ToolHive token delegation bypasses authorization checks enabling privilege-exceeding access and loss of permission integrity
An attacker can submit an external identity credential carrying a predefined delegation claim to activate a special validation branch. At runtime this branch exempts the normal subject mapping logic entirely and accepts the delegate identifier embedded in the token wholesale. When the server is configured with a wildcard client list, a maliciously crafted request can present any unregistered application as a legitimate agent entity, breaking established access control policy and granting unauthorized processes the privilege to invoke core interfaces. Affected instances face lateral privilege-exceeding operations and sensitive data disclosure.
Component
ToolHive is a tool integration management platform for AI agents and development workflows. Its underlying architecture is built on the OAuth 2.0 toke…
It is recommended to enforce strict claim provenance binding at the authorization decision layer, disable global implicit trust of external delegation fields, require an explicit allowlist approval process for wildcard matching policies, and deploy static syntax review during configuration initialization to intercept high-risk parameter combinations — converging the delegation trust domain to eliminate confused deputy attack paths at their root.
CVE Intelligence
1
CVE-2026-19977
CVSS
10.0 Critical
2026-08-17
EFM ipTIME A3004T Session Validation Manipulation Leading to Authentication Bypass
In EFM ipTIME A3004T version 14.19.0, the httpcon_check_session_url function in the Session Validation component contains an improper authentication (CWE-287) security flaw. By manipulating this function in a specific way, an attacker can cause improper authentication and bypass the normal authentication flow. The vulnerability allows a remote attacker to access protected resources without credentials, and exploit code is now public. The vendor was contacted early in the disclosure process but did not respond, and no official patch is available. The vulnerability affects all EFM ipTIME A3004T devices running version 14.19.0. An attacker can launch the attack remotely and achieve unauthorized access with no user interaction.
Component
The EFM ipTIME A3004T is a network access device providing connectivity and session management, widely used in home and small business network environments.
Risks
Complete system control: An attacker can bypass authentication to obtain device administration privileges directly, then execute arbitrary commands, modify configuration or install malicious software
No user interaction required: An attacker only needs to send a crafted request remotely over the network; no click or interaction from the target user is required
Data disclosure and tampering: With authentication bypassed, an attacker can steal sensitive network data or tamper with network configuration, causing service disruption or man-in-the-middle attacks
Restrict access to the device management interface at the firewall or gateway level, allowing only trusted IP addresses
Monitor network traffic for anomalous request patterns targeting httpcon_check_session_url and block suspicious connections promptly
Package Poisoning
10
Package Poisoning
npm2026-08-17
@junofficial/baileys@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
8331b1360c3efa263e03409fe98ff316
Package Poisoning
npm2026-08-17
@siwatfa/yorn@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
ec587381f2d9c368a4e2a719e75c302b
Package Poisoning
npm2026-08-17
a.poltoradnev-package-a@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
2253c25c2785dce7156fc038894747be
Package Poisoning
npm2026-08-17
autoai@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
d9c87e80d2e4b37c192a19d503187991
Package Poisoning
npm2026-08-17
cloud-agen-bot@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
0ddc8dd51956cc840df3b398f420e4ef
Package Poisoning
npm2026-08-17
club-sauce@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
8cf242c8f043c9099a5b5487d72860f6
Package Poisoning
npm2026-08-17
junofficial-userbot@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
e699ead5bb2060d48e9dfe484e9f5441
Package Poisoning
npm2026-08-17
sugarball-cli@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
847b55c4c17f14f115011ddf423a16ab
Package Poisoning
npm2026-08-17
userbotjs@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
6e0bc32ef9a59f86f9c40aa526c48c18
Package Poisoning
npm2026-08-17
userbotjs-jun@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.