NEWSkillSec — elevating AI Skills security from malware detection to capability auditingSkillSecLearn more →
← Back to Intel Center
SECURITY INTEL · DAILY
Link copiedRSS

2026-09-10 Daily Security Intelligence

10 itemsTop severity 10.0 (Critical)CSSA 1 · CVE 2 · Poisoning 7

CSSA Exclusive Early Warning1

CSSA Exclusive Early Warning10.0 Critical

9router Search Proxy SSRF Protection Bypass Leading to Internal Network Probing and Authentication Failure

An attacker can pass a malicious provider_options.baseUrl parameter through the /v1/search endpoint and exploit multiple bypass techniques in the SSRF guard—including lack of DNS-resolution validation, defective IPv6-mapped address regex matching, ignoring trailing dots on hostnames, and failure to re-validate redirect targets—causing the server to issue requests to internal private networks or cloud metadata endpoints. Because requests toward loopback addresses are incorrectly marked by middleware as trusted local sources, an attacker can obtain keyless access to local /v1/* interfaces, steal upstream search provider API keys, and perform deep reconnaissance of internal services with sensitive data exfiltration.

Component
9router is an open-source AI routing and search aggregation service built on Node.js. Its core architecture aims to unify multiple upstream search eng…
Type
SSRF (CWE-918)
Repo
Remediation
  • It is recommended to enforce a strict allowlist of IP addresses after DNS resolution of domain names, disable automatic redirects or recursively security-check redirect targets, fix the regex defect in IPv6 address normalization logic, and remove blacklist restrictions that rely only on string matching. In addition, never treat requests whose source IP is a loopback address as authenticated by default; enforce an independent authentication flow for local interface access to block privilege-escalation risks.

CVE Intelligence2

CVE-2026-67401CVSS 10.0 Critical2026-09-10

cPanel EmailTrack SQL Injection Leading to Remote Code Execution

In cPanel, the EmailTrack component improperly escapes special elements in SQL commands (CWE-89), resulting in a SQL injection security flaw. Accounts with mail features enabled can craft malicious SQL queries to achieve remote code execution with root privileges. The vulnerability allows an attacker to bypass ordinary privilege restrictions through the mail feature entry point and directly obtain the highest control over the server. It affects all unpatched cPanel deployments, especially servers with mail tracking enabled. An attacker only needs existing mail account credentials to launch the attack and can achieve remote code execution without additional user interaction.

Component
cPanel is a widely used web hosting control panel that provides a graphical interface and automation tools to simplify management of websites, email, and databases.
Risks
  • From ordinary user to administrator: If the victim runs the browser with administrator privileges, an attacker can obtain the same privileges
  • Complete system control: An attacker can use this vulnerability to execute arbitrary code on the victim system, and depending on user privileges, install programs, view/modify/delete data, or create new accounts with full privileges
  • No user interaction required: Through Drive-by Compromise techniques (T1189), a user only needs to visit a malicious webpage to trigger the vulnerability without additional interaction
Source
Remediation
  • Monitor anomalous memory access behavior logs
  • Enable sandbox isolation mechanisms in the runtime environment
  • Block Canvas script loading from untrusted sources
CVE-2026-47156CVSS 10.0 Critical2026-09-10

MantisBT SOAP API Authentication Bypass Vulnerability Leading to Administrator Privilege Escalation

In MantisBT 2.28.3 and earlier, the SOAP API mci_check_login() function has a critical authentication bypass flaw (CWE-287). Any user who knows any valid cookie_string can, when the target username (including administrators) is known, authenticate as that user without knowing the target password. Because default MantisBT installations enable self-registration ($g_allow_signup = ON), the vulnerability can be exploited with zero prior access. A self-registered user can use their own cookie_string (readable after login from the browser's MANTIS_STRING_COOKIE) to impersonate an administrator via the SOAP API. The REST API and Web UI are unaffected because they derive the username server-side or validate the session cookie to prevent forgery. Version 2.28.4 contains the fix. There are currently no known mitigations.

Component
MantisBT is an open-source defect tracking system widely used for bug management and process control in software projects.
Risks
  • From ordinary user to administrator: An attacker can obtain an ordinary account via self-registration and use the vulnerability to escalate directly to administrator privileges
  • Complete system control: An attacker can use this vulnerability to execute arbitrary code on the victim system, and depending on user privileges, install programs, view/modify/delete data, or create new accounts with full privileges
  • Zero prior-access attack: Because self-registration is enabled by default, an attacker needs no initial credentials and can trigger the vulnerability by crafting malicious SOAP requests
Source
Remediation
  • Immediately upgrade MantisBT to 2.28.4 or later to apply the official fix
  • If an immediate upgrade is not possible, disable self-registration (set $g_allow_signup = OFF)
  • Monitor anomalous SOAP API login requests and authentication logs, and block suspicious IP addresses

Package Poisoning7

Package Poisoningnpm2026-09-10

gmgn-trading-kit@1.7.2 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
df6c48588df0cd242c948d90afe28e29
Package Poisoningnpm2026-09-10

discord-mfa-solver@1.0.1 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
c368628df7ec616acab74b7f3dcf0935
Package Poisoningnpm2026-09-10

@neroxkira/vangal-baileys@1.0.1 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
1b0c437872f593b5d14d5171cbc9c18c
Package Poisoningnpm2026-09-10

@sahril2nd/baileys@1.0.21 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
28492d6b542fe88bfab589879ae420a5
Package Poisoningnpm2026-09-10

@auction-fe/reporting-system@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
fd3a41d9d258c12fa6885f19db501ff8
Package Poisoningnpm2026-09-10

@auction-fe/ui-kit@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
ca28cb21d73e23792e12f564e7d14e5f
Package Poisoningnpm2026-09-10

@convertics/script@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
eb1da3ae41f1641b1c38fcae0da75e48