CSSA Exclusive Early Warning10.0 Critical
CubeSandbox CubeOps weak credential configuration allows forged administrator tokens leading to authentication bypass
Because the BootstrapJWTSecret function performs no validity check on empty strings at startup, the system loads a zero-length HMAC key whenever the JWT secret in the database is empty or reads back abnormally. An attacker can exploit this flaw to construct a valid access token containing the administrator role without any network interaction or complex preconditions, bypassing the authentication middleware directly and obtaining full control over every protected endpoint under /api/v1.
Component
CubeSandbox is a one-stop cloud-native application development platform from Tencent Cloud. Its core control plane component CubeOps handles system in…
Type
Use of Weak Credentials (CWE-1391)
Repo
Remediation- It is recommended to add non-empty validation for the JWT secret in code, ensure the key length meets security requirements, and require generation of a high-entropy random key on first deployment. The storage layer logic that swallows database errors should also be fixed to improve robustness.
CSSA Exclusive Early Warning10.0 Critical
better-auth URL validation defect allows attackers to bypass SSRF protection leading to internal network probing and data disclosure
The vulnerability originates in an asymmetry between the discovery endpoint URL validation logic and the manual configuration path. When a tenant registers an external identity provider, the system requires the unknown origin to be added to the trusted list to pass validation, but this action simultaneously disables security checks against private addresses and DNS resolution. An attacker can exploit this logic defect by crafting a malicious HTTPS request that induces the server to connect to internal networks, performing a server-side request forgery attack that exposes internal services or leaks sensitive information.
Component
better-auth is an open-source authentication library aiming to provide modern web applications with secure, flexible and easily integrated authenticat…
Type
SSRF (CWE-918)
Repo
Remediation- It is recommended that developers unify the URL validation model so publicly routable HTTPS hosts still undergo strict IP address and DNS resolution security checks without needing to be added to the trusted list, reserving the trusted list exemption only for non-standard protocols or private addresses — fixing the SSRF protection bypass without sacrificing functionality.
CVE-2026-74990CVSS 9.8 Critical2026-08-18
Thunderbird Memory Corruption Leading to Remote Code Execution
Internally discovered memory corruption vulnerabilities (CWE-119) exist in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or other security-relevant defects and, with enough effort, could presumably be exploited. The issue has been fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14 and Thunderbird 153.1. Thunderbird carries a memory corruption risk when processing certain data, which an attacker can trigger with a crafted email or attachment, leading to remote code execution or service disruption. The vulnerability affects all Thunderbird users who have not updated to the fixed versions above. An attacker only needs to induce the target to open a crafted email to exploit it, requiring no user interaction and allowing remote control.
Component
Thunderbird is an open-source cross-platform email client developed by Mozilla, supporting mail management, newsgroup reading and calendar functionality.
Risks
- From standard user to administrator: If the victim runs the email client with administrative privileges, the attacker gains the same privileges
- Complete system control: An attacker can execute arbitrary code on the victim system, and depending on user privileges, install programs, view/modify/delete data or create new accounts with full privileges
- No user interaction required: Through drive-by compromise (T1189), a user only needs to open a malicious email to trigger the vulnerability, with no additional interaction
Source
Remediation- Monitor logs for anomalous memory access behavior
- Enable sandbox isolation for the runtime environment
- Block loading of email attachments from untrusted sources
CVE-2026-59940CVSS 9.8 Critical2026-08-18
Seroval fromJSON Deserialization Leading to Remote Code Execution
In Seroval prior to version 1.5.3, the seroval.fromJSON() function does not verify genuine internal Promise resolver records, resulting in deserialization of trusted data (CWE-502). An attacker-controlled JSON Promise control node can manipulate values in the generic deserialization reference table, producing deserialization side effects when plugins are enabled and potentially causing unintended server-side calls or remote code execution when downstream frameworks register callable wrappers. The vulnerability affects all Seroval users who have not updated to 1.5.3. An attacker can trigger it with crafted JSON data, requiring no user interaction and allowing remote control.
Component
Seroval is a library that facilitates stringification of JavaScript values, supporting serialization and deserialization of complex structures beyond what JSON.stringify can handle.
Risks
- From standard user to administrator: If the victim runs an application depending on Seroval with administrative privileges, the attacker gains the same privileges
- Complete system control: An attacker can execute arbitrary code on the victim system, and depending on user privileges, install programs, view/modify/delete data or create new accounts with full privileges
- No user interaction required: With crafted JSON data, an attacker can trigger the vulnerability automatically during downstream framework processing, with no additional user interaction
Source
Remediation- Immediately upgrade Seroval to version 1.5.3 or later
- Apply strict allowlist validation to input data and reject untrusted Promise control nodes
- Restrict the registration scope of callable wrappers in downstream frameworks to avoid unintended server-side calls
Package PoisoningPyPI2026-08-19
infogram-bot@1.6.0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
37664be0544034a16e1dc98660079415
Package Poisoningnpm2026-08-19
bqq1@1.0.0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
880e8dd99bcdab7a264b2d2bd7de4a2e
Package Poisoningnpm2026-08-19
txs-lib-sdk@1.0.2 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
27e9b8dce5f0871365c2f122737a12d2
Package Poisoningnpm2026-08-19
chaikit@2.3.5 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
79ac17604df97b414e0160628044f14a
Package Poisoningnpm2026-08-19
@sarex-team/sdk-js@9.9.11 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
e6e48ce32fd1c1f8fef18345dbbd0b55
Package Poisoningnpm2026-08-19
@sarex-team/viewer@9.9.11 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
65dd93d31b3160314132bcc0a7e18237
Package Poisoningnpm2026-08-19
hardhat-hold@2.0.1 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
f920d19a4402378da0355080c805ef0f
Package Poisoningnpm2026-08-19
secp256k1-lib@1.0.3 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
1418cb9c240e36876b980e5783057672
Package Poisoningnpm2026-08-19
price-scripping-js@1.1.2 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
4dc78f582330b9510eea2a5f3b8ee256