CSSA Exclusive Early Warning10.0 Critical
modelcontextprotocol prompt injection through unfiltered instructions leading to hijacking of the model context
The defect stems from the description field returned by the server in interface responses lacking content validation and security boundary constraints. An attacker can craft a request carrying malicious override statements to poison this field directly. When public caching is enabled, the poisoned data is persisted by intermediate proxy nodes and broadcast to other users. After parsing, victim clients concatenate the raw text unconditionally into the large model system prompt, breaking the security isolation mechanism and leading to arbitrary instruction execution and remote takeover of model behavior logic.
Component
modelcontextprotocol is a standardized communication framework for interaction between large language models and external tools. Its architecture uses…
Type
Improper Neutralization of Special Elements used in a Command ('Command Injection') (CWE-77)
Repo
Remediation- It is recommended that the development team apply strict input filtering and length limits to received external description data, deploy semantic detection to identify anomalous override patterns, and establish a trusted content isolation zone on the client side that clearly distinguishes third-party input from the core system prompt through metadata tagging. Cache distribution policy should also be reviewed to close off cross-tenant data poisoning paths.
CSSA Exclusive Early Warning10.0 Critical
Semantica data ingestion missing destination validation leading to server-side request forgery and unauthorized access to internal resources
An attacker can use the unprotected network request interface to submit a maliciously crafted feed address parameter to the target server, causing the underlying module to issue an unfiltered HTTP call directly. Because the code lacks protocol allowlist validation and internal address resolution interception, and automatic redirection is enabled by default, the malicious request can cross the network boundary and reach internal infrastructure or cloud metadata endpoints. The defect allows an attacker to probe private network topology beyond their privileges, steal sensitive configuration information or impersonate internal service identities, resulting in failure of system boundary isolation and loss of data confidentiality.
Component
Semantica is a data processing framework for multi-source information aggregation. Its core architecture uses a modular design supporting automated cr…
Type
SSRF (CWE-918)
Repo
Remediation- It is recommended to perform strict domain resolution validation before issuing network requests, disable automatic redirection and configure a protocol allowlist. Interception rules for internal address ranges should also be added, and all external links routed through a unified security gateway for filtering, ensuring the destination always remains within the public internet range.
CVE-2026-73299CVSS 10.0 Critical2026-08-13
Prompty Nunjucks Template Injection Leading to Remote Code Execution
In Prompty prior to versions 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer places no restriction on JavaScript member access when evaluating untrusted .prompty template bodies (CWE-94). An attacker-controlled template can traverse constructor and prototype properties to execute arbitrary JavaScript in the host Node.js process. The vulnerability affects all Prompty users who have not updated to 0.1.5 or 2.0.0-beta.5. An attacker can trigger it with a crafted .prompty file, leading to remote code execution, and it can be exploited over a remote network with no user interaction.
Component
Prompty is a Markdown file format (.prompty) for large language model prompts, designed to simplify prompt engineering workflows.
Risks
- Complete system control: An attacker can execute arbitrary JavaScript in the host Node.js process and thereby fully control the system running it
- Remote code execution: With a NETWORK attack vector and LOW complexity, an attacker can launch the attack remotely with no local access
- High impact scope: The CVSS score shows HIGH impact to confidentiality, integrity and availability with a CHANGED scope, meaning the attack may break the original privilege boundary
Source
Remediation- Immediately upgrade Prompty to 0.1.5 or 2.0.0-beta.5 or later
- Avoid loading or rendering .prompty template files from untrusted sources
- Enable strict security policy in the Node.js environment to restrict access to constructor and prototype properties
CVE-2026-73294CVSS 9.9 Critical2026-08-13
Semaphore UI OS Command Injection Leading to Remote Code Execution
In Semaphore UI prior to versions 2.18.17 and 2.19.5-beta2, repository git_url handling contains an operating system command injection (CWE-78) security flaw. An attacker can pass a controllable --upload-pack option to CmdGitClient.GetLastRemoteCommitHash through the POST /api/project/{id}/repositories endpoint or scheduled commit-hash polling, executing arbitrary OS commands in the Semaphore server process. The vulnerability allows users with project Manager or Owner permissions to achieve remote code execution, seriously threatening server security. It affects all Semaphore UI users who have not updated to 2.18.17 or 2.19.5-beta2. An attacker needs project Manager or Owner permissions to trigger it; exploitation is easy and requires no additional user interaction.
Component
Semaphore UI is a web interface for managing DevOps tooling, designed to simplify management and execution of CI/CD workflows.
Risks
- From standard user to administrator: If the victim runs the Semaphore service with elevated privileges, the attacker gains the same privileges
- Complete system control: An attacker can execute arbitrary code on the server, and depending on service privileges, install programs, view/modify/delete data or create new accounts with full privileges
- Remote code execution: By crafting a malicious git_url parameter, an attacker can execute system commands directly in the server process with no additional interaction
Source
Remediation- Immediately upgrade Semaphore UI to 2.18.17 or 2.19.5-beta2 or later
- Review and restrict permission assignment for project Manager and Owner roles
- Monitor logs for anomalous command execution in server processes
Package Poisoningnpm2026-08-13
internallib_v392@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
e19471497b2a83dc20406e2a9b2e2d66
Package Poisoningnpm2026-08-13
bcs-compact@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
8fb8867206fd2c0caaa55df3dab765b9
Package Poisoningnpm2026-08-13
sui-gql@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
273e0c688b29ea0de9e5427a9238e080
Package Poisoningnpm2026-08-13
svelte-kit-vim@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
2d4e688d9982022259ec8bf675e29a47
Package Poisoningnpm2026-08-13
internallib_v756@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
0b45ab31bfa952c0c1965765c5ab66a7