security-vulnerability

Tag

Cards List
#security-vulnerability

KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066)

Lobsters Hottest · 2026-07-30 Cached

A critical remote code execution vulnerability (CVE-2026-66066) has been discovered in Ruby on Rails' Active Storage when using the default Vips image processor, affecting Rails 7.x and 8.x default configurations. Patches have been released and immediate upgrading is recommended.

0 favorites 0 likes
#security-vulnerability

I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID

Lobsters Hottest · 2026-06-17 Cached

A security researcher discovered that registering as a FIFA agent granted access to FIFA's Microsoft Entra tenant, allowing them to bypass client-side authentication and access the live production streaming management panel for the 2026 World Cup, including RTMP stream keys for all matches. The researcher had to contact FIFA, MediaKind, HBS, CISA, and the FBI to get the issue fixed.

0 favorites 0 likes
#security-vulnerability

CVE-2026-48710: A Maintainer's Perspective

Lobsters Hottest · 2026-05-29 Cached

Marcelo Trylesinski shares his perspective on CVE-2026-48710, a security vulnerability in Starlette involving path-based authorization bypass via manipulated Host headers. He argues the vulnerability stems from application patterns and deployment, not the framework itself.

0 favorites 0 likes
#security-vulnerability

CVE-2026-48710 Starlette Host-Header Auth Bypass

Lobsters Hottest · 2026-05-27 Cached

A critical host-header authentication bypass vulnerability (CVE-2026-48710) in Starlette and FastAPI affects many Python ASGI applications, including AI inference servers (e.g., vLLM), AI proxy servers (e.g., LiteLLM), and MCP gateways, potentially allowing unauthorized access.

0 favorites 0 likes
#security-vulnerability

Millions of AI agents imperiled by critical vulnerability in open source package

Ars Technica · 2026-05-26 Cached

A critical vulnerability (CVE-2026-48710, named BadHost) in the open-source ASGI framework Starlette exposes millions of AI agents and servers to potential data theft and credential compromise, affecting frameworks like FastAPI, vLLM, and LiteLLM. Patched in Starlette 1.0.1, the flaw is trivial to exploit and underscores risks in the AI tooling ecosystem.

0 favorites 0 likes
#security-vulnerability

Does Anybody Actually Like React?

Hacker News Top · 2026-05-26 Cached

A compilation of critical blog posts about React, covering performance issues, a critical security vulnerability (CVE-2025-55182, CVSS 10.0), and broader ecosystem concerns.

0 favorites 0 likes
#security-vulnerability

the may 2026 fedi software vulnerability

Lobsters Hottest · 2026-05-20 Cached

A critical vulnerability in Fediverse software (Mastodon, Misskey, and forks) related to Linked Data Signatures was discovered by Anthropic via Doyensec. The vulnerability allows property reordering via JSON-LD expansion, enabling attackers to exploit signed objects.

0 favorites 0 likes
#security-vulnerability

@Star_Knight12: Next.js just got its worst vulnerability ever, CVSS 8.6. → affects versions 13.4.13+, 14.x, 15.x, and 16.0.0–16.2.4 → a…

X AI KOLs Following · 2026-05-14

Next.js has a critical vulnerability (CVSS 8.6) affecting versions 13.4.13+, 14.x, 15.x, and 16.0.0–16.2.4, allowing unauthenticated attackers to access internal services, cloud credentials, and API keys. Upgrade to 15.5.16 or 16.2.5 immediately.

0 favorites 0 likes
#security-vulnerability

YellowKey Bitlocker Bypass Vulnerability

Lobsters Hottest · 2026-05-13 Cached

YellowKey is a proof-of-concept exploit that bypasses BitLocker encryption on Windows 11 by leveraging a vulnerability in the Windows Recovery Environment, allowing unrestricted access to protected volumes.

0 favorites 0 likes
#security-vulnerability

Claude Code RCE: Exploiting Deeplink Handlers via Settings Injection

Lobsters Hottest · 2026-05-13 Cached

A security researcher discovered a Remote Code Execution (RCE) vulnerability in Claude Code caused by improper parsing of deeplink settings, allowing arbitrary command injection via hooks. The issue has been resolved in version 2.1.118.

0 favorites 0 likes
#security-vulnerability

Critical Ollama Bugs Expose AI Servers to Memory Leaks and Windows RCE

Reddit r/ArtificialInteligence · 2026-05-11 Cached

Critical security vulnerabilities in Ollama, including a memory leak exploit dubbed 'Bleeding Llama' and a Windows RCE flaw, have been disclosed, prompting urgent upgrades for users.

0 favorites 0 likes
#security-vulnerability

My Agentic Trust Issues: From Prompt Injection to Supply-Chain Compromise on gemini-cli

Lobsters Hottest · 2026-05-09 Cached

Pillar Security researchers disclosed a critical CVSS 10 vulnerability (TrustIssues) in Google's gemini-cli and related GitHub workflows, where prompt injection allowed attackers to exfiltrate secrets and compromise the repository supply chain.

0 favorites 0 likes
#security-vulnerability

The React2Shell Story and What Happened Next.js

Lobsters Hottest · 2026-05-09 Cached

This article details the discovery and disclosure of CVE-2025-5518 (React2Shell), a critical remote code execution vulnerability in React Server Components, explaining how researchers bypassed Flight protocol validations to access object prototypes.

0 favorites 0 likes
#security-vulnerability

CVE-2026-31431: Copy Fail

Lobsters Hottest · 2026-05-08 Cached

CVE-2026-31431 (Copy Fail) is a local privilege escalation vulnerability in the Linux kernel affecting all major distributions since 2017, allowing unprivileged users to gain root shell access through a deterministic 4-byte write to any readable file's page cache via the AF_ALG crypto subsystem.

0 favorites 0 likes
#security-vulnerability

Copy Fail 2: Electric Boogaloo

Lobsters Hottest · 2026-05-08 Cached

Copy Fail 2 is a proof-of-concept exploit for an unprivileged Linux Local Privilege Escalation (LPE) vulnerability in the kernel's xfrm subsystem, allowing attackers to gain root access on modern distributions.

0 favorites 0 likes
#security-vulnerability

GNU IFUNC is the real culprit behind CVE-2024-3094

Hacker News Top · 2026-05-08 Cached

The article argues that GNU IFUNC and design decisions linking OpenSSH to SystemD were the primary enablers of the CVE-2024-3094 xz-utils backdoor, rather than the malicious code itself.

0 favorites 0 likes
#security-vulnerability

Anthropic Claude Code Leak Reveals Critical Command Injection Vulnerabilities

Lobsters Hottest · 2026-04-19 Cached

Critical command injection vulnerabilities (CVE-2026-35022, CVSS 9.8) discovered in Anthropic's Claude Code CLI and SDK allow attackers to execute arbitrary commands and steal credentials through environment variables, file paths, and authentication helpers. The flaws enable poisoned pipeline execution attacks in CI/CD environments, requiring immediate patching and configuration changes.

0 favorites 0 likes
← Back to home

Submit Feedback