NEWSkillSec — elevating AI Skills security from malware detection to capability auditingSkillSecLearn more →
← Back to Intel Center
SECURITY INTEL · MONTHLY
RSS

2026-09 CleanSource Community Monthly Security Intelligence Digest

166 Advisories
64 Critical (CSSA+CVE)
19 Publish days
100 Poisoning samples

September’s 19 publication packages contain 166 advisories. Four areas need priority checks: agent/MCP approval and isolation, network device management interfaces, query and URL validation, and malicious payloads executed by dependencies. Some dates have no separate daily bulletin; combined ranges and counting rules are listed at the end.

01 Core statistics

Statistics

Poisoning accounts for 100 records; 64 vulnerability records meet the critical threshold.

CSSA alerts: 30; CVE analyses: 36; poisoning samples: 100. The registry field splits poisoning into npm 96, PyPI 3 and gem 1. Critical counts only non-poisoning records with Number(score) ≥ 9.

Only published Simplified Chinese intelligence files for the month are counted. Each publication package counts once, including files with a range; records are not deduplicated across packages. The repeated agno entries on September 18 and 19 both remain in the totals. These numbers therefore do not count distinct vulnerabilities or affected devices.

02 Trend analysis

Trending

T1 Agents / MCP: enforce approval rules at execution

Model-generated titles, command text and configuration files can bypass approval; the execution layer needs independent checks.

AgentScope openclaw KiroCrew hermes-agent convex-backend PraisonAI agno SGLang

AgentScope misses command separators and classifies dangerous commands as read-only; openclaw does not pass tools.deny to the CLI; KiroCrew auto-approves based on model-generated titles. Absolute paths or an env wrapper bypass hermes-agent’s approvals.deny, potentially granting root where passwordless elevation is configured.

convex-backend guards only kind: "prod", while other selectors can still resolve to production. LiteLLM’s unverified email fallback can rebind an SSO/JWT subject and inherit administrator rights. Failed memory filtering in PraisonAI exposes other tenants’ data; AgentApproval also interpolates untrusted tool arguments into approval prompts.

An untrusted .env can override GEMINI_CLI_HOME in Gemini CLI (CVE-2026-13745); Mistral Vibe (CVE-2026-87986) skips checks on unparsed shell fragments. claude-code-action lets hidden instructions reach the model by sanitizing before decoding HTML entities.

Check execution isolation too: Corsair MCP’s run_script shares global objects with the host process. agno AgentOS accepts unauthenticated calls when A2A is enabled without credentials; adding code-execution tools creates an RCE risk. SGLang DiffusionServer (CVE-2026-93088) passes unauthenticated network messages directly to pickle.loads().

T2 Networks and infrastructure: check access to management interfaces

Management APIs, SSH and Telnet still lead to host takeover; retain each exploit’s prerequisites when assessing exposure.

HPE Networking Fabric Composer Tenda AC1206 Tenda AC18 Advantech WISE-6610 RouterOS Arista EOS Citrix NetScaler

HPE Fabric Composer (CVE-2026-76657) allows unauthenticated attackers to bypass API authentication; CVE-2026-76658 affects its SSH daemon. Telnet interfaces in Tenda AC1206 (CVE-2026-82693) and AC18 (CVE-2026-82695) also lack authentication or allow authentication bypass.

The act parameter in Advantech WISE-6610 (CVE-2026-79697) and CVE-2026-79698 permits command injection. The daily bulletin gives 1.2.4_20260821 as the fixed version. Input validation flaws in Citrix NetScaler ADC/Gateway (CVE-2026-88771) also permit unauthenticated remote command execution.

RouterOS (CVE-2026-67276) requires knowledge of an authorized RSA key’s modulus and fails to validate the exponent. Arista EOS (CVE-2026-73453) affects supported vulnerable platforms with P4Runtime enabled; that feature is disabled by default. These records do not all describe directly exploitable default deployments.

T3 Injection and SSRF: inspect filters and final request destinations

Surface checks on query parameters and URLs can fail when the query executes or the request reaches an internal service.

Drogon R2R 9router DataEase cPanel Dayforce Payroll

Drogon ORM inserts unchecked operators into WHERE clauses; R2R inserts filter keys and values directly into SQL and maps anonymous access to a privileged account by default. The password-recovery endpoint in Dayforce Payroll (CVE-2026-73640) permits time-based blind injection; the repository confirms only R2026.2.0.

9router’s defenses can be bypassed through DNS resolution, IPv6-mapped addresses, trailing hostname dots and redirects. Loopback requests are also treated as trusted, potentially exposing upstream API keys. DataEase connects SQL injection and file reads with SSRF caused by JDBC parameters.

cPanel EmailTrack (CVE-2026-67401) lets an account with mail enabled obtain root execution through SQL injection. Mail-account credentials are a prerequisite; check both endpoint access and database privileges.

T4 Supply-chain poisoning: trace package names, triggers and payloads

npm accounts for 96 records; malicious code can run during installation, import or a feature call.

@yane88/hexhub-client @stellarshift/evm-address-kit @aircanada/components tailwindcss-forms-style llm-nebula aseitylab

Scoped packages recur, including @yane88/hexhub-client, @stellarshift/evm-address-kit, @aircanada/components and @wizloft/harness-memory. Names such as google-cloud-internal-build-helper also appear in poisoning records; an internal-looking name does not establish provenance.

tailwindcss-forms-style uses a name similar to @tailwindcss/forms, retrieves transaction information through Ethereum RPC, decodes a payload address, then downloads, executes and erases its own malicious code. reactlogo-load extracts a URL from PNG LSB-encoded bits and fetches and executes code when loadLogo() is called. At month-end, llm-nebula executes a payload during preinstall.

On PyPI, timeweave poses as a timezone cache utility and downloads and executes Windows code; lucy-python-script-2030 steals sensitive data on import; aseitylab executes obfuscated payloads during installation or import and obtains instructions from blockchain C2. The gem package no-fun is recorded as communicating with a domain associated with malicious activity.

03 Dimensional notes

Deep Dive

Set response priorities using exposure, execution rights and dependency trigger paths.

Ecosystem

Of 100 poisoning records, npm accounts for 96, PyPI for 3 and gem for 1. This is the distribution observed in this month’s publication packages; it does not establish that other ecosystems are safer.

Auth model

openclaw does not pass deny configuration to execution; LiteLLM’s email fallback changes the account subject; PraisonAI’s memory filters fail to isolate tenants. Configuration, identity binding and data queries all need server-side validation.

Exploit path

RouterOS requires an authorized key’s modulus, Arista EOS requires P4Runtime to be enabled, and cPanel EmailTrack requires a mail account. Check component versions, enabled features and endpoint reachability alongside scores.

04 Recommendations

Summary

Confirm affected components and runtime settings before scheduling fixes and forensics.

R1 Priority checks

Engineering
  • Inventory API, SSH and Telnet exposure for HPE Fabric Composer (CVE-2026-76657 / CVE-2026-76658) and Tenda (CVE-2026-82693 / CVE-2026-82695); restrict access sources.
  • Check WISE-6610 firmware. For CVE-2026-79697 / CVE-2026-79698, upgrade to 1.2.4_20260821 or later as stated in the daily bulletin.
Security
  • Verify RouterOS RSA authentication and Arista EOS P4Runtime exposure against actual settings, for CVE-2026-67276 / CVE-2026-73453 respectively.
  • Check ZeroMQ access controls for SGLang DiffusionServer (CVE-2026-93088) and investigate unusual processes and deserialization calls.

R2 Build and merge

Engineering
  • Test separators, absolute paths and unparsed shell input in AgentScope, hermes-agent and Mistral Vibe (CVE-2026-87986); verify that openclaw’s tools.deny actually restricts execution.
  • Load only trusted .env files in Gemini CLI (CVE-2026-13745); correct the entity-decoding and sanitization order in claude-code-action.
Security
  • Apply consistent authorization to every production selector in convex-backend; review LiteLLM SSO/JWT subject binding and PraisonAI tenant isolation.
  • Use parameterized queries and operator/key allowlists in Drogon / R2R. In 9router, validate resolved IPs and every redirect, and authenticate loopback interfaces independently.

R3 Supply-chain governance

Engineering
  • Search lockfiles and dependency trees for @yane88/hexhub-client, @stellarshift/evm-address-kit, @aircanada/components and tailwindcss-forms-style; verify provenance and versions.
  • Review installation records for llm-nebula, feature calls for reactlogo-load, and installation or import records for timeweave, lucy-python-script-2030 and aseitylab.
Security
  • If hosts installed or ran packages flagged as compromising the system, such as @aircanada/components or @wizloft/harness-memory, isolate them for forensics and rotate credentials from a trusted device. Package removal does not clear an intrusion.
  • Include on-chain address retrieval by tailwindcss-forms-style and blockchain C2 in aseitylab in egress investigations; inspect downloaded payloads and remaining processes.

R4 Runtime and telemetry

Engineering
  • Isolate Corsair MCP’s run_script and agno’s code-execution tools. Configure authentication before enabling A2A in AgentOS, and restrict access to host files and credentials.
  • Restrict network access to OpenRLHF’s /get_reward and enable authentication. Review mail-account and database execution privileges for cPanel EmailTrack (CVE-2026-67401).
Security
  • Audit KiroCrew and PraisonAI AgentApproval decisions against actual tools, parameters and execution records; check for approvals induced by titles or embedded instructions.
  • Correlate 9router loopback requests, unusual DataEase egress and poisoned-package subprocesses; trace credential and data access on affected hosts.

Coverage: no separate Simplified Chinese daily bulletin exists for September 04, 05, 06, 11, 12, 22, 24, 25, 26, 27 or 30. The 09-07 package states a range of 09-04 through 09-07; the 09-13 package states 09-11 through 09-13. Other dates without a separate bulletin add no counts and do not imply that no security events occurred.
Published by CleanSource Community | Date: 2026-10-07
Sources: published Simplified Chinese CSSA, CVE and open source registry poisoning intelligence in the repository for September 2026 | Please credit the source when redistributing

Want to see this on your own codebase?Get a Demo