CSSA Exclusive Early Warning10.0 Critical
hermes-agent prompt injection forging privileged instructions leading to loss of control over model behavior
The vulnerability originates in the relay redirection channel, which uses static plaintext markers with no cryptographic provenance verification. An attacker only needs to enter specific contextual keywords during normal interaction to trigger the model's own inference, after which the large language model autonomously constructs disguised markers wrapping fabricated content during generation. This defect leaves the runtime unable to distinguish genuine external injection from model hallucination output, causing the system to misjudge forged text as a high-priority user instruction and execute it directly. Affected sessions face instruction override beyond authorization, context pollution and forced deviation of business processes.
Component
hermes-agent is an autonomous agent runtime framework for large language model interaction. Its core architecture is built on structured message flow…
Type
Injection (CWE-74)
Repo
Remediation- It is recommended to adopt a structurally decoupled approach that encapsulates control instructions as a standard role message stream, introduce dynamic token signing to verify provenance authenticity, strengthen boundary isolation for system prompts, and configure strict input filtering and context validation rules to block illegitimate content injection.
CVE-2026-68079CVSS 9.8 Critical2026-08-06
Apache CXF Authorization Code Replay Leading to Authentication Bypass
In Apache CXF's DefaultEncryptingCodeDataProvider, a defect in the removeCodeGrant implementation allows a captured authorization code to be redeemed an unlimited number of times, violating the RFC requirement that an authorization code must not be used more than once. The vulnerability affects CXF before 3.6.12, 4.2.0 before 4.2.3, and 4.0.0 before 4.1.8. An attacker can exploit it remotely over the network with no user interaction and low attack complexity, potentially causing high confidentiality, integrity and availability impact.
Component
Apache CXF is an open-source web services framework supporting multiple standards including SOAP, REST and OAuth, widely used for service integration in enterprise applications.
Risks
- Authentication bypass: An attacker can capture and replay an authorization code to bypass the normal authentication flow and illegitimately obtain user identity tokens
- Complete system control: Once authentication succeeds, the attacker can use the acquired privileges to reach protected resources and perform arbitrary operations, resulting in data disclosure or tampering
- No user interaction required: The vulnerability can be triggered remotely over the network; the attacker needs no additional action from the user
Source
Remediation- Immediately upgrade Apache CXF to 4.2.3, 4.1.8 or 3.6.12 or later
- Monitor OAuth authorization code usage logs to detect anomalous replay behavior
- Enforce strict session management and token invalidation, limiting the lifetime of authorization codes
CVE-2026-48170CVSS 9.8 Critical2026-06-23
libxml2 xmlOutputBufferWriteString Heap Buffer Overflow Leading to Remote Code Execution
A heap buffer overflow exists in the xmlOutputBufferWriteString function in xmlIO.c in libxml2. When processing input containing certain format strings, an attacker may trigger the vulnerability with crafted data, causing memory corruption and potentially arbitrary code execution. libxml2 contains a memory corruption vulnerability when processing XML input of a particular form, which an attacker can trigger with crafted XML data, leading to remote code execution or service disruption. The vulnerability affects all libxml2 users without the patch applied, including the many applications and services that depend on the library. An attacker only needs to induce the target to process a crafted XML file to exploit it, requiring no user interaction and allowing remote control.
Component
libxml2 is a C library for parsing XML documents, widely used across open-source software and operating systems.
Risks
- From standard user to administrator: If the victim runs an application depending on libxml2 with administrative privileges, the attacker gains the same privileges
- Complete system control: An attacker can execute arbitrary code on the victim system, and depending on user privileges, install programs, view/modify/delete data or create new accounts with full privileges
- No user interaction required: Through drive-by compromise (T1189), a user only needs to process a malicious XML file to trigger the vulnerability, with no additional interaction
Source
Remediation- Monitor logs for anomalous memory access behavior
- Enable sandbox isolation for the runtime environment
- Block loading of XML data from untrusted sources
Package Poisoningnpm2026-08-07
@junyoung-kim/reins@0.1.6 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
317b894ae24986a803fd567391a0b7cc
Package Poisoningnpm2026-08-07
aitable-workflow-server@9.9.9 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
691aea4a5402e292a04ae37bf65d6c0d
Package Poisoningnpm2026-08-07
remote-claude-daemon@0.5.2 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
4e763b044c3c890ff173123bd10d4dae
Package Poisoningnpm2026-08-07
shadowx-fca@10.0.0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
60cf8fbd522f660cf2d556952840d70d
Package Poisoningnpm2026-08-07
zyr-agent@1.6.2 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
94de55590d251ab0643e27306de08be4
Package Poisoningnpm2026-08-07
weight2loss@1.0.5 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
9a35821cd933aadf314e2ae0d1759407
Package Poisoningnpm2026-08-08
aclade-agent@1.0.4 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
01a24c061455e651a67a3390cff9d7d7
Package Poisoningnpm2026-08-08
agenthub-ai@0.20.1 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
fcf6d8d357322b439bb0b4a99e5d8e84
Package Poisoningnpm2026-08-08
w-screenctl@1.0.6 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
01bab44ca56083e8d94b1d7857dd0f68
Package Poisoningnpm2026-08-08
@depup/astro@7.1.3-depup.2 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
f95bc3a7cf3750ed2bf843956dad482a
Package Poisoningnpm2026-08-08
@depup/aws-sdk__credential-provider-process@3.972.66-depup.0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
1a87ed22cc11b8323e93e02cc1998b9c
Package Poisoningnpm2026-08-08
@mrbenty8jf1p9y5/oidc-bind-canary@0.0.3 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
6f66c434e099c5731cd1eceb38ebccef
Package Poisoningnpm2026-08-08
map-streak-kit@1.0.0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
c2d2148a6ccca8528cbc3816c9c337a5