NEWSkillSec — elevating AI Skills security from malware detection to capability auditingSkillSecLearn more →
← Back to Intel Center
SECURITY INTEL · DAILY
Link copiedRSS

2026-07-23 Daily Security Intelligence

3 itemsTop severity 10.0 (Critical)CSSA 1 · CVE 1 · Poisoning 1

CSSA Exclusive Early Warning1

CSSA Exclusive Early Warning10.0 Critical

LocalAI service code injection bypassing sandbox protection leading to remote command execution

An attacker can reach the unauthenticated fine-tuning task interface with a crafted HTTP request and inject malicious inline Python code into the reward function parameter. The server passes this code to the Python interpreter without security filtering, and because the built-in sandbox allowlist mechanism is flawed by design, the attacker can use class inheritance chain introspection to break out of the privilege restriction and invoke underlying operating system modules to execute arbitrary commands. The vulnerability is network-reachable and requires no credentials to trigger; affected instances face complete server compromise and malicious tampering with business logic.

Component
LocalAI is an open-source platform for locally deployed large language model inference and fine-tuning. Its architecture uses a modular backend design…
Type
Code Injection (CWE-94)
Repo
Remediation
  • It is recommended to abandon the allowlist-based interpreted sandbox and instead run untrusted code in a separate subprocess or container with isolation, alongside strict network and file access controls. Interface authentication and input filtering should also be enforced to close the script injection path entirely.

CVE Intelligence1

CVE-2026-60366CVSS 10.0 Critical2026-07-23

Oracle Platform Security for Java Remote Code Execution Vulnerability Leading to Complete Takeover

In the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars), the supported versions affected are 12.2.1.4.0 and 14.1.2.0.0. This easily exploitable vulnerability allows an unauthenticated attacker with HTTP network access to compromise Oracle Platform Security for Java. While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change). Successful exploitation can result in complete takeover of Oracle Platform Security for Java. The CVSS 3.1 base score is 10.0 (confidentiality, integrity and availability impacts). The vulnerability affects all unpatched Oracle Platform Security for Java users, including environments deployed on versions 12.2.1.4.0 and 14.1.2.0.0. An attacker only needs network access to trigger it, requiring no authentication and allowing remote control.

Component
Oracle Platform Security for Java is part of Oracle Fusion Middleware, providing security services for the Java platform and involving the Centralized Thirdparty Jars component.
Risks
  • Complete system control: An attacker can execute arbitrary code on the victim system, and depending on user privileges, install programs, view/modify/delete data or create new accounts with full privileges
  • No user interaction required: The vulnerability triggers through HTTP network access alone, with no user interaction
  • Scope change impact: Although the vulnerability resides in Oracle Platform Security for Java, attacks may significantly affect other products
Source
Remediation
  • Monitor logs for anomalous HTTP access behavior
  • Enable network isolation for the runtime environment
  • Block HTTP requests from untrusted sources

Package Poisoning1

Package Poisoningnpm2026-07-23

app-data-ist@2.1.6 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
05188812970b290fd007a5527aa46c3b