CSSA Exclusive Early Warning10.0 Critical
openclaw multi-agent platform authorization check failure allowing attackers to perform unauthorized high-risk operations and lose control of system privileges
The vulnerability stems from a logic defect in the claude-cli backend when handling agents.list[].tools.deny: the denied tool list is not dynamically passed into CLI invocation arguments, so native tools such as exec and write remain enabled. An attacker can exploit this remotely over the network without additional authentication or user interaction to induce a restricted agent to run high-risk commands that should have been forbidden, bypassing intended privilege isolation and causing confidentiality disclosure, data tampering and service availability damage.
Component
openclaw is an automation orchestration platform for multi-agent collaboration. Its architectural core manages multiple agent instances backed by diff…
Type
Incorrect Authorization (CWE-863)
Repo
Remediation- Developers should refactor backend command-line argument construction so that agent-level tool allowlists and denylists map correctly into the runtime environment, and add configuration-validity checks during system status inspection to warn promptly when permission settings cannot be enforced, achieving precise access control and closed-loop risk management.
CSSA Exclusive Early Warning10.0 Critical
TensorFlow RaggedGather integer overflow leading to heap buffer overflow and denial of service
An attacker can craft RaggedGather operator inputs with specific parameters to trigger the issue. Because internal accumulation of output counts lacks bounds checking for the int32 type, integer overflow wraps to a smaller value, causing the system to allocate an undersized memory buffer while subsequent data-copy loops still write according to the actual logical row count, producing a heap buffer overflow that corrupts process memory integrity and may cause service interruption or code execution.
Component
TensorFlow is an open-source machine learning framework based on dataflow programming. Its core architecture supports large-scale numerical computatio…
Type
Integer Overflow to Buffer Overflow (CWE-680)
Repo
Remediation- Developers should enforce strict overflow checks on code paths involving numeric accumulation and memory allocation, use wider arithmetic or safe library functions to validate result ranges, abort and return an error immediately when potential overflow is detected, and strengthen input-parameter validation to block maliciously crafted data flows.
CVE-2026-77009CVSS 9.9 Critical2026-09-02
WatchMan-Site7 plugin debug console arbitrary code execution
In WatchMan-Site7 WordPress plugin versions 4.2.0 and earlier, the debug console does not enforce access restrictions and contains improper control of code generation (CWE-94). The console directly executes user-supplied PHP code, allowing any authenticated user (for example a subscriber) to run arbitrary code on the server. The vulnerability affects all WatchMan-Site7 plugin users who have not updated to a fixed version. An attacker needs only a low-privilege authenticated account to trigger it remotely without complex interaction.
Component
WatchMan-Site7 is a WordPress plugin intended to provide site monitoring and management features, but improper debug-function configuration introduces severe security risk.
Risks
- From low-privilege user to full server control: Even with only a minimal subscriber account, an attacker can elevate privileges to server level through this vulnerability
- Complete system control: An attacker can execute arbitrary PHP code on the server to read, modify or delete site data and even control the underlying server
- Low-barrier remote attack: An attacker needs no physical access or high-privilege credentials—only a valid low-privilege account
Source
Remediation- Restrict access to the debug console endpoint at the server layer
- Monitor logs for anomalous PHP code execution behavior on the server
CVE-2026-4357CVSS 10.0 Critical2026-09-02
Embed HTML5 Game plugin unauthorized file upload leading to remote code execution
In Embed HTML5 Game WordPress plugin versions 1.3 and earlier, unrestricted upload of file with dangerous type (CWE-434) exists because the plugin does not properly restrict the identity of users uploading files or the uploaded file types. An unauthenticated attacker can upload a PHP backdoor to the affected site and fully control the server. The vulnerability affects all Embed HTML5 Game plugin users who have not updated to a secure version, across WordPress site deployment scenarios. An attacker can launch the attack remotely without authentication by crafting malicious requests to upload malicious scripts and achieve remote code execution.
Component
Embed HTML5 Game is a WordPress plugin that helps users easily embed and display HTML5 games on their sites.
Risks
- Complete system control: An attacker can execute arbitrary code on the victim server and, depending on server privileges, install programs, view/modify/delete data or create new accounts with full privileges
- Unauthenticated attack: An attacker needs no login or credentials and can trigger the vulnerability directly over the network
- Persistent backdoor: An uploaded PHP backdoor can keep the attacker in control of the server even after the vulnerability is fixed
Source
Remediation- Configure a web application firewall (WAF) to intercept illegal file-upload requests
- Periodically scan site files to detect and remove suspicious PHP backdoor files
Package Poisoningnpm2026-09-03
@stellarshift/abi-tools@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
84af270381a0a6500449bc0cce6c0392
Package Poisoningnpm2026-09-03
@stellarshift/evm-address-kit@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
8ab78491c447aaa7ad4397df8b391dd6
Package Poisoningnpm2026-09-03
@stellarshift/token-units@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
8897adce2683e37ddfeab77f849722d3
Package Poisoningnpm2026-09-03
real-router-utils@1.0.0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
059ef9a7c548e09bee5a6b9006e217d7
Package Poisoningnpm2026-09-03
apple-internal-test-utility@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
70c0f216d51158543f641bbeb52412f6
Package Poisoningnpm2026-09-03
frank-apple-sync-service@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
dfd7119d8b197c47db5e0489ec877f54
Package Poisoningnpm2026-09-03
frank-apple-utils@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
62a2edb304b16cfd24329a5016ceca0b
Package Poisoningnpm2026-09-03
google-cloud-internal-build-helper@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
3b3b2024c10259d12711952512698c17
Package Poisoningnpm2026-09-03
google-cloud-internal-core-utils@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
a8b383f52f9b5dab612a2ebcbfab8843
Package Poisoningnpm2026-09-03
google-internal-cloud-audit-security-check@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
5ddd8464adf7b45bb1f825917397b374