CSSA Exclusive Early Warning9.6 Critical
cal.diy authorization defect allows privilege-exceeding handling of team bookings and data compromise
The defect originates from a hardcoded permission validation stub service in the booking access control module, which always returns an allow result when handling team booking scenarios, leaving upper-layer route handlers unable to intercept unauthorized requests. An attacker holding only ordinary user credentials can craft malicious confirmation instructions over the network interface, tampering with the target booking identifier to trigger privilege-exceeding logic. This path bypasses the dynamic identity binding mechanism directly, allowing an attacker to illegitimately approve or reject any pending team schedule and pivot laterally into the private booking records of organization members. Affected systems face cross-tenant unauthorized read and write and disruption of business workflow order.
Component
cal.diy is an open-source platform for enterprise schedule management and appointment scheduling. Its core architecture is built on the tRPC communica…
Type
Missing Authorization (CWE-862)
Repo
Remediation- It is recommended that the development team remove all test permission validation stub code and replace it with a real authorization implementation backed by the relational database, strictly enforcing user identity binding and role permission mapping. Least privilege should be applied at sensitive business nodes so that contextual permission is re-verified before every data operation. Automated authorization test cases and end-to-end audit logging should also be introduced, with defensive programming standards established to prevent this class of logic defect.
CSSA Exclusive Early Warning9.0 Critical
Claude Code command wrapping and variable interpolation defect enabling malicious operations that wipe the host system drive
An attacker can craft a file path parameter containing special syntax to induce the local interpreter to perform undefined variable interpolation within a double-quoted context, statically collapsing the original target path into the root directory identifier. This mechanism also bypasses static path protection that only covers literal built-in command invocations. The attack chain nests the underlying system shell to redirect the restricted operation into an equivalent deletion command, using error stream redirection and silent execution flags to suppress runtime feedback. When such a high-risk instruction exceeds the preset foreground interaction timeout, the system automatically hands it to a background thread to continue running with no secondary confirmation interception, ultimately causing irreversible erasure of the host operating system core partition and associated configuration files, resulting in permanent service outage and loss of business continuity.
Component
Claude Code is an intelligent coding assistant integrated into developer workflows, using an interaction model where a local client collaborates with…
Type
OS Command Injection (CWE-78)
Repo
Remediation- It is recommended to enforce strict path allowlist validation and ensure security rules cover all equivalent shell-wrapped commands. Syntax analysis should be deployed at the instruction routing layer to block irregular paths, high-risk operations should require mandatory human review, log capture policy should be standardized, and system call scope should be restricted under least privilege.
CVE-2026-75045CVSS 9.1 Critical2026-08-18
YouTrack Unauthenticated Database Backup Download via Shared Draft Signature
In JetBrains YouTrack prior to versions 2025.3.156085, 2026.1.13913 and 2026.2.18112, an authentication bypass using an alternate path or channel (CWE-288) security flaw exists. An unauthenticated attacker can download database backups directly through a shared draft signature, resulting in sensitive data disclosure. The vulnerability affects all YouTrack users who have not updated to the above secure versions. An attacker can trigger it remotely over the network without any authentication, exploitation complexity is low, and it directly grants high-confidentiality and high-integrity data access.
Component
JetBrains YouTrack is a powerful issue tracking and project management application widely used by software development teams for task management, defect tracking and collaboration.
Risks
- Sensitive data disclosure: An attacker can download the complete database backup, obtaining all project data, user information, code associations and internal communication records
- Complete data access: Because the database backup contains core business data, the attacker gains read access to all information in the system
- Unauthenticated remote attack: An attacker needs no login or user interaction and can trigger the vulnerability with a network request alone, making the barrier extremely low
Source
Remediation- Immediately upgrade YouTrack to 2025.3.156085, 2026.1.13913 or 2026.2.18112 or later
- Restrict network access to YouTrack instances, allowing connections only from trusted IP addresses
- Monitor for anomalous large file downloads and unauthorized database access logs
CVE-2026-74901CVSS 9.8 Critical2026-08-17
openssl_encrypt Authentication Bypass Leading to Loss of Data Integrity
In openssl_encrypt prior to version 1.4.0, the pqc.py module contains an authentication bypass (CWE-347) security flaw: when AES-GCM decryption fails, the system incorrectly falls back to unauthenticated AES-CTR mode. An attacker can modify ciphertext in transit to bypass integrity verification and perform bit-flipping attacks undetected. The vulnerability affects all openssl_encrypt users who have not updated to 1.4.0. An attacker only needs to intercept and modify ciphertext in network transit to exploit it, requiring no user interaction and allowing remote control.
Component
openssl_encrypt is a software library for cryptographic operations supporting multiple algorithms including AES-GCM and AES-CTR modes.
Risks
- Loss of data integrity: An attacker can tamper with ciphertext in transit so the recipient decrypts incorrect data without integrity verification detecting it
- Authentication bypass: By falling back to unauthenticated AES-CTR mode, an attacker can bypass the original authentication mechanism and perform malicious operations
- Remote attack: An attacker needs no local access and can trigger the vulnerability simply by intercepting and modifying data over the network, giving it broad reach
Source
Remediation- Immediately upgrade openssl_encrypt to version 1.4.0 or later
- Enable an additional integrity verification mechanism such as HMAC at the transport layer
- Monitor network traffic for anomalous ciphertext modification and block suspicious connections promptly
Package Poisoningnpm2026-08-18
bcs-core@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
eaac5b4a93514e197782b300a136ae90
Package Poisoningnpm2026-08-18
leb128x@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
70608bb7fe522648626629ef63bd9531
Package Poisoningnpm2026-08-18
reseller-app@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
1bdde0a0452c7b593ffb3c4eabb9cb9f
Package Poisoningnpm2026-08-18
sui-gql-core@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
d88bb84fa805d8166f66d9189f24beb6
Package Poisoningnpm2026-08-18
sui-move-rpc@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
4990ad581ab620badc84e7be998b307e
Package Poisoningnpm2026-08-18
blastradar@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
df23136304d6c07837deaa9d9d026fcc
Package Poisoningnpm2026-08-18
sui-move-graphql@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
4fb838d9d1b24a73704fca1266b3a9c0
Package Poisoningnpm2026-08-18
ulebkit@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
864335a3abbc5adfeff382d58ffbd903