CSSA Exclusive Early Warning10.0 Critical
R2R Retrieval Service SQL Injection via Search Endpoint Leading to Unauthorized Data Disclosure
An attacker can send crafted malicious requests to the POST /v3/retrieval/search interface, exploiting the fact that filter key values are concatenated directly into SQL strings rather than using parameterized binding, thereby injecting arbitrary SQL predicates into the WHERE clause. Because the default configuration allows anonymous access mapped to a high-privilege account, an attacker can perform time-based or boolean blind injection without authentication and steal sensitive information from the database, posing severe risks to data confidentiality and integrity.
Component
R2R is an AI-based document retrieval and management system whose core architecture relies on a hybrid of vector databases and full-text search engine…
Type
SQL Injection (CWE-89)
Repo
Remediation- Fixes should forbid concatenating user input directly into SQL statements, switch to parameterized queries or strict allowlist validation of filter key names, ensure all database operations use prepared statements, and change the system default configuration to require authentication so unauthorized high-privilege database access is prevented.
CSSA Exclusive Early Warning10.0 Critical
PraisonAI Memory Module Authorization Bypass Leading to Cross-Tenant Data Leakage and Resource Exhaustion
An attacker exploits a filtering failure of the user_id parameter when reading from default memory adapters such as Chroma and SQLite to perform unauthorized access and obtain other tenants' sensitive memory data; simultaneously exploits missing token metering logic on streaming response paths that causes inaccurate cost monitoring, and leverages a defect in hierarchical workflow modes that ignores maximum iteration limits by constructing permanently failing tasks to trigger infinite loops, thereby causing sustained compute resource consumption and denial of service.
Component
PraisonAI is an open-source SDK for multi-agent collaborative work. Its core architecture aims to provide a protocol-driven, secure-by-default, and as…
Type
Authorization Bypass Through User-Controlled Key (CWE-639)
Repo
Remediation- It is recommended to enforce user-identity-based metadata filtering in the memory search mixer and push that isolation policy down to each adapter's query stage; fix streaming processing code to fully capture final usage data chunks; introduce a global iteration ceiling and per-task failure retry count limits in hierarchical scheduling logic to prevent runaway processes.
CVE-2026-12646CVSS 9.9 Critical2026-09-08
Ivanti Neurons for ITSM Missing Authorization Vulnerability Leading to Remote Code Execution
In Ivanti Neurons for ITSM prior to version 2026.2, the core service has a missing authorization (CWE-862) security flaw. Due to the lack of proper access control mechanisms, a remotely authenticated attacker can use this vulnerability to execute arbitrary code on the server. The vulnerability allows an attacker with a low-privilege account to escalate privileges and fully control the server over the network without user interaction. It affects all Ivanti Neurons for ITSM users who have not updated to 2026.2, including enterprise IT service management deployments. An attacker only needs authenticated credentials to trigger the vulnerability, severely threatening system integrity, confidentiality, and availability.
Component
Ivanti Neurons for ITSM is an enterprise IT service management product used to automate and manage IT service processes, ticketing systems, and infrastructure monitoring.
Risks
- Privilege escalation and lateral movement: An attacker can break authorization limits with a low-privilege account and obtain the highest control over the server
- Complete system control: An attacker can use this vulnerability to execute arbitrary code on the server, and depending on server privileges, install malware, view/modify/delete sensitive data, or create new accounts with full privileges
- Remote network attack: Through CVSS vector AV:N (network) and AC:L (low complexity), an attacker can exploit remotely without physical access or complex prerequisites
Source
Remediation- Immediately upgrade Ivanti Neurons for ITSM to 2026.2 or later to fix the vulnerability
- Apply least privilege, strictly limiting the access scope and privilege level of remotely authenticated accounts
- Monitor anomalous process starts and code execution on the server, and deploy an intrusion detection system (IDS) to identify suspicious activity
CVE-2026-78234CVSS 9.9 Critical2026-09-08
hawtio-operator Arbitrary Certificate Issuance Vulnerability Leading to In-Cluster Service Identity Impersonation
A critical flaw exists in hawtio-operator. The Operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses that key to issue client certificates whose Subject Common Name (CN) is supplied by the author of a namespaced Hawtio Custom Resource. Because the Operator ships a ClusterRole that aggregates Hawtio CR permissions into the edit and admin roles, any user with edit permission in any namespace can obtain a Service-CA-issued certificate with an arbitrary subject. That certificate can be used to impersonate any in-cluster service identity toward peer services that trust Service CA for client authentication, including Jolokia agents and other components that trust Service CA.
Component
hawtio-operator is an Operator for managing Hawtio console deployments in Kubernetes/OpenShift clusters, intended to simplify monitoring and management of Java applications.
Risks
- Privilege escalation and identity impersonation: A low-privilege user with edit permission in any namespace can obtain a signed certificate for an arbitrary service identity
- Lateral movement: An attacker can use forged certificates to impersonate critical in-cluster services (such as Jolokia agents) and bypass client authentication mechanisms
- Complete trust-chain compromise: Because certificates are issued by the trusted Service CA, downstream services cannot detect the forged identity through ordinary certificate validation, leading to data disclosure or malicious operations
Source
Remediation- Immediately review and restrict hawtio-operator ClusterRole permissions, removing unnecessary aggregation into edit and admin roles
- Monitor anomalous key-access behavior in the openshift-service-ca namespace
- Apply additional authentication or authorization checks for services that rely on Service CA for client authentication
Package Poisoningnpm2026-09-09
open-item-validator@1.0.5 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
0ee57b2782650f15ccdc32f614723055
Package Poisoningnpm2026-09-09
file-type-detector@1.1.1 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
050e17389b65e4f93930cf0cf885aa01
Package Poisoningnpm2026-09-09
gloggo@1.1.3 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
763c7b3f2ba2c0638263920e8d5a358d
Package Poisoningnpm2026-09-09
toru-ultimate@1.0.0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
84bb36054832b37eadb9e48fcc41fcf9
Package Poisoningnpm2026-09-09
@yongot/canary-mcp-isolation@1.0.1 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
bcd7b518be449df015a52d074be322fa
Package Poisoningnpm2026-09-09
@yongot/canary-mcp-test@2.0.0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
2015c4633ae3a9b269b93bcb60e53e7e
Package Poisoningnpm2026-09-09
bx-ui-view@1.0.0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
44332c4415dd5dbb30ce3d6d8d664aa3
Package Poisoningnpm2026-09-09
reactlogo-load@1.0.0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
c186dfc5649d86b16c950d498f0177cb
Package Poisoningnpm2026-09-09
cat-sis2go-utils@99.1.0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
f3e390496e7cff043e196a4330f526ce