September’s 19 publication packages contain 166 advisories. Four areas need priority checks: agent/MCP approval and isolation, network device management interfaces, query and URL validation, and malicious payloads executed by dependencies. Some dates have no separate daily bulletin; combined ranges and counting rules are listed at the end.
Statistics
Poisoning accounts for 100 records; 64 vulnerability records meet the critical threshold.
CSSA alerts: 30; CVE analyses: 36; poisoning samples: 100. The registry field splits poisoning into npm 96, PyPI 3 and gem 1. Critical counts only non-poisoning records with Number(score) ≥ 9.
Only published Simplified Chinese intelligence files for the month are counted. Each publication package counts once, including files with a range; records are not deduplicated across packages. The repeated agno entries on September 18 and 19 both remain in the totals. These numbers therefore do not count distinct vulnerabilities or affected devices.
Trending
Model-generated titles, command text and configuration files can bypass approval; the execution layer needs independent checks.
AgentScope misses command separators and classifies dangerous commands as read-only; openclaw does not pass tools.deny to the CLI; KiroCrew auto-approves based on model-generated titles. Absolute paths or an env wrapper bypass hermes-agent’s approvals.deny, potentially granting root where passwordless elevation is configured.
convex-backend guards only kind: "prod", while other selectors can still resolve to production. LiteLLM’s unverified email fallback can rebind an SSO/JWT subject and inherit administrator rights. Failed memory filtering in PraisonAI exposes other tenants’ data; AgentApproval also interpolates untrusted tool arguments into approval prompts.
An untrusted .env can override GEMINI_CLI_HOME in Gemini CLI (CVE-2026-13745); Mistral Vibe (CVE-2026-87986) skips checks on unparsed shell fragments. claude-code-action lets hidden instructions reach the model by sanitizing before decoding HTML entities.
Check execution isolation too: Corsair MCP’s run_script shares global objects with the host process. agno AgentOS accepts unauthenticated calls when A2A is enabled without credentials; adding code-execution tools creates an RCE risk. SGLang DiffusionServer (CVE-2026-93088) passes unauthenticated network messages directly to pickle.loads().
Management APIs, SSH and Telnet still lead to host takeover; retain each exploit’s prerequisites when assessing exposure.
HPE Fabric Composer (CVE-2026-76657) allows unauthenticated attackers to bypass API authentication; CVE-2026-76658 affects its SSH daemon. Telnet interfaces in Tenda AC1206 (CVE-2026-82693) and AC18 (CVE-2026-82695) also lack authentication or allow authentication bypass.
The act parameter in Advantech WISE-6610 (CVE-2026-79697) and CVE-2026-79698 permits command injection. The daily bulletin gives 1.2.4_20260821 as the fixed version. Input validation flaws in Citrix NetScaler ADC/Gateway (CVE-2026-88771) also permit unauthenticated remote command execution.
RouterOS (CVE-2026-67276) requires knowledge of an authorized RSA key’s modulus and fails to validate the exponent. Arista EOS (CVE-2026-73453) affects supported vulnerable platforms with P4Runtime enabled; that feature is disabled by default. These records do not all describe directly exploitable default deployments.
Surface checks on query parameters and URLs can fail when the query executes or the request reaches an internal service.
Drogon ORM inserts unchecked operators into WHERE clauses; R2R inserts filter keys and values directly into SQL and maps anonymous access to a privileged account by default. The password-recovery endpoint in Dayforce Payroll (CVE-2026-73640) permits time-based blind injection; the repository confirms only R2026.2.0.
9router’s defenses can be bypassed through DNS resolution, IPv6-mapped addresses, trailing hostname dots and redirects. Loopback requests are also treated as trusted, potentially exposing upstream API keys. DataEase connects SQL injection and file reads with SSRF caused by JDBC parameters.
cPanel EmailTrack (CVE-2026-67401) lets an account with mail enabled obtain root execution through SQL injection. Mail-account credentials are a prerequisite; check both endpoint access and database privileges.
npm accounts for 96 records; malicious code can run during installation, import or a feature call.
Scoped packages recur, including @yane88/hexhub-client, @stellarshift/evm-address-kit, @aircanada/components and @wizloft/harness-memory. Names such as google-cloud-internal-build-helper also appear in poisoning records; an internal-looking name does not establish provenance.
tailwindcss-forms-style uses a name similar to @tailwindcss/forms, retrieves transaction information through Ethereum RPC, decodes a payload address, then downloads, executes and erases its own malicious code. reactlogo-load extracts a URL from PNG LSB-encoded bits and fetches and executes code when loadLogo() is called. At month-end, llm-nebula executes a payload during preinstall.
On PyPI, timeweave poses as a timezone cache utility and downloads and executes Windows code; lucy-python-script-2030 steals sensitive data on import; aseitylab executes obfuscated payloads during installation or import and obtains instructions from blockchain C2. The gem package no-fun is recorded as communicating with a domain associated with malicious activity.
Deep Dive
Set response priorities using exposure, execution rights and dependency trigger paths.
Of 100 poisoning records, npm accounts for 96, PyPI for 3 and gem for 1. This is the distribution observed in this month’s publication packages; it does not establish that other ecosystems are safer.
openclaw does not pass deny configuration to execution; LiteLLM’s email fallback changes the account subject; PraisonAI’s memory filters fail to isolate tenants. Configuration, identity binding and data queries all need server-side validation.
RouterOS requires an authorized key’s modulus, Arista EOS requires P4Runtime to be enabled, and cPanel EmailTrack requires a mail account. Check component versions, enabled features and endpoint reachability alongside scores.
Summary
Confirm affected components and runtime settings before scheduling fixes and forensics.
1.2.4_20260821 or later as stated in the daily bulletin.tools.deny actually restricts execution..env files in Gemini CLI (CVE-2026-13745); correct the entity-decoding and sanitization order in claude-code-action.@yane88/hexhub-client, @stellarshift/evm-address-kit, @aircanada/components and tailwindcss-forms-style; verify provenance and versions.llm-nebula, feature calls for reactlogo-load, and installation or import records for timeweave, lucy-python-script-2030 and aseitylab.@aircanada/components or @wizloft/harness-memory, isolate them for forensics and rotate credentials from a trusted device. Package removal does not clear an intrusion.tailwindcss-forms-style and blockchain C2 in aseitylab in egress investigations; inspect downloaded payloads and remaining processes.run_script and agno’s code-execution tools. Configure authentication before enabling A2A in AgentOS, and restrict access to host files and credentials./get_reward and enable authentication. Review mail-account and database execution privileges for cPanel EmailTrack (CVE-2026-67401).Coverage: no separate Simplified Chinese daily bulletin exists for September 04, 05, 06, 11, 12, 22, 24, 25, 26, 27 or 30. The 09-07 package states a range of 09-04 through 09-07; the 09-13 package states 09-11 through 09-13. Other dates without a separate bulletin add no counts and do not imply that no security events occurred.
Published by CleanSource Community | Date: 2026-10-07
Sources: published Simplified Chinese CSSA, CVE and open source registry poisoning intelligence in the repository for September 2026 | Please credit the source when redistributing
Business
Official account