CSSA Exclusive Early Warning10.0 Critical
sub2api proxy trusts forged HTTP headers, rendering IP access control and rate limiting ineffective
An attacker exploits the default configuration's unconditional trust of the CF-Connecting-IP header, crafting malicious HTTP requests to forge the source IP address and thereby bypass both the API key IP allowlist check and the rate limiting on the login endpoint. The defect stems from the backend failing to distinguish trusted reverse proxies from ordinary clients, leaving the security protection logic entirely circumvented.
Component
sub2api is a Go-based subscription conversion and management API service. Its core architecture relies on a reverse proxy pattern to handle client req…
Type
Reliance on Untrusted Inputs in a Security Decision (CWE-807)
Repo
Remediation- It is recommended to modify the configuration to disable the default trust of forwarded IP options, and to strip or overwrite the relevant HTTP headers from untrusted sources at the reverse proxy layer. A strict proxy chain trust verification mechanism should also be established to ensure accurate IP resolution.
CSSA Exclusive Early Warning10.0 Critical
CubeSandbox missing authentication and rate limiting allows any user to remotely perform full sandbox lifecycle operations
The vulnerability arises because CubeAPI binds to 0.0.0.0:3000 by default when no authentication credentials are configured, and logs this only at INFO level rather than raising a warning, allowing an attacker to reach sensitive endpoints from anywhere on the network without credentials. Because the rate limiting middleware loads only in the code branch where authentication is enabled, the unauthenticated mode has no frequency control at all. Combined with an unconditionally applied permissive CORS policy, an attacker can easily launch large-scale concurrent requests or cross-site scripting attacks, abusing the sandbox management interface and causing compute resource exhaustion, data disclosure and denial of service.
Component
CubeSandbox is a high-performance KVM-based isolated sandbox system whose core component CubeAPI handles control plane requests for sandbox creation,…
Type
Missing Authentication for Critical Function (CWE-306)
Repo
Remediation- It is recommended to decouple the authentication and rate limiting modules in code so that rate limiting is enforced regardless of whether authentication is enabled. The default bind address should be changed to 127.0.0.1, or a severe warning raised and startup refused when an unauthenticated configuration is detected. CORS configuration should also be tightened with an allowlist policy to prevent cross-origin abuse, and environment variable settings strictly validated before production deployment.
CVE-2026-78155CVSS 9.9 Critical2026-08-23
StackGres Operator Privilege Escalation Leading to Administrator Access
In the StackGres operator, an untrusted search path (CWE-426) security flaw results in a privilege escalation vulnerability. A low-privilege tenant owning a database can exploit it to obtain administrator privileges. The vulnerability allows exploitation over the network with low complexity, changing the security scope without user interaction and causing serious impact to confidentiality, integrity and availability. It affects all unpatched StackGres operator deployments. An attacker needs only low-privilege tenant identity to trigger it and then escalate to administrator level.
Component
The StackGres operator is a Kubernetes operator for managing PostgreSQL database clusters, designed to simplify database lifecycle management.
Risks
- From low privilege to administrator: A low-privilege tenant owning a database can obtain cluster administrator privileges directly through this vulnerability
- Complete system control: Once administrator privileges are obtained, an attacker can fully control the database cluster, viewing, modifying or deleting all data and performing arbitrary administrative operations
- Remote network attack: The attack vector is NETWORK with low attack complexity and requires no user interaction
Source
Remediation- Apply least privilege and strictly restrict tenant access to operator resources
- Monitor operator audit logs to detect anomalous privilege escalation behavior
CVE-2026-5388CVSS 9.8 Critical2026-08-23
justhtml URL Sanitization and HTML Serialization Bypass Leading to Cross-Site Scripting
In justhtml prior to version 1.15.0, multiple security issues exist in the URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True) and edge cases across several custom sanitization policies. Depending on configuration, an attacker can bypass sanitization to inject active HTML and JavaScript — for example through encoded javascript: URLs, backslash-based relative URLs resolved to remote hosts, programmatic element and attribute names or HTML comments that break markup structure, reintroduction of a raw closing textarea tag through Markdown passthrough, or retention of style, meta http-equiv=refresh and base href tags in custom policies. Most custom policy issues do not affect the default sanitize=True configuration; they primarily affect helper APIs, programmatic DOM construction, html_passthrough=True and custom policy or transformation pipelines.
Component
justhtml is an open-source library for HTML sanitization, serialization and transformation, commonly used in web applications to process user input or third-party content.
Risks
- Cross-site scripting (XSS): An attacker can inject malicious scripts to steal user session tokens, cookies or sensitive information
- Page content tampering: By injecting style or meta http-equiv=refresh tags, an attacker can alter page appearance or redirect users to malicious sites
- No user interaction required: Under specific configurations such as html_passthrough=True, an attacker may trigger the vulnerability and execute code directly through crafted input without additional user interaction
Source
Remediation- Immediately upgrade justhtml to version 1.15.0 or later
- Review and restrict use of html_passthrough=True and custom sanitization policies
- Apply strict allowlist filtering to input data and avoid permissive default sanitization configurations
CVE-2026-78167CVSS 10.0 Critical2026-08-24
EFM ipTIME T16000M Session Validation Bypass Leading to Remote Code Execution
In EFM ipTIME T16000M version 14.20.2, the httpcon_check_session_url function within the Session Validation Handler component contains an improper authentication (CWE-287) security flaw. The vulnerability results in authentication bypass and allows remote exploitation. Exploit code is public and usable in attacks. The vendor was contacted early in the disclosure process but did not respond. The vulnerability affects all devices running EFM ipTIME T16000M firmware 14.20.2. An attacker can launch the attack remotely over the network and bypass authentication with no user interaction, potentially obtaining control of the device.
Component
The EFM ipTIME T16000M is an enterprise-grade network router and firewall device providing network access and security control.
Risks
- Complete system control: An attacker can bypass authentication and execute arbitrary code on the victim system, and depending on user privileges, install programs, view/modify/delete data or create new accounts with full privileges
- No user interaction required: The vulnerability triggers through a remote network request with no additional action from the target user
- Privilege escalation: From ordinary network visitor to device administrator — successful exploitation grants full administrative control of the device
Source
Remediation- Monitor logs for anomalous network session validation requests
- Enable IP allowlist access control on the device management interface
- Block session validation traffic from untrusted sources
Package Poisoningnpm2026-08-24
hydration-dim-kit@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
d79bd7cc5b3b0ebc4965048b95085c88
Package Poisoningnpm2026-08-24
@opap/player-kyc-widget@3.999.999 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
3ce114537783f4070a1cb5505878a89a
Package Poisoningnpm2026-08-24
sm-admin@99.0.1 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
76f7e1cd450f825b53524b56d68e927a
Package Poisoningnpm2026-08-24
sm-apikey-model@99.0.0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
7038e95a7c012ea16476ed0d7051fa7b
Package Poisoningnpm2026-08-24
sm-billing-form@99.0.0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
8ab97513ba4bac76b3a7b91a292f31c1
Package Poisoningnpm2026-08-24
sm-cart@99.0.1 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
777c691cce9d2a45a8f8d2df4b496d04
Package Poisoningnpm2026-08-24
sm-checkout@99.0.0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
0a4c9fa76e0f5812e5a5385ed1afe80a
Package Poisoningnpm2026-08-24
sm-payment@99.0.0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
8e9de7bb06d9561edc377c3aca86429d