NEWSkillSec — elevating AI Skills security from malware detection to capability auditingSkillSecLearn more →
← Back to Intel Center
SECURITY INTEL · DAILY
Link copiedRSS

2026-08-14 ~ 08-16 Daily Security Intelligence

20 itemsTop severity 9.8 (Critical)CSSA 1 · CVE 2 · Poisoning 17

CSSA Exclusive Early Warning1

CSSA Exclusive Early Warning9.3 Critical

Firecrawl shared cookie jar leading to cross-tenant data leakage and distorted results

The vulnerability originates in a defect in secure request scheduler initialization: a single global cookie container is instantiated at module load and persists for the process lifetime, with no state isolation per request or task. An attacker can craft a collection request against a specific target domain that causes the target server to return a session credential, which is then written into the shared store and automatically attached to subsequent requests to the same domain from different tenants. This mechanism breaks context boundaries in multi-tenant environments, allowing a malicious user to reach protected resources of other accounts through residual session identifiers, while stale credentials also interfere with normal collection paths, corrupting authentication state at target sites and severely distorting returned data.

Component
Firecrawl is an open-source web data collection and processing engine built on the Node.js runtime. It uses a modular design for URL parsing, content…
Type
Improper Removal of Sensitive Information Before Storage or Transfer (CWE-212)
Repo
Remediation
  • It is recommended to restructure request scheduler state management so that sensitive credential storage is confined to a single request lifetime. Development should follow stateless design principles, avoiding server-side session residue, and use scope isolation to keep tenant contexts independent, closing off cross-request information contamination entirely.

CVE Intelligence2

CVE-2026-61969CVSS 9.3 Critical2026-08-13

Listdom Unauthenticated SQL Injection Leading to Database Disclosure

In Listdom 5.6.0 and earlier, the data processing module lacks strict filtering and escaping of input parameters, resulting in unauthenticated SQL injection (CWE-89). An attacker can send crafted malicious requests over the network without any authentication and manipulate backend database queries directly. The vulnerability affects all Listdom users who have not updated to a patched version. An attacker only needs to craft a specific HTTP request to trigger it, requiring no user interaction and allowing remote execution, potentially leading to sensitive data disclosure or loss of database integrity.

Component
Listdom is an open-source listing management and data presentation component widely used in web applications to display and manage structured data.
Risks
  • Complete database exposure: An attacker can read, modify or delete any data in the database, including user credentials and personal information
  • Remote code execution risk: Under certain database configurations, SQL injection may be escalated to execute system commands and take full control of the server
  • Unauthenticated attack: Because no authentication is required, an attacker can launch the attack directly from the internet without any legitimate account
Source
Remediation
  • Apply strict parameterized queries or prepared statements to all user input at the application layer
  • Deploy a web application firewall (WAF) to intercept common SQL injection patterns
CVE-2026-61967CVSS 9.8 Critical2026-08-13

miniorange otp verification Unauthenticated Privilege Escalation Leading to Remote Code Execution

In miniorange otp verification 5.5.1 and earlier, a permission validation defect in the authentication module results in unauthenticated privilege escalation (CWE-640). An attacker can escalate privileges without any authentication, threatening system integrity and security. The plugin contains a logic flaw in specific request handling scenarios that an attacker can trigger with a crafted request, leading to unauthorized access or remote code execution. The vulnerability affects all miniorange otp verification users who have not updated beyond 5.5.1, including WordPress deployments. An attacker only needs to send a crafted network request to the target server to exploit it, requiring no user interaction and allowing remote control.

Component
miniorange otp verification is an authentication plugin for strengthening website security, supporting one-time password (OTP) verification.
Risks
  • From standard user to administrator: If the victim runs the service with administrative privileges, the attacker gains the same privileges
  • Complete system control: An attacker can execute arbitrary code on the victim system, and depending on user privileges, install programs, view/modify/delete data or create new accounts with full privileges
  • No user interaction required: Through drive-by compromise (T1189), a user only needs to visit a malicious page to trigger the vulnerability, with no additional interaction
Source
Remediation
  • Monitor logs for anomalous privilege escalation behavior
  • Enable sandbox isolation for the runtime environment
  • Block OTP verification requests from untrusted sources

Package Poisoning17

Package Poisoningnpm2026-08-14

@kolbo/mcp@1.57.1 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
f12a2e18a52cd885f3f07b468ba5f52c
Package Poisoningnpm2026-08-14

@khaznatech/core@99.0.0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
86fe71379ee3ea89c8598b4c7d90da33
Package Poisoningnpm2026-08-14

eslint-generate-release@99.9.1 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
ad82b672bc81184df61c32a9e0d92b04
Package Poisoningnpm2026-08-14

resolve-audit@99.9.1 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
53948c1af6cffc380af7c5b954238934
Package Poisoningnpm2026-08-14

@secauditb20y/sec-test-r3b@1.0.0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
ecd5ccb4cd3c3a0483bb58412708e619
Package Poisoningnpm2026-08-14

@dsp-next-gen-ui/needs-review@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
47994e7dde94f96266d45bd5b72b8895
Package Poisoningnpm2026-08-14

async-critical-section@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
f3285d333462e48c702a01a2d25ac247
Package Poisoningnpm2026-08-14

index-design-system@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
857bbfc011a3617af1b2231ea00e37a8
Package Poisoningnpm2026-08-14

resource-lease-pool@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
073d0a5589f2f1f1741157c95f8dd4bd
Package Poisoningnpm2026-08-14

source-analyzer@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
4119b75a35a7d72a07d75e6c545d96c5
Package Poisoningnpm2026-08-15

@devmikets/hyperliquid-sdk@1.9.6 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
d9643c83a8933a511124cf955460abd3
Package Poisoningnpm2026-08-15

@divineubg/divine@1.0.5 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
074beb65ac6d218b0f0da3cae220cefe
Package Poisoningnpm2026-08-15

@ghost_debugger/nanocache@0.1.1 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
e4d3b732fb5e8b2dc240d6b7c2b98755
Package Poisoningnpm2026-08-15

@polymarkets/clob-client-v2@1.0.6 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
4f142dad7986b4abf2c24c231673e5ec
Package Poisoningnpm2026-08-15

@velliajs/discord@1.0.5 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
81bed922682e1f37bebfec35c525f4da
Package Poisoningnpm2026-08-16

@finaxis/common-js@0.3.4 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
3bb485c2d3073bd058ce8a3dd4e48a0c
Package Poisoningnpm2026-08-16

depcruise-wrap-stream-in-html@99.9.1 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
9c022db24466bead50c3ce00a5064e7d