CSSA Exclusive Early Warning10.0 Critical
hermes-agent gateway authorization defect and code injection leading to permission bypass and remote code execution
This vulnerability comprises two critical defects. First, under multiplexed configuration the gateway's _auth_env function fails to properly isolate environment variable scope, incorrectly falling back to the global os.environ when a specific configuration file is missing, allowing an attacker to exploit the permissive policy of another configuration file for privilege-exceeding access. Second, when processing queue tasks, tools/bot_relay.py applies no strict character set validation or escaping to the connection_id field and concatenates it directly into an executed Python code string, allowing an attacker to inject arbitrary Python statements through a crafted ID and achieve remote code execution in a process holding the corresponding privileges.
Component
hermes-agent is a Python-based multi-platform message agent system whose core architecture aims to unify access and management across instant messagin…
Type
Code Injection (CWE-94)
Repo
Remediation- It is recommended that developers fix the environment variable reading logic to ensure configuration scope isolation, and apply strict type checking and secure encoding to all dynamic input data, prohibiting direct concatenation of untrusted data into executable code context.
CSSA Exclusive Early Warning10.0 Critical
python-sdk client lacking redirect validation leading to SSRF and disclosure of internal sensitive data
The vulnerability originates in the HTTP client factory configuration enabling redirect following unconditionally with no destination host validation. By controlling a malicious MCP server that returns a 3xx status code, an attacker can redirect client requests to internal or loopback addresses such as 127.0.0.1. If the target service responds with JSON-RPC formatted data, the client mistakenly treats it as a legitimate server response and injects it into the LLM session, leading to internal probe reconnaissance and disclosure of sensitive identity information.
Component
python-sdk is the Python implementation of the Model Context Protocol, serving as a standardized communication bridge between AI applications and larg…
Type
SSRF (CWE-918)
Repo
Remediation- It is recommended that developers disable default redirect following when constructing the HTTP client, or add strict allowlist validation of the target URL host and internal address filtering before performing a redirect, ensuring connections are permitted only to predefined safe domains. Client-side network boundary protection should mirror the existing server-side security middleware.
CVE-2026-77635CVSS 9.8 Critical2026-08-25
CakePHP FunctionsBuilder jsonPath SQL Injection Leading to Database Compromise
In CakePHP prior to versions 5.1.10, 5.2.15 and 5.3.7, the FunctionsBuilder::jsonValue() method lacks effective filtering of the jsonPath parameter when used with PostgresDriver, resulting in SQL injection (CWE-89). When user-controllable data reaches that parameter, an attacker can craft malicious SQL statements leading to database disclosure, tampering or execution of arbitrary system commands. The vulnerability affects all CakePHP users who have not updated to the fixed versions above, particularly backend applications using PostgreSQL. An attacker can trigger it with a specific request and manipulate the database remotely without complex preconditions.
Component
CakePHP is a rapid development framework for PHP that simplifies web application development by following convention over configuration.
Risks
- Complete database exposure: An attacker can read, modify or delete sensitive information in the database including user credentials and business data
- Remote code execution: Under certain configurations an attacker may execute operating system commands through SQL injection and fully control the server
- Unauthenticated attack: If the application does not validate input strictly, an attacker can trigger the vulnerability directly through an HTTP request with no login required
Source
Remediation- Immediately upgrade CakePHP to 5.1.10, 5.2.15 or 5.3.7 or later
- Apply strict allowlist validation or escaping to data passed into the jsonPath parameter
- Limit database account privileges and avoid connecting the application with a high-privilege account
CVE-2026-32558CVSS 9.8 Critical2026-08-24
Affiliate Pro Unauthenticated Privilege Escalation Leading to Remote Code Execution
In Affiliate Pro - Affiliate Program for WooCommerce & WordPress 8.9.1 and earlier, the permission validation module contains a logic defect resulting in incorrect privilege assignment (CWE-266). An unauthenticated attacker can craft a specific request to bypass authentication and escalate their own privileges directly, threatening site data integrity and system control. The plugin contains a permission bypass in certain endpoint invocation scenarios that an attacker can trigger remotely over the network, leading to unauthorized access or complete site takeover. The vulnerability affects all Affiliate Pro users who have not updated beyond 8.9.1, including e-commerce and content management platforms built on WooCommerce and WordPress. An attacker only needs to send a malicious request to the target site, requiring no user interaction and allowing remote control.
Component
Affiliate Pro is an affiliate marketing plugin designed for WooCommerce and WordPress, used to manage reseller programs, track sales and automate commission payments.
Risks
- From visitor to administrator: Exploiting this vulnerability, an attacker can escalate from an unprivileged visitor directly to a user with administrator privileges
- Complete site control: An attacker can perform arbitrary operations on the victim site including modifying products, viewing/changing/deleting user data, installing malicious plugins or creating new accounts with full privileges
- No user interaction required: The vulnerability triggers through automated network requests with no need to lure users into clicking links or any interaction
Source
Remediation- Immediately upgrade the Affiliate Pro plugin to a secure version after 8.9.1
- Monitor site backend login logs and anomalous permission change behavior
- Configure a web application firewall (WAF) to block unauthorized access attempts against the plugin's specific endpoints
CVE-2026-77994CVSS 9.8 Critical2026-08-24
Joomla Page Builder CK Second-Order SQL Injection Leading to Remote Code Execution
In the Joomla extension Page Builder CK prior to version 3.6.5, the loadStyles method of the front-end page model handles input improperly, resulting in second-order SQL injection (CWE-89). An attacker can craft specific data to trigger SQL injection, leading to database disclosure, tampering or remote code execution. The vulnerability affects all Page Builder CK users who have not updated to 3.6.5. An attacker can trigger it through front-end page interaction, exploiting the second-order nature to execute malicious SQL commands in a subsequent request.
Component
Page Builder CK is a popular Joomla CMS extension for building and managing front-end page layout and styling.
Risks
- Complete database control: An attacker can read, modify or delete sensitive information in the database including user credentials and site configuration
- Remote code execution: Under certain configurations, SQL injection may be leveraged to execute arbitrary system commands on the server
- Privilege escalation: If the application runs with elevated privileges, an attacker may obtain full control of the server
- Exploitation without direct interaction: The second-order nature lets an attacker trigger the vulnerability through other normal operations after the initial data submission, making it highly covert
Source
Remediation- Immediately upgrade the Page Builder CK extension to version 3.6.5 or later
- Apply strict prepared statements and escaping to database query parameters
- Deploy a web application firewall (WAF) to intercept suspicious SQL injection requests
Package Poisoningnpm2026-08-25
@medisend/auth@0.0.1-security-research flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
6cf7cbadfea90673eda5dc423392af43
Package Poisoningnpm2026-08-25
kelly-stake-sizing@0.1.1 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
1c20a1dd2fb23d086786baf1ac252343
Package Poisoningnpm2026-08-25
svelte-dim-ui@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
9e0eb4c09af0897c10d38c5641ba31d6
Package Poisoningnpm2026-08-25
classhomework@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
24ff6662567d594218a3c3956f29d275
Package Poisoningnpm2026-08-25
classwork@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
c3aa7d7d326c817df8edeac3464e917c
Package Poisoningnpm2026-08-25
desmosisfire@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
ad172bbc784beafc003e4937eb9af214
Package Poisoningnpm2026-08-25
desmosistuff@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
b8cb6ed8403b02edb352f560a5d4bde0
Package Poisoningnpm2026-08-25
desmosschoolwork@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
1c1b000b2126ff213f4146d357dbe528
Package Poisoningnpm2026-08-25
ilovedesmos@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
112a43457429e35039fbe51b6fc5baca
Package Poisoningnpm2026-08-25
tungtungisgoated@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
99c06fcac970bce46e8b14d40be223ae