August’s advisories cluster around four themes: trust-boundary failures in MCP / agent tooling, fail-open behavior on security controls, SSRF patterns in “fetch-on-behalf-of” features, and npm supply-chain poisoning that now includes scoped-package waves, dependency confusion, and on-chain C2 (EtherHiding). Figures below use Sectrend CSSA’s Simplified-Chinese source set with language duplicates removed.
Statistics
Breakdown: 30 CSSA exclusive early warnings, 39 CVE deep-dives, 166 registry-poisoning records (npm 164 / PyPI 2). Poisoning still dominates volume and is almost entirely on npm; the high critical share means many samples can lead to takeover, auth bypass, or data exfiltration—raw counts alone understate risk.
Trending
CSSA samples through August show agent/MCP risk is no longer just a forgotten auth check. The recurring pattern is a default-open trust boundary across protocol, SDK, gateway, and approval UX.
Notable cases include MetaMCP over-privileged OAuth credential access, prompt injection and SSRF in modelcontextprotocol / python-sdk, repeated hermes-agent issues (prompt injection, sandbox disabled, approval bypass, gateway auth flaws), and Claude Code command-injection paths via unsanitized environment variables. Enterprise intake that only tracks classic CVEs will systematically miss this class.
Several high-signal items share one failure mode—security controls that allow on error: CubeSandbox / CubeOps weak or missing auth enabling admin-token forgery; openssl_encrypt (CVE-2026-74901) falling back from AES-GCM to unauthenticated AES-CTR on decrypt failure; Apache Superset MCP swallowing exceptions into auth failure; hermes-agent treating approval timeouts as obstacles the model can route around. Design reviews should ask explicitly where decrypt, auth, approval, and sandbox-init failures land.
SSRF-related samples were dense (SeaweedFS, Semantica, better-auth, TencentDB-Agent-Memory, sub2api, python-sdk, Adobe Campaign, and more). The common shape is a server that fetches URLs for users or agents with weak validation, redirect gaps, or spoofable headers. Any crawl / preview / proxy-download / image-fetch / webhook-origin feature should be threat-modeled as high risk by default.
Of 166 poisoning records, almost all were npm. Watch for scoped-package campaigns; private-name dependency confusion (e.g. sm-* commerce modules, internallib_v*); EtherHiding via @syncraft-labs/* (decode-and-execute from Ethereum tx data—registry takedown does not remove C2); and version masquerading. Operations need pattern libraries, not only daily blocklists.
Deep Dive
npm remains the primary poisoning surface; sparse PyPI samples this month do not imply safety.
Agents/MCP often ship high privilege with weak approval; missing auth repeatedly caused cross-tenant read/write.
Unauth RCE, SQLi, and auth bypass remain frequent. Prioritize by exposure and reachability, not CVSS alone.
Summary
sm-*, internallib_v*, @syncraft-labs/*, and other August poison namesSubscribe to Sectrend's monthly security intelligence digest — one email a month with the full open source supply chain risk picture.
Subscribe →Published by CleanSource Community | Date: 2026-08-04
Sources: Sectrend CSSA vulnerability intelligence (270k+ advisories) · open source registry poisoning monitoring | Please credit the source when redistributing
商务合作
微信公众号