remote-code-execution

Tag

Cards List
#remote-code-execution

"One robot could infect other vulnerable robots nearby ... Attackers could take control of entire fleets of robots."

Reddit r/ArtificialInteligence · 2026-08-22

A remote code execution vulnerability has been found in Unitree robots, and it is wormable, enabling attackers to infect and control multiple robots.

0 favorites 0 likes
#remote-code-execution

CVE-2026-33696: From a Schema Name to RCE in n8n

Lobsters Hottest · 2026-08-16 Cached

This CVE describes a prototype pollution vulnerability in n8n that can be exploited for remote code execution through a Git node gadget chain.

0 favorites 0 likes
#remote-code-execution

ZOOMSDAY, Zoom Zero-Click Vulnerabilities Via Annotation

Lobsters Hottest · 2026-08-13 Cached

Researchers used publicly available AI models to discover a critical zero-click, memory-corruption vulnerability in Zoom's annotation feature, allowing remote code execution on all meeting participants across all platforms. Zoom has issued fixes, but the research highlights how AI is lowering the barrier to nation-state-level exploits.

0 favorites 0 likes
#remote-code-execution

@aacle_: One injection. One config write. Full RCE on the developer's machine. That's CVE-2025-53773, and it's the pattern behin…

X AI KOLs Timeline · 2026-07-30 Cached

This article breaks down the MCP security attack chain behind CVE-2025-53773, where a single prompt injection lets a developer agent modify its own configuration and achieve remote code execution. It details the hop-by-hop escalation and the key control that stops it.

0 favorites 0 likes
#remote-code-execution

KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066)

Lobsters Hottest · 2026-07-30 Cached

A critical remote code execution vulnerability (CVE-2026-66066) has been discovered in Ruby on Rails' Active Storage when using the default Vips image processor, affecting Rails 7.x and 8.x default configurations. Patches have been released and immediate upgrading is recommended.

0 favorites 0 likes
#remote-code-execution

CosmosEscape: Taking over Every Database in Azure Cosmos DB

Hacker News Top · 2026-07-30 Cached

Research reveals a critical vulnerability in Azure Cosmos DB's Gremlin API that could have allowed attackers to compromise all databases in the service, including Microsoft's internal ones. Microsoft has fully remediated the issue and no customer action is required.

0 favorites 0 likes
#remote-code-execution

@Dinosn: Dnsmasq DNS Remote Heap Buffer Overflow

X AI KOLs Timeline · 2026-07-20 Cached

A heap buffer overflow vulnerability in Dnsmasq (CVE-2026-2291) allows remote code execution via a malicious upstream DNS server. The issue was introduced in version 2.73 and fixed in 2.92rel2 and 2.93.

0 favorites 0 likes
#remote-code-execution

Hacking Apple - SQL Injection to Remote Code Execution — ProjectDiscovery Blog

Lobsters Hottest · 2026-07-12 Cached

A detailed write-up from ProjectDiscovery detailing how they discovered a critical SQL injection vulnerability in Apple's Book Travel portal via Masa/Mura CMS and achieved Remote Code Execution.

0 favorites 0 likes
#remote-code-execution

Hackers are exploiting a critical WordPress form plugin flaw to take over websites

Reddit r/ArtificialInteligence · 2026-06-05

Hackers are actively exploiting a critical remote code execution vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin, affecting versions up to 1.9.12. The flaw allows unescaped form values to be passed to eval(), enabling full site compromise. Wordfence urges immediate plugin updates.

0 favorites 0 likes
#remote-code-execution

New Nginx Exploit

Hacker News Top · 2026-05-14 Cached

A critical heap buffer overflow vulnerability in Nginx's rewrite module (CVE-2026-42945) allows unauthenticated remote code execution, with a proof-of-concept exploit released. The bug affects Nginx versions from 0.6.27 to 1.30.0 and various Nginx Plus releases.

0 favorites 0 likes
#remote-code-execution

Achieving NGINX Remote Code Execution via an 18-Year-Old Vulnerability

Lobsters Hottest · 2026-05-13 Cached

Researchers used an autonomous system to discover a critical heap buffer overflow vulnerability in NGINX's rewrite module (CVE-2026-42945), present since 2008, enabling remote code execution. Multiple CVEs were confirmed by NGINX.

0 favorites 0 likes
#remote-code-execution

Claude Code RCE: Exploiting Deeplink Handlers via Settings Injection

Lobsters Hottest · 2026-05-13 Cached

A security researcher discovered a Remote Code Execution (RCE) vulnerability in Claude Code caused by improper parsing of deeplink settings, allowing arbitrary command injection via hooks. The issue has been resolved in version 2.1.118.

0 favorites 0 likes
#remote-code-execution

The React2Shell Story and What Happened Next.js

Lobsters Hottest · 2026-05-09 Cached

This article details the discovery and disclosure of CVE-2025-5518 (React2Shell), a critical remote code execution vulnerability in React Server Components, explaining how researchers bypassed Flight protocol validations to access object prototypes.

0 favorites 0 likes
#remote-code-execution

The React2Shell Story

Hacker News Top · 2026-05-08 Cached

Security researcher Lachlan discovered and reported a critical remote code execution vulnerability dubbed "React2Shell" in React's Server Components protocol to Meta on November 30, 2025. Meta released a fix and public advisory (CVE-2025-55182) on December 3, urging developers to update immediately as the vulnerability affected millions of websites built with React/Next.js.

0 favorites 0 likes
← Back to home

Submit Feedback