CSSA Exclusive Early Warning10.0 Critical
TencentDB-Agent-Memory unauthorized access and argument injection leading to privilege abuse and internal network probing
An attacker can exploit the absence of authentication middleware on management interfaces to craft HTTP requests that directly alter tenant rate limiting policies or trigger instance data purging. When the administrator key is left empty, the authorization logic passes all requests by default. In addition, the knowledge acquisition module relies solely on static regular expression matching of hostnames when parsing remote repository addresses, performing no reverse DNS resolution and applying no allowlist filtering to input parameters. This allows an attacker to bypass security policy through DNS rebinding and concatenate malicious command-line options, ultimately achieving unauthorized privilege abuse, denial of service and illegitimate probing of internal cloud metadata and service endpoints.
Component
This component provides core data routing and cache acceleration for distributed knowledge base and memory agent systems. Its architecture uses a modu…
Type
Missing Authentication for Critical Function (CWE-306)
Repo
Remediation- It is recommended to apply mandatory authentication middleware uniformly at the critical business routing layer so that every sensitive interface completes credential verification, and to enforce deny-by-default behavior when configuration is missing. Dynamic domain resolution should be introduced before any network request is issued, with strict comparison of the target IP's address range, and parameters passed to third-party libraries should undergo strict format validation and special character escaping to close off command injection paths entirely.
CSSA Exclusive Early Warning10.0 Critical
hexstrike-ai unauthenticated arbitrary code execution leading to complete server takeover
An attacker can send an HTTP POST request containing malicious Python source code to the target server's /api/python/execute endpoint. Lacking any authentication, the route accepts the payload directly, writes it to a temporary file and then invokes the underlying subprocess interpreter to run it. Because no sandbox isolation or input validation is applied, the malicious script executes with system privileges equivalent to the server process, supporting multi-stage logic orchestration and covert exfiltration. Affected hosts face the full range of threats including theft of core data, tampering with configuration files and implantation of persistent backdoors, severely disrupting business continuity.
Component
hexstrike-ai is an automated network testing and data analysis platform built on the Flask framework. Its core uses a modular microservice architectur…
Type
Code Injection (CWE-94)
Repo
Remediation- It is recommended to remove any non-essential external code execution interface. Where one must be retained, strong authentication and fine-grained access control are mandatory, along with a runtime sandbox that restricts network communication and filesystem read/write permissions, and an allowlist policy that strictly filters incoming script content — ensuring every dynamic execution happens inside an isolated and controllable security boundary.
CVE-2026-69264CVSS 10.0 Critical2026-08-05
Flowise CSVAgent Code Injection Leading to Remote Code Execution
In Flowise prior to version 3.1.3, the CSVAgent component lacks effective filtering of the csvFile data URI fragment, resulting in code injection (CWE-94). Attacker-controlled malicious data is interpolated directly into a Python source template and executed through Pyodide. Because the js bridge that Pyodide enables by default exposes eval and dynamic import in a Node.js environment, an attacker can break out of Python string constraints and invoke Node.js built-in modules such as fs and child_process, performing arbitrary file I/O or operating system commands as the Flowise process. The vulnerability affects all Flowise users who have not updated to 3.1.3. A workspace user with chatflows:create or agentflows/chatflows update permission can plant a malicious CSV Agent node, and once that chatflow is exposed through POST /api/v1/prediction/:id, any unauthenticated request can trigger remote code execution on the host.
Component
Flowise is a low-code open-source LLM development platform that lets users build AI chatbots and workflows through a visual interface.
Risks
- Complete system control: An attacker can execute arbitrary code on the victim system, and depending on Flowise process privileges, install programs, view/modify/delete data or create new accounts with full privileges
- Exploitation without authentication: Once a malicious chatflow is exposed, any unauthenticated request can trigger the vulnerability with no additional interaction
- Privilege escalation: If the Flowise process runs with elevated privileges, the attacker obtains the same level of access
Source
Remediation- Immediately upgrade Flowise to version 3.1.3 or later
- Strictly restrict permissions to create and update chatflows and agentflows
- Apply strict access control and authentication to the /api/v1/prediction/:id endpoint
CVE-2026-25289CVSS 9.6 Critical2026-08-05
Qualcomm NAN Service Discovery Frame Memory Corruption Leading to Remote Code Execution
In affected Qualcomm devices, the NAN (Neighbor Awareness Networking) service discovery module contains a stack buffer overflow (CWE-121) when processing the device capability extension attribute in certain NAN service discovery frames carrying an invalid length value. The defect causes memory corruption, threatening process stability and security. Qualcomm devices contain a memory corruption vulnerability in specific NAN communication scenarios that an attacker can trigger with crafted NAN frames, leading to remote code execution or service disruption. The vulnerability affects all unpatched Qualcomm devices, including wireless communication modules supporting NAN. An attacker only needs to send a crafted packet within the adjacent network to exploit it, requiring no user interaction and allowing remote control.
Component
Qualcomm is a leading wireless communication technology company whose chipsets are widely used in smartphones, IoT devices and wireless communication infrastructure, supporting advanced wireless protocols including NAN.
Risks
- From standard user to administrator: If the victim device runs the related service with elevated privileges, the attacker gains the same privileges
- Complete system control: An attacker can execute arbitrary code on the victim device, and depending on user privileges, install programs, view/modify/delete data or create new accounts with full privileges
- No user interaction required: By broadcasting malicious NAN frames on the adjacent network, an attacker triggers the vulnerability without any interaction from the target user
Source
Remediation- Monitor logs for anomalous NAN service discovery frames and memory access behavior
- Enable strict input validation and sandbox isolation for wireless communication modules
- Block NAN service discovery frames from untrusted sources or with malformed structure
Package Poisoningnpm2026-08-05
twork-data-services-aggregator-api-v2-data-view-company-company-profile-mf-data-transformer@20.5.3 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
afe563453b500a7f1527d5d897db9b2b
Package Poisoningnpm2026-08-05
platform-ui-codemods@20.6.7 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
e41e83a12513ee7c447a74460cb118d8
Package Poisoningnpm2026-08-05
platform-ui-island@20.5.9 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
52333d36fc164e45d41fbb450773b812
Package Poisoningnpm2026-08-05
sextant-cli-linux-arm64@0.0.1-rc29 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
6f4ff0f8298494bd240cb31c6e50551d
Package Poisoningnpm2026-08-05
specials-mvno-client@20.9.8 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
22c8a2f411e37cf68fde62f10513b165
Package Poisoningnpm2026-08-05
tinkoff-ui-action@20.5.7 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
07a92db2657e4e4dc5a6340deba3ab33
Package Poisoningnpm2026-08-05
alipclutch-baileys@8.6.59 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
4394ca9876ff3cf9c7f801ec0765ceec
Package Poisoningnpm2026-08-05
bip32-js@1.0.0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
6e5b1c4ee97b404bdf10442c47bc5fa0