CSSA Exclusive Early Warning10.0 Critical
browser-use code injection through the Model Context Protocol leading to host privilege takeover
An attacker can send a request containing a malicious payload to the target system through the Model Context Protocol service endpoint. Because the interface layer implements no strict sandbox isolation or input validation, the incoming dynamic script is handed directly to the host environment for parsing and execution. This flaw allows a network-reachable external entity, or an AI agent that has been manipulated, to bypass normal access control and trigger arbitrary code execution in the target process. The security impact extends to full control of the host operating system, accompanied by the risk of pre-injected scripts hijacking active sessions, which can lead to illegitimate extraction of sensitive credentials and cookies from authenticated environments and subsequently to lateral movement and data leakage.
Component
browser-use is an open-source framework for automated browser operation and agent interaction. Its core architecture builds standardized service inter…
Type
Code Injection (CWE-94)
Repo
Remediation- It is recommended to apply strict allowlist filtering to input parameters, disable dynamic compilation and interpretation, deploy an independent sandbox on the server side to isolate the script execution context, and introduce static code analysis and runtime validation modules to block anomalous execution flows.
CVE-2026-69240CVSS 9.8 Critical2026-08-04
Sequelize Oracle Dialect SQL Injection Leading to Arbitrary SQL Expression Execution
In Sequelize prior to version 6.37.4, when the dialect is set to oracle, the escape function defined in sql-string.js contains a security flaw: if the input value begins with TO_TIMESTAMP or TO_DATE, the function returns the raw value without escaping single quotes, resulting in SQL injection (CWE-89). An attacker can inject arbitrary SQL expressions through application values, threatening database integrity and confidentiality. Sequelize contains a SQL injection vulnerability under specific Oracle dialect scenarios that an attacker can trigger with a crafted string, leading to data disclosure, tampering or remote code execution. The vulnerability affects all Sequelize users who have not updated to 6.37.4, particularly backend services using Oracle databases. An attacker can exploit it remotely over the network without complex preconditions.
Component
Sequelize is a powerful Node.js ORM supporting multiple database dialects, used to simplify database operations and data mapping.
Risks
- Complete data disclosure: An attacker can use SQL injection to read any sensitive information in the database, including user credentials and business data
- Data integrity damage: An attacker can modify or delete database records, causing business logic errors or data loss
- Remote code execution risk: Under certain configurations, SQL injection may escalate into server-side code execution and full control of the backend service
- Unauthenticated remote attack: An attacker only needs to send a crafted request to the vulnerable application endpoint, with no user interaction or credentials required
Source
Remediation- Immediately upgrade Sequelize to version 6.37.4 or later to fix the vulnerability
- Review query logic involving the Oracle dialect and avoid concatenating user input directly
- Deploy a web application firewall (WAF) to intercept common SQL injection patterns
CVE-2026-69085CVSS 10.0 Critical2026-08-03
SiYuan SQL Injection Allowing Database Content to Be Read and Modified
In SiYuan prior to v3.7.3, the /api/filetree/searchDocs endpoint concatenates the caller-supplied keyword parameter directly into a SQL statement without escaping or parameter binding, resulting in SQL injection (CWE-89). The endpoint is reachable with a publish RoleReader token, or without any authentication when publish mode is enabled and Publish.Auth.Enable is set to false. Because the statement executes on a read-write SQLite handle through a driver that supports stacked (semicolon-separated) statements, an attacker can read and modify the database content of every plaintext (unencrypted) notebook on the instance. The vulnerability affects all SiYuan users who have not updated to v3.7.3. An attacker can trigger it with a crafted request, leading to data disclosure or tampering.
Component
SiYuan is a privacy-first, self-hosted knowledge base application supporting block-level references, bidirectional links, outline mode and Markdown syntax.
Risks
- Complete data disclosure: An attacker can read the database content of every plaintext notebook on the instance, exposing sensitive information
- Data integrity damage: An attacker can modify database content, undermining the integrity and consistency of note data
- Unauthenticated attack: Under certain configurations (publish mode enabled with Publish.Auth.Enable set to false), an attacker can exploit the vulnerability with no authentication at all
Source
Remediation- Immediately upgrade SiYuan to v3.7.3 or later
- If an immediate upgrade is not possible, ensure Publish.Auth.Enable is set to true and restrict RoleReader token access
- Encrypt database content at rest to reduce plaintext exposure risk
CVE-2026-64827CVSS 9.8 Critical2026-08-03
Telenia TVox Authentication Bypass Leading to Unauthorized Access
In Telenia Software TVox 26.x through 26.5.3 and 24.x through 24.9.21, the set_env.php file contains an authentication bypass. The flaw originates in the redirectToLoginAdminIRequestHaveAccessToken() function, which derives the current page name from PHP_SELF and skips authentication when that value matches login_admin.php. An attacker can append /login_admin.php to the path of any target PHP script, causing the authentication check to pass and granting unauthorized access to every PHP script under the manager HTML directory. The vulnerability affects all Telenia TVox users who have not updated to a patched version. An attacker can exploit it remotely without authentication and directly obtain system administration privileges.
Component
Telenia TVox is software developed by Telenia Software, typically used in specific business management or communications scenarios, and includes a web-based administration interface.
Risks
- Unauthorized access to administrative functions: An attacker can bypass login verification and reach every PHP script under the manager HTML directory
- Complete system control: Because administrative scripts typically carry elevated privileges, an attacker may perform arbitrary operations such as viewing, modifying or deleting sensitive data
- No user interaction required: The attacker only needs to craft a specific URL request; no click or interaction from the target user is required
Source
Remediation- Configure access control rules at the web server level to restrict direct access to the manager directory
- Monitor web access logs for anomalous request paths containing the /login_admin.php suffix
Package PoisoningPyPI2026-08-04
instalogin1234@0.0.1 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
0ac3eb7cbdc5b53850ed1e9c7082c22b
Package Poisoningnpm2026-08-04
internallib_v524@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
535d7cf14203c4f714ae8b9c0c5eeee4
Package Poisoningnpm2026-08-04
internallib_v688@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
aa19e3bfc4be2ac9f6c8bc96ab60a85c