CSSA Exclusive Early Warning9.6 Critical
Claude Code command injection through unescaped environment variables leading to arbitrary code execution
The vulnerability originates in the Bash toolchain emitting environment variable key-value pairs as plain concatenated text when generating the command execution prefix, without strict syntactic escaping. An attacker can preconfigure malicious environment parameters containing shell metacharacters such as newlines and braces, causing multi-line assignment statements to be parsed as independent executable script fragments. The defect breaks the context isolation boundary of the original command stream, leaving all subsequent tool invocations in a syntactically broken state while the malicious payload executes first as a leading instruction. Affected instances face session-level process hijacking, allowing an attacker to break the privilege boundary and obtain full host control, leading to disclosure of critical business data and abuse of compute resources.
Component
Claude Code is an interactive terminal development assistant built on large language models. Its core architecture integrates an automated Bash execut…
Type
OS Command Injection (CWE-78)
Repo
Remediation- It is recommended to apply strict context-aware encoding before passing dynamic parameters to the interpreter, using escaping functions specific to the target shell for special characters. Input validation and structured serialization should also be introduced to block metacharacter parsing paths and preserve safe isolation during command assembly.
CSSA Exclusive Early Warning9.9 Critical
Hindsight missing authorization allows privilege-exceeding knowledge base calls leading to multi-tenant data disclosure and tampering
The defect stems from the knowledge base route handler not connecting the request context into the operation validation chain, causing the underlying engine methods to skip authorization checks before executing read and write logic. An attacker who merely obtains a target identifier can craft arbitrary HTTP requests reaching the affected paths, exploiting the logical gap between tenant authentication and resource ownership verification to probe beyond their privileges. The affected surface spans the full set of endpoints including knowledge node traversal, content extraction, directory creation and entry deletion, allowing unauthorized parties to read sensitive inference data of neighboring tenants laterally and tamper with the structured storage topology, undermining data boundary integrity in multi-instance deployments.
Component
Hindsight is a knowledge base management and memory model processing engine for multi-tenant architectures. Its core uses a modular extension design a…
Type
Missing Authorization (CWE-862)
Repo
Remediation- It is recommended to inject mandatory authorization middleware uniformly at the global routing layer so that every state-changing and data query endpoint passes strict resource ownership validation. Developers should complete the operation enumeration mapping table, binding business actions to permission policies, and intercept unauthorized call chains before the controller entry point, eliminating dead code branches entirely.
CVE-2026-72899CVSS 10.0 Critical2026-08-11
Metabase Unauthenticated SQL Injection Leading to Remote Code Execution
In Metabase, publicly shared cards and dashboards mishandle field filter (dimension) parameters, resulting in SQL injection (CWE-89). An unauthenticated attacker can craft a malicious request that injects arbitrary SQL statements through the exposed field filter parameter, threatening database integrity and confidentiality. Metabase contains a serious logic flaw in specific sharing scenarios that an attacker can trigger through a public link, leading to data disclosure, tampering or remote code execution. The vulnerability affects all unpatched Metabase deployments, particularly environments with public sharing enabled and dimension parameters exposed. An attacker can launch the attack remotely without any authentication, requiring no user interaction and gaining full control of the backend database.
Component
Metabase is an open-source data analytics and visualization platform that lets users query databases and build dashboards through a simple interface.
Risks
- From standard user to administrator: If the attacker obtains database administrator privileges through this vulnerability, they can fully control the backend data system
- Complete system control: An attacker can execute arbitrary database commands through SQL injection, and depending on database privileges, view/modify/delete sensitive data or execute system commands
- No user interaction required: Through a public sharing link, an attacker can send malicious requests directly to the Metabase server with no click or interaction from the target user
Source
Remediation- Review and disable all unnecessary publicly shared cards and dashboards
- Remove or strictly limit exposure of field filter (dimension) parameters in publicly shared content
CVE-2026-72590CVSS 9.8 Critical2026-08-10
crontab-ui OS Command Injection Leading to Remote Code Execution
In alseambusher/crontab-ui 0.4.2 and earlier, the /crontab endpoint lacks strict input validation on the env_vars parameter, resulting in an operating system command injection (CWE-93) security flaw. An attacker can send a carefully crafted GET request containing URL-encoded newlines to inject arbitrary cron job entries and thereby execute arbitrary commands on the target system. The vulnerability affects all crontab-ui users who have not updated to a patched version. An attacker can trigger it remotely without authentication, exploitation is easy, and it can result in complete system compromise.
Component
crontab-ui is an open-source web interface for managing cron scheduled tasks, designed to simplify configuration and management of scheduled jobs on Linux systems.
Risks
- From standard user to administrator: If the victim runs the service as root or a high-privilege user, the attacker gains the same privileges
- Complete system control: An attacker can execute arbitrary code on the victim system, and depending on user privileges, install programs, view/modify/delete data or create new accounts with full privileges
- No user interaction required: The vulnerability triggers directly through a crafted request with no user interaction, and can be exploited at scale by automated scripts
Source
Remediation- Intercept anomalous GET requests to the /crontab endpoint at the firewall or WAF layer, particularly parameters containing special characters or encoded newlines
- Restrict access to the service, allowing only trusted IP addresses to reach the management interface
Package Poisoningnpm2026-08-11
@sqlite-labs/createsql@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
388bd21fe5b84558cd480ad2ae128ce9
Package Poisoningnpm2026-08-11
@sqlite-labs/nodesql@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
4f0aa1ea5c032a52a81ac97c349cfdc5
Package Poisoningnpm2026-08-11
@sqlite-prime/createsql@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
729dcf50d493542f36f3e878c22b1c1f
Package Poisoningnpm2026-08-11
@sqlite-prime/nodesql@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
a60a3f4c43905b47e24158c6fb407f06
Package Poisoningnpm2026-08-11
@sqlite-table/schema-generator@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
484a4a21a9c9c644764d0a6d2099a35c
Package Poisoningnpm2026-08-11
@sqlite-table/sql-creator@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
3f53290b185bc2d7b9e6f1e807d9832a
Package Poisoningnpm2026-08-11
kit-map-streak@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
bfa6006682048ac899b4a3d0563227a5
Package Poisoningnpm2026-08-11
svelte-kit-streak@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
36b308c13f71fef9acbb323b5ff0da38
Package Poisoningnpm2026-08-11
tailwind-elements-ui@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
a09860afd8f0c70281f5cd2bb1ca64c4