NEWSkillSec — elevating AI Skills security from malware detection to capability auditingSkillSecLearn more →
← Back to Intel Center
SECURITY INTEL · DAILY
Link copiedRSS

2026-09-08 Daily Security Intelligence

12 itemsTop severity 10.0 (Critical)CSSA 2 · CVE 2 · Poisoning 8

CSSA Exclusive Early Warning2

CSSA Exclusive Early Warning10.0 Critical

hermes-agent Approval Mechanism Failure Allows Path Rewrite Bypass of Denylist to Obtain Root Privileges

This vulnerability stems from a logic defect in approvals.deny whitelist matching. An attacker exploits the limitation that fnmatch only performs whole-string text matching by specifying absolute paths such as /usr/bin/sudo or invoking the env wrapper to execute sudo, successfully bypassing interception rules targeting "sudo *". Because the matching mechanism does not normalize the first command token or resolve the executable identity, semantically equivalent privilege-escalation commands can execute. In cloud environments configured for passwordless privilege escalation, a remote attacker can thereby break through the security fence and obtain host Root privileges.

Component
hermes-agent is an autonomous agent system based on large language models. Its core function is to parse natural language instructions and convert the…
Type
Protection Mechanism Failure (CWE-693)
Repo
Remediation
  • It is recommended to add a first-token normalization step before command execution, extract the executable filename for independent matching validation, or upgrade the approval mechanism to support identity recognition based on binary file identity rather than pure text fuzzy matching, and correct documentation to accurately reflect the actual boundaries of current protections so users do not form incorrect expectations of unbypassable defenses.
CSSA Exclusive Early Warning10.0 Critical

bisheng Hard-coded HMAC Key Enables Forged SSO Requests Leading to Unauthorized Remote Code Execution

By exploiting a hard-coded HMAC key in the default deployment configuration and a broken environment-variable override mechanism, an attacker can bypass signature verification and send malicious requests to the /api/v1/internal/sso/login-sync endpoint, generating valid JWT session tokens for arbitrarily specified users. This vulnerability not only allows takeover of existing accounts with known external IDs or self-granting of department administrator privileges, but can also be combined with known code-execution flaws to execute arbitrary system commands with root privileges in the server background without any authentication, comprehensively compromising data confidentiality, integrity, and availability.

Component
Bisheng is an enterprise AI workflow orchestration platform built in Python. Its core architecture relies on RESTful APIs and microservice components,…
Type
Use of Hard-coded Credentials (CWE-798)
Repo
Remediation
  • It is recommended to remove hard-coded sensitive credentials from configuration files, replace them with strong random strings injected via encrypted channels as environment variables, fix configuration loading logic to support dynamic environment-variable overrides, and add replay-attack protection plus strict input validation at the API layer.

CVE Intelligence2

CVE-2026-44756CVSS 10.0 Critical2026-09-08

Extended Passport Protocol Processing Library Malformed EPP Header Memory Safety Vulnerability Leading to Remote Code Execution

In the Extended Passport Protocol (EPP) processing library, a buffer copy without input size checking (CWE-120) results in a memory safety vulnerability. Under specific conditions, an unauthenticated attacker can attack by sending carefully crafted network requests containing malformed EPP headers, potentially causing undefined behavior and abnormal program termination. Successful exploitation may severely impact application confidentiality, integrity, and availability, and may even lead to remote code execution. The vulnerability affects all systems using the affected EPP processing library; an attacker requires no authentication to launch the attack remotely over the network, and exploitation complexity is low.

Component
Extended Passport Protocol (EPP) processing library is used for EPP-related network communication and data parsing, and is widely applied in domain registration, identity authentication, and similar scenarios.
Risks
  • From ordinary user to administrator: If the service runs with high privileges, an attacker can obtain the same privileges
  • Complete system control: An attacker can use this vulnerability to execute arbitrary code on the server, and depending on service privileges, install programs, view/modify/delete data, or create new accounts with full privileges
  • No user interaction required: An attacker only needs to send specially crafted network requests to trigger the vulnerability, with no user interaction and remote control possible
Source
Remediation
  • Monitor anomalous network request and memory access behavior logs
  • Enable strict input validation and boundary checking mechanisms for EPP services
  • Block EPP header requests from unknown sources or with abnormal formats
CVE-2026-75650CVSS 10.0 Critical2026-09-08

Adobe Commerce Template Engine Improper Neutralization of Special Elements Leading to Arbitrary Code Execution

In Adobe Commerce, the template engine improperly neutralizes special elements (CWE-1336), resulting in an arbitrary code execution security flaw. An attacker can use this vulnerability to execute arbitrary code in the context of the current user. The vulnerability can be exploited without user interaction, and the scope is changed. Adobe Commerce has a logic defect when handling template rendering; an attacker can trigger it by crafting malicious requests, leading to remote code execution. The vulnerability affects all unpatched Adobe Commerce versions. An attacker only needs to launch an attack over the network to complete exploitation, with no user interaction and remote control possible.

Component
Adobe Commerce is an enterprise e-commerce platform providing powerful product management, order processing, and template rendering capabilities.
Risks
  • From ordinary user to administrator: If the victim runs the service with administrator privileges, an attacker can obtain the same privileges
  • Complete system control: An attacker can use this vulnerability to execute arbitrary code on the victim system, and depending on user privileges, install programs, view/modify/delete data, or create new accounts with full privileges
  • No user interaction required: Through remote network attack, an attacker can trigger the vulnerability without inducing any user interaction
Source
Remediation
  • Monitor anomalous code execution behavior logs
  • Enable strict input validation mechanisms in the runtime environment
  • Block template rendering requests from untrusted sources

Package Poisoning8

Package Poisoningnpm2026-09-08

@aircanada/components@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
eaafa008b716bd8f0c8abfef2e3d8880
Package Poisoningnpm2026-09-08

@aircanada/core@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
ed28fe6b177d56fa5a38def13cd64e34
Package Poisoningnpm2026-09-08

@aircanada/navigation-handler@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
5c889706b5a9e938cc465a17fa888816
Package Poisoningnpm2026-09-08

@idkruan-10/dpd-depconf-probe@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
f9a02e3de43dd3befafd5eb0254a741e
Package Poisoningnpm2026-09-08

op-ts-server-core@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
fd29c33c687677a272ad231b4b09f11b
Package Poisoningnpm2026-09-08

service-home@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
d5a4216333ac6e16d1ea99b0058890a0
Package Poisoningnpm2026-09-08

krdpass-auth-react-native@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
4435d8d6e1969bfc093976a856c7b5b0
Package Poisoningnpm2026-09-08

@web2apk/baileys@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
9805d9e9ddd26da5be63739ec721af0c