CSSA Exclusive Early Warning10.0 Critical
crewAI framework deserialization of untrusted data enabling attackers to achieve remote code execution
An attacker can exploit unvalidated deserialization logic in the framework's internal file handling module by crafting a serialized object file carrying a malicious payload and inducing the system to load it. When the target environment reads the file, the underlying interpreter directly instantiates the preset reverse call chain, breaking out of the sandbox isolation boundary and injecting and executing arbitrary instructions in the host context. This flaw is primarily exposed through shared storage interaction or external configuration import, leaving affected services facing threats such as process hijacking and theft of sensitive credentials.
Component
crewAI is a distributed agent orchestration framework built on Python. Its core architecture uses a modular design to support collaborative task sched…
Type
Deserialization of Untrusted Data (CWE-502)
Repo
Remediation- It is recommended that development teams abandon native deserialization functions and switch entirely to structured data exchange formats for persistence. If the business genuinely depends on object reconstruction, enforce a strict allowlist validation policy and restrict the range of importable modules, verify integrity signatures on input sources, and use runtime sandbox technology to block illegal code paths, fundamentally eliminating the risk of untrusted data entering the core execution stack.
CVE-2026-50736CVSS 9.8 Critical2026-07-29
pglogical Queue Mechanism SQL Injection Leading to Superuser Privilege Escalation
In a default installation, pglogical's queue mechanism is used to pass out-of-band commands (such as replicated DDL) from the publisher to the subscriber, and executes the message payload at the subscriber with the privilege level of the apply worker, which is equivalent to a PostgreSQL superuser. An attacker acting as a publisher can send a carefully crafted queue message that causes arbitrary SQL to be executed as superuser on the subscriber, escalating from a role permitted to use pglogical to full superuser privileges and breaking isolation between tenants in shared deployments. To exploit this, the attacker must be able to point a subscription at an endpoint they control. In default installations this requires privileges normally held only by superusers, so the issue primarily affects hosted deployments that have delegated the ability to create subscriptions to non-superuser roles.
Component
pglogical is a logical replication extension for PostgreSQL used to replicate data and schema changes between databases.
Risks
- From standard user to administrator: If the victim runs the browser with administrative privileges, the attacker gains the same privileges
- Complete system control: An attacker can execute arbitrary code on the victim system, and depending on user privileges, install programs, view/modify/delete data or create new accounts with full privileges
- No user interaction required: Through drive-by compromise (T1189), a user only needs to visit a malicious page to trigger the vulnerability, with no additional interaction
Source
Remediation- Monitor logs for anomalous memory access behavior
- Enable sandbox isolation for the runtime environment
- Block Canvas script loading from untrusted sources
CVE-2026-16498CVSS 10.0 Critical2026-07-29
terraform-mcp-server Cross-Tenant Credential Reuse Leading to Remote Code Execution
In terraform-mcp-server prior to version 1.1.0, the streamable-HTTP stateless transport mode contains a cross-tenant credential reuse security flaw (CWE-488). The vulnerability means one user's Terraform token may be used to perform tool calls on behalf of subsequent users, creating a risk of session data being exposed to the wrong session. terraform-mcp-server fails to properly isolate credential contexts across tenants when handling stateless HTTP requests, and an attacker can trigger the vulnerability with a specific request, leading to unauthorized tool call execution. The vulnerability affects all terraform-mcp-server users who have not updated to 1.1.0, including deployments using the streamable-HTTP transport mode. An attacker needs only network access to exploit it, without complex preconditions and with remote control.
Component
terraform-mcp-server is an MCP (Model Context Protocol) server component for Terraform, supporting tool invocation and state management through a stateless transport mode.
Risks
- From standard user to administrator: If the victim runs terraform-mcp-server with elevated privileges, the attacker gains the same privileges
- Complete system control: An attacker can execute arbitrary tool calls on the victim system, and depending on user privileges, view/modify/delete data or perform sensitive operations
- No user interaction required: The vulnerability triggers directly through a network request; the attacker can exploit the credential reuse mechanism without luring the user into any interaction
Source
Remediation- Immediately upgrade terraform-mcp-server to version 1.1.0 or later
- Monitor logs for anomalous tool invocations and credential usage behavior
- Implement strict tenant isolation and session validation policies
Package Poisoning2026-07-29
@ flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
742d27d4345f7af96e7902478f0dfd93
Package Poisoning2026-07-29
@ flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
760ccf85a789655d380d7e11faa27a51
Package Poisoning2026-07-29
@ flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
756389dbd590619cf7e06bf772a2f2d1
Package Poisoning2026-07-29
@ flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
4a97f24c288627aa3b70086a057a28b1
Package Poisoning2026-07-29
@ flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
2fb1f2f1f5b102fd96d4574481a1c715
Package Poisoning2026-07-29
@ flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
32ad9e11f8321a3366dbc47bffb0ce7a
Package Poisoning2026-07-29
@ flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
a556bd7055f71d8eacc8f593abbc8705
Package Poisoning2026-07-29
@ flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
fe93bffae00ed1f3fac1c387262bfd65