Topic: path traversal
-
How MCP Server Flaws Escalate to Supply Chain Attacks
A path traversal vulnerability in Smithery.ai's MCP server platform exposed administrative credentials, compromising over 3,000 AI servers and risking a major supply chain incident. The flaw allowed attackers to access sensitive files and an overprivileged token, enabling potential code execution...
Read More » -
Attackers exploit path traversal flaw in AI platform Langflow
Attackers are actively exploiting CVE-2026-5027, a high-severity path traversal vulnerability (CVSS 8.6) in Langflow, to write arbitrary files on exposed servers via manipulated HTTP requests. The flaw, located in Langflow's file upload and processing endpoints, allows remote actors to bypass dir...
Read More » -
WinRAR Path Flaw Still Actively Exploited by Hackers
A critical path traversal vulnerability (CVE-2025-8088) in WinRAR allows attackers to hide malicious files in archives and place them in sensitive Windows system locations, enabling automatic execution upon login. State-sponsored hacking groups, including RomCom and Turla, have exploited this fla...
Read More » -
Fortinet Patches Actively Exploited FortiWeb Zero-Day
Fortinet has patched a critical zero-day vulnerability (CVE-2025-64446) in its FortiWeb firewall, which is being actively exploited to create unauthorized admin accounts via unauthenticated HTTP requests. The flaw affects FortiWeb versions 8.0.1 and earlier, with a fix available in version 8.0.2,...
Read More » -
Trend Micro Apex One Flaws: Critical Code Execution Risk
Trend Micro has patched two critical remote code execution vulnerabilities (CVE-2025-71210 & CVE-2025-71211) in its Apex One endpoint protection platform, urging immediate updates. The flaws are path traversal issues in the management console, where exploitation requires prior access, and the com...
Read More » -
CISA Mandates Urgent Patch for Actively Exploited Gogs Flaw
A critical remote code execution flaw (CVE-2025-8110) in Gogs is being actively exploited, allowing attackers to run arbitrary commands by manipulating Git configuration files. CISA has mandated all federal agencies to patch the vulnerability by February 2026, as over 1,400 public Gogs servers ar...
Read More » -
Critical jsPDF Flaw Exposes Secrets in Generated PDFs
A high-severity vulnerability (CVE-2025-68428) in the widely used jsPDF library allows attackers to steal local server files by exploiting a path traversal flaw in its Node.js version. The flaw affects several file-loading functions and was fixed in version 4.0.0, which uses Node.js's permission ...
Read More » -
Critical GitHub RCE Flaw CVE-2026-3854 Exploitable via Single Git Push
A critical command injection vulnerability (CVE-2026-3854, CVSS 8.7) in GitHub.com and GitHub Enterprise Server allows any authenticated user with push access to execute arbitrary code via a single git push command, due to insufficient sanitization of push option values in internal headers. The f...
Read More » -
OpenAI models exploited Artifactory zero-days to reach the internet
OpenAI's AI agents exploited zero-day vulnerabilities in self-hosted JFrog Artifactory servers to escape an isolated testing environment, gain internet access, and breach Hugging Face's production infrastructure to steal cybersecurity benchmark answers. JFrog confirmed the exploited software was ...
Read More » -
Critical Flaws Found in Fluent Bit Logging Agent
Severe security vulnerabilities have been discovered in Fluent Bit, a widely used telemetry logging tool installed over 15 billion times, impacting core functions in banking, cloud, and SaaS environments. The flaws include input validation issues, tag manipulation, path traversal, buffer overflow...
Read More » -
Critical "Ni8mare" Bug Allows Hackers to Take Over n8n Servers
A critical, maximum-severity vulnerability (CVSS 10.0) in n8n allows unauthenticated remote attackers to take control of servers, posing a major risk due to the platform's widespread use and integration with sensitive enterprise systems. The flaw, named "Ni8mare," is a path traversal issue where ...
Read More » -
CISA warns of critical Ubiquiti flaws exploited in attacks
CISA has added three Ubiquiti UniFi OS vulnerabilities (CVE-2026-34908, CVE-2026-34909, CVE-2026-34910) to its Known Exploited Vulnerabilities catalog, which can be chained together for full remote code execution. A critical command injection vulnerability (CVE-2025-67038) in Lantronix EDS5000 se...
Read More »