modelcontextprotocol prompt injection through unfiltered instructions leading to hijacking of the model context
The defect stems from the description field returned by the server in interface responses lacking content validation and security boundary constraints. An attacker can craft a request carrying malicious override statements to poison this field directly. When public caching is enabled, the poisoned data is persisted by intermediate proxy nodes and broadcast to other users. After parsing, victim clients concatenate the raw text unconditionally into the large model system prompt, breaking the security isolation mechanism and leading to arbitrary instruction execution and remote takeover of model behavior logic.
Component
modelcontextprotocol is a standardized communication framework for interaction between large language models and external tools. Its architecture uses…
Type
Improper Neutralization of Special Elements used in a Command ('Command Injection') (CWE-77)
It is recommended that the development team apply strict input filtering and length limits to received external description data, deploy semantic detection to identify anomalous override patterns, and establish a trusted content isolation zone on the client side that clearly distinguishes third-party input from the core system prompt through metadata tagging. Cache distribution policy should also be reviewed to close off cross-tenant data poisoning paths.
CSSA Exclusive Early Warning
10.0 Critical
Semantica data ingestion missing destination validation leading to server-side request forgery and unauthorized access to internal resources
An attacker can use the unprotected network request interface to submit a maliciously crafted feed address parameter to the target server, causing the underlying module to issue an unfiltered HTTP call directly. Because the code lacks protocol allowlist validation and internal address resolution interception, and automatic redirection is enabled by default, the malicious request can cross the network boundary and reach internal infrastructure or cloud metadata endpoints. The defect allows an attacker to probe private network topology beyond their privileges, steal sensitive configuration information or impersonate internal service identities, resulting in failure of system boundary isolation and loss of data confidentiality.
Component
Semantica is a data processing framework for multi-source information aggregation. Its core architecture uses a modular design supporting automated cr…
It is recommended to perform strict domain resolution validation before issuing network requests, disable automatic redirection and configure a protocol allowlist. Interception rules for internal address ranges should also be added, and all external links routed through a unified security gateway for filtering, ensuring the destination always remains within the public internet range.
CVE Intelligence
2
CVE-2026-73299
CVSS
10.0 Critical
2026-08-13
Prompty Nunjucks Template Injection Leading to Remote Code Execution
In Prompty prior to versions 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer places no restriction on JavaScript member access when evaluating untrusted .prompty template bodies (CWE-94). An attacker-controlled template can traverse constructor and prototype properties to execute arbitrary JavaScript in the host Node.js process. The vulnerability affects all Prompty users who have not updated to 0.1.5 or 2.0.0-beta.5. An attacker can trigger it with a crafted .prompty file, leading to remote code execution, and it can be exploited over a remote network with no user interaction.
Component
Prompty is a Markdown file format (.prompty) for large language model prompts, designed to simplify prompt engineering workflows.
Risks
Complete system control: An attacker can execute arbitrary JavaScript in the host Node.js process and thereby fully control the system running it
Remote code execution: With a NETWORK attack vector and LOW complexity, an attacker can launch the attack remotely with no local access
High impact scope: The CVSS score shows HIGH impact to confidentiality, integrity and availability with a CHANGED scope, meaning the attack may break the original privilege boundary
Immediately upgrade Prompty to 0.1.5 or 2.0.0-beta.5 or later
Avoid loading or rendering .prompty template files from untrusted sources
Enable strict security policy in the Node.js environment to restrict access to constructor and prototype properties
CVE-2026-73294
CVSS
9.9 Critical
2026-08-13
Semaphore UI OS Command Injection Leading to Remote Code Execution
In Semaphore UI prior to versions 2.18.17 and 2.19.5-beta2, repository git_url handling contains an operating system command injection (CWE-78) security flaw. An attacker can pass a controllable --upload-pack option to CmdGitClient.GetLastRemoteCommitHash through the POST /api/project/{id}/repositories endpoint or scheduled commit-hash polling, executing arbitrary OS commands in the Semaphore server process. The vulnerability allows users with project Manager or Owner permissions to achieve remote code execution, seriously threatening server security. It affects all Semaphore UI users who have not updated to 2.18.17 or 2.19.5-beta2. An attacker needs project Manager or Owner permissions to trigger it; exploitation is easy and requires no additional user interaction.
Component
Semaphore UI is a web interface for managing DevOps tooling, designed to simplify management and execution of CI/CD workflows.
Risks
From standard user to administrator: If the victim runs the Semaphore service with elevated privileges, the attacker gains the same privileges
Complete system control: An attacker can execute arbitrary code on the server, and depending on service privileges, install programs, view/modify/delete data or create new accounts with full privileges
Remote code execution: By crafting a malicious git_url parameter, an attacker can execute system commands directly in the server process with no additional interaction
Immediately upgrade Semaphore UI to 2.18.17 or 2.19.5-beta2 or later
Review and restrict permission assignment for project Manager and Owner roles
Monitor logs for anomalous command execution in server processes
Package Poisoning
5
Package Poisoning
npm2026-08-13
internallib_v392@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
e19471497b2a83dc20406e2a9b2e2d66
Package Poisoning
npm2026-08-13
bcs-compact@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
8fb8867206fd2c0caaa55df3dab765b9
Package Poisoning
npm2026-08-13
sui-gql@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
273e0c688b29ea0de9e5427a9238e080
Package Poisoning
npm2026-08-13
svelte-kit-vim@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
2d4e688d9982022259ec8bf675e29a47
Package Poisoning
npm2026-08-13
internallib_v756@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.