claude-code-action bypasses sanitization through HTML entity encoding to inject hidden instructions, causing malicious manipulation of large-model behavior
An attacker can insert a malicious payload encoded as numeric HTML entities into interactive content. A logic flaw in sanitizeContent decodes entities after syntax stripping, so hidden HTML comments or attributes escape filtering and enter the LLM prompt, causing the model to execute unauthorized instructions. The vulnerability comes from incorrect input-preprocessing order and affects every data-formatting module that calls this sanitization function.
Component
claude-code-action is a GitHub Actions tool released by Anthropic to integrate the Claude code assistant into CI/CD workflows. Its core architecture depends on structured parsing of issue, pull-request, and comment content. The system extracts context to build prompts that drive automated code review and generation, so developers can use AI effectively in collaborative development.
Reorder the data-sanitization pipeline so HTML entity decoding runs first, ensuring later security filters can match and strip plaintext. Add regression tests for double-encoding so similar bypasses do not recur.
CVE Intelligence
2
CVE-2026-93088
CVSS
9.8 Critical
2026-09-22
SGLang DiffusionServer unauthenticated arbitrary code execution vulnerability leading to remote code execution
In SGLang's multimodal generation runtime, the DiffusionServer component of the disaggregated-diffusion orchestrator has a severe security defect. The component binds an unauthenticated ZeroMQ ROUTER socket to a network interface and, before any validation, passes the last frame of a received multipart message directly to pickle.loads(). This deserialization of untrusted data (CWE-502) lets an attacker craft a malicious message and execute arbitrary code on the target system. The vulnerability affects every SGLang DiffusionServer deployment that has no additional protection. An attacker needs no authentication, can trigger it remotely over the network with low complexity and no user interaction, and can take complete control of the system.
Component
SGLang is a high-performance runtime framework for large-language-model inference. Its multimodal generation runtime supports complex diffusion-model orchestration and distributed computation.
Risks
Complete system control: An attacker can use this vulnerability to execute arbitrary code on the victim system and, depending on the service's privileges, install programs, view/change/delete data, or create new fully privileged accounts
Unauthenticated remote attack: An attacker needs no credentials and can attack directly through the network interface, with very low exploitation difficulty
Broad impact: Without an authentication mechanism, any entity that can reach the network interface is a potential attacker, severely threatening confidentiality, integrity, and availability
Immediately apply an access-control list (ACL) to the DiffusionServer network interface and allow only trusted IP addresses
Do not pass data from untrusted sources directly to pickle.loads(); use a safer serialization format or strict input validation
Monitor ZeroMQ sockets for anomalous traffic and deploy intrusion detection to identify malicious serialized payloads
CVE-2026-65113
CVSS
9.8 Critical
2026-09-22
NVIDIA Linux infrastructure controller hardcoded-credential vulnerability leading to privilege escalation
NVIDIA Infrastructure Controller for Linux has a security defect that uses hardcoded credentials (CWE-798). An attacker may cause the system to authenticate with those hardcoded credentials. Successful exploitation can lead to privilege escalation, data tampering, denial of service, and information disclosure. The vulnerability affects every unpatched NVIDIA Linux infrastructure controller deployment. An attacker can attack remotely over the network with no user interaction and low attack complexity, directly threatening confidentiality, integrity, and availability.
Component
NVIDIA Infrastructure Controller for Linux is a software component provided by NVIDIA to manage and control GPU infrastructure on Linux.
Risks
Privilege escalation: An attacker can use the hardcoded credentials to obtain higher-than-intended privileges, including root
Data tampering and disclosure: An attacker can access sensitive data and modify critical configuration or business data, causing information disclosure
Denial of service: An attacker can use this vulnerability to interrupt the service and affect business continuity
Remote no-interaction attack: The attack vector is the network (NETWORK) and requires no user interaction (UI:N); an attacker can exploit the vulnerability directly from a remote location
Immediately find and remove hardcoded credentials in code or configuration and switch to a secure key-management service
Monitor anomalous logins and privilege-escalation attempts
Restrict network access to NVIDIA Infrastructure Controller and apply least privilege
Package Poisoning
10
Package Poisoning
npm2026-09-23
kambxjowhdsgyw@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
79f19cca3fab03f775f44b951271327b
Package Poisoning
gem2026-09-23
no-fun@999.99.99
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
570796df1c46acaba8e027b01487c8f4
Package Poisoning
npm2026-09-23
@tvg-mar/tvg-promos-atomic-ui@9.9.10
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
ee21d8c6e1106e9da4e775a5951d42e2
Package Poisoning
npm2026-09-23
@wizloft/harness-authority@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
4e51bef22b7e18d97a445b089ed7f826
Package Poisoning
npm2026-09-23
@wizloft/harness-file-providers@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
2e70c4260981092d97017529365985c2
Package Poisoning
npm2026-09-23
@wizloft/harness-memory@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
5243fc964cbf89a0742ff006648a4e48
Package Poisoning
npm2026-09-23
@wizloft/harness-plugin-file-events@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
32d756329c122f7ee0fbb580adb95cdc
Package Poisoning
npm2026-09-23
kamafhbnowct@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
3ff6b7674096891dbbc41b4ae0763cbb
Package Poisoning
npm2026-09-23
z-deno-truth-bwhlsz@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
570eed60ef7866c908b659f6d7d2b642
Package Poisoning
npm2026-09-23
z-deno-truth-ya1t4m@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.