs, view/modify/delete data or create new accounts with full privileges
- No user interaction required: An attacker does not need to trick a user into any action; simply sending a crafted packet to the exposed network interface triggers the vulnerability
- Remote code execution: Because the flaw sits in a network-reachable service endpoint, an attacker can launch the attack from anywhere on the internet and take over the server completely
Source
Remediation- Restrict the bind address of the SchedulerServer ZMQ socket and avoid binding to all interfaces (0.0.0.0)
- Configure firewall rules at the network level to allow only trusted IP addresses to reach the ZMQ service port
CVE-2026-64622CVSS 7.5 High2026-07-20
Network-AI Approval Endpoint Missing Authorization Leading to Sensitive Information Disclosure
In Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3, the configured authorization checks (checkAuth/secret) are not applied to the ApprovalInbox GET read routes, resulting in a missing authorization (CWE-862) security flaw. Even when an operator has configured a secret, an unauthenticated attacker can still access sensitive approval request details. The routes GET /approvals/?status=all, GET /approvals/:id, GET /approvals/stats and GET /approvals/sse leak complete ApprovalEntry content, including action/target shell-command strings, file paths, rationale and risk levels. All responses also carry a hardcoded Access-Control-Allow-Origin: * header, enabling cross-origin leakage from any website the operator visits. This is an incomplete fix for GHSA-mxjx-28vx-xjjj. The vulnerability affects all Network-AI users who have not updated to a patched version. An attacker can retrieve sensitive data remotely without authentication and can use the CORS header for cross-origin data theft.
Component
Network-AI is an open-source npm component used for managing approval workflows related to network artificial intelligence.
Risks
- Sensitive information disclosure: An attacker can obtain complete approval entry content, including shell command strings, file paths, business rationale and risk levels, potentially exposing internal logic or enabling further attacks
- Cross-origin data theft: Because responses include Access-Control-Allow-Origin: *, an attacker can craft a malicious page that silently steals approval data in the victim's browser
- Unauthenticated attack: An attacker needs no credentials to reach the protected endpoints directly, lowering the barrier to exploitation
Source
Remediation- Restrict access to /approvals/ endpoints at the gateway or reverse proxy layer
- Remove or correct the Access-Control-Allow-Origin: * response header and enforce a strict CORS policy
Package Poisoningnpm2026-07-21
tilaver-mfa@1.0.0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
8860e0ab30ef0ad1d27e57a59c9f9b79
Package PoisoningPyPI2026-07-21
defi-kit@2.1.1 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
42e42f69b64ea9b08fcc977feb43c686
Package Poisoningnpm2026-07-21
requestor-util@99.9.1 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
56fbc66f56f39b1ec620ec816ad1eb5a
Package Poisoningnpm2026-07-21
commonweb-card@99.9.1 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
4206708f0c601284cd3f8a44b26e4356
Package Poisoningnpm2026-07-21
commonweb-moneymovement@99.9.1 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
210fdb7f189569d36427e8620860f743
Package Poisoningnpm2026-07-21
commonweb-rewards@99.9.1 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
800c5cf39fbda5d021d156b8569d309c
Package Poisoningnpm2026-07-21
commonweb-wallet@99.9.1 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
fcf92cfd65e5b7067bad8c4ec561d1c3
Package Poisoningnpm2026-07-21
consumerweb-calurls@99.9.1 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
75e604597284db018308594fa5da8352
Package Poisoningnpm2026-07-21
signzy-field-level-encrypter@12.9.13 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
f960516e9c9b68d232f9ef025f6e86c7