NEWSkillSec — elevating AI Skills security from malware detection to capability auditingSkillSecLearn more →
← Back to Intel Center
SECURITY INTEL · DAILY
Link copiedRSS

2026-08-20 Daily Security Intelligence

9 itemsTop severity 10.0 (Critical)CSSA 2 · CVE 2 · Poisoning 5

CSSA Exclusive Early Warning2

CSSA Exclusive Early Warning10.0 Critical

hermes-agent incorrect interaction mode setting disables the security approval mechanism, letting the model bypass restrictions and execute dangerous commands

The vulnerability originates in the cli.py entry point unconditionally setting the HERMES_INTERACTIVE environment variable to 1, causing non-interactive single-query mode to be misidentified as interactive. This triggers a human approval prompt that can never be answered, leading to timeouts or tool invocation failures. Because the refusal surfaces as a generic fault rather than an explicit security policy denial, the agent model treats it as a technical obstacle to overcome and reconstructs the dangerous instruction through execution channels such as execute_code that are not subject to the same restrictions — for example running shutil.rmtree via python3 -c — successfully bypassing command filtering for categories such as recursive deletion. The affected host ultimately faces loss of data integrity and high-risk unauthorized operations.

Component
hermes-agent is an intelligent agent system built on large language models. Its core architecture aims to automate task execution through natural lang…
Type
Protection Mechanism Failure (CWE-693)
Repo
Remediation
  • It is recommended to disable the interactive flag in non-interactive mode to avoid futile approval hangs, and to configure an explicit automatic denial or allowlist policy for that path. All execution channels should apply the same security classification checks so the model receives a clear policy denial signal, preventing it from seeking workarounds around security restrictions.
CSSA Exclusive Early Warning10.0 Critical

Apache Superset MCP service exception handling defect disables authentication, permitting unauthorized access

An attacker exploits the silent swallowing of exceptions thrown by MCP_AUTH_FACTORY in the _create_auth_provider function. When a custom authentication factory fails because of a configuration error, dependency change or missing environment variable, the system returns None instead of terminating startup, leaving the MCP server running with no authentication. Any remote user can then issue requests without credentials, causing sensitive data disclosure and loss of system integrity.

Component
Apache Superset is an open-source data visualization and exploration platform. Its MCP service module aims to provide data query and analysis capabili…
Type
Missing Authentication for Critical Function (CWE-306)
Repo
Remediation
  • It is recommended to remove the exception suppression around authentication factory initialization and follow fail-safe principles by rethrowing the exception to prevent service startup, or to refuse service outright when the authentication provider is empty while a factory is configured — ensuring the system never degrades to an unprotected state when the authentication component is unavailable.

CVE Intelligence2

CVE-2026-76243CVSS 9.8 Critical2026-08-19

Stigmem Unauthenticated Access Leading to Arbitrary Read, Write and Federation Operations

In Stigmem prior to version 0.9.0a2, disabling authentication in a non-loopback deployment results in an unauthenticated access (CWE-285) security flaw. If a node is exposed beyond the local development environment, an attacker can perform read, write and federation operations anonymously. The vulnerability allows an unauthenticated attacker to manipulate data and services directly wherever the network is exposed, seriously threatening system integrity and confidentiality. It affects all Stigmem users who have not updated to 0.9.0a2, particularly deployments binding the service to non-local interfaces without enforced authentication. An attacker can launch the attack remotely without any credentials, obtaining sensitive data or tampering with system state directly.

Component
Stigmem is an open-source software component commonly used for data processing or service node deployment, supporting network interaction and federation operations.
Risks
  • Data disclosure and tampering: An attacker can perform read and write operations anonymously, stealing sensitive data or damaging data integrity
  • Service takeover: Through federation operations an attacker may enroll the affected node into a malicious network, leading to service abuse or use as an attack pivot
  • Unauthenticated remote attack: With no effective authorization mechanism, any attacker able to reach the network port can exploit the vulnerability without needing to bypass authentication
Source
Remediation
  • Immediately upgrade Stigmem to version 0.9.0a2 or later
  • Enforce authentication in non-local deployment environments
  • Configure firewall rules to restrict access to Stigmem ports, allowing only trusted IP addresses
CVE-2026-73388CVSS 9.3 Critical2026-08-19

Nikstore Core Unauthenticated SQL Injection Leading to Database Disclosure

In Nikstore Core 1.5 and earlier, the core processing module lacks strict filtering and escaping of input parameters, resulting in an unauthenticated SQL injection (CWE-89) security flaw. An attacker can send a crafted malicious request over the network without any authentication and manipulate backend database queries directly. The vulnerability allows an attacker to bypass authentication, steal sensitive data, tamper with database content or take further control of the server. It affects all users running Nikstore Core 1.5 and earlier, and because no user interaction is required, an attacker can exploit it remotely at scale with automated scripts.

Component
Nikstore Core is an open-source core component typically used for data processing or application backend services, supporting complex business logic and database interaction.
Risks
  • Complete data disclosure: An attacker can read sensitive information in the database including user credentials, personally identifiable information and business data
  • Database integrity damage: An attacker can execute arbitrary SQL commands to modify, delete or insert malicious data, disrupting business logic
  • Remote unauthorized access: With no authentication required, an attacker can launch the attack directly from the internet with no social engineering or user interaction
Source
Remediation
  • Immediately upgrade Nikstore Core to a secure version after 1.5
  • Deploy a web application firewall (WAF) at the application layer to intercept common SQL injection patterns
  • Minimize database access permissions and restrict what the application account can do in the database

Package Poisoning5

Package Poisoningnpm2026-08-20

ai-texts-utils@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
0146821466ebfda76227a76aadd6c53e
Package Poisoningnpm2026-08-20

mc-provider@1.0.10 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
c6b238519943f1abd95d4da0b2be4d33
Package Poisoningnpm2026-08-20

node-runtime-utils@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
f6c561b78feb70fe5fc40738cd979273
Package Poisoningnpm2026-08-20

@httttt/mcp-demo@1.0.0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
c8e4e3a01cb8df5eaa593d36a887e48d
Package Poisoningnpm2026-08-20

expect-dotenv@7.2.1 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
afbea90650288a41fd6da2152e3490b5