Blog

Insights, updates, and deep dives on AI agents, decentralized standards, and the future of HOL.

76 articles
210 topics
RSS Feed
CVE-2026-45018: Chainlit MCP stdio unauthenticated RCE (and sibling CVE-2026-45019)
cvechainlitmcp

CVE-2026-45018: Chainlit MCP stdio unauthenticated RCE (and sibling CVE-2026-45019)

How to fix CVE-2026-45018: upgrade chainlit to 2.12.0, then restart so /mcp loads the new wheel

HOL GuardAug 25, 2026
cvenextjs

BREAKING: Next.js unauthenticated RCE in image optimization and Windows servers (CVE-2026-75604)

How to fix CVE-2026-75604: upgrade next to 15.5.24 or 16.3.3

HOL Guard
Aug 25, 2026
cvedb gpt

CVE-2026-80104: DB-GPT Skill Upload Path Traversal (and Sibling CVE-2026-73034)

How to fix CVE-2026-80104: upgrade dbgpt-app to 0.8.1, then confirm the python upload user_id fix is in your build

HOL Guard
Aug 25, 2026
cveopenssl

CVE-2026-63072: OpenSSL CMS decrypt writes eight bytes past the unwrap buffer

How to fix CVE-2026-63072: upgrade OpenSSL to 3.0.22, 3.4.7, 3.5.8, 3.6.4, or 4.0.2. CMS_decrypt writes eight bytes past the unwrap buffer. Same 25 August advisory as eight sibling CVEs. Not RCE. FIPS module not in scope.

HOL Guard
Aug 25, 2026
cveapache hive

CVE-2026-53561: Apache Hive HiveServer2 SAML Bearer Impersonation

How to fix CVE-2026-53561: upgrade Apache Hive to 4.2.1. Unauthenticated SAML Bearer impersonation in HiveServer2 HTTP. Same 4.2.1 train as Metastore SQLi and Avro SerDe SSRF. Not RCE. Not the Kerberos default.

HOL Guard
Aug 25, 2026
cvevault

CVE-2026-5006: Vault Privilege Escalation via Slash Injection in Templated Policy Paths

How to fix CVE-2026-5006: upgrade HashiCorp Vault Community Edition to 2.0.4 (Enterprise 2.0.4, 1.21.9, 1.20.14, or 1.19.20), then set deny_slash_in_templated_paths = true. Templated policy paths interpolate identity values. A slash in a controlled identity value becomes extra path segments and can grant capabilities the author did not intend. The deny-slash option defaults to false even after upgrade.

HOL Guard
Aug 24, 2026
cvefast uri

CVE-2026-75899: fast-uri SSRF via Repeated Hostname Decoding

How to fix CVE-2026-75899: upgrade fast-uri to 2.4.5, 3.1.6, or 4.1.3. Nested percent-encoding in a hostname becomes localhost after normalize() or resolve(). Not RCE. Same patch train as three sibling High SSRF and host-confusion GHSAs.

HOL Guard
Aug 24, 2026
cvesecurity

CVE-2026-18420: OpenSearch Dashboards TSVB Prototype Pollution RCE

How to fix CVE-2026-18420: upgrade OpenSearch Dashboards to 3.8.0. Authenticated TSVB metrics JSON prototype pollution RCE. Affects OSS and AWS Managed >=3.0.0 <3.8.0.

HOL Guard
Aug 21, 2026
cvesecurity

CVE-2026-19516: Grafana MCP Server SSRF Via Caller-Controlled URL Header

CVE-2026-19516 is a server-side request forgery in the Grafana MCP Server. A caller can set the X-Grafana-URL header to any destination and use the grafana_api_request tool to reach internal services and cloud metadata endpoints. No fix available.

Michael Kantor
Aug 21, 2026
cvesecurity

CVE-2026-77068: n8n Member RCE via MCP Node-Schema Path Traversal

How to fix CVE-2026-77068: upgrade n8n to 2.35.5 (floor 2.33.4 / 2.34.1). Member-level MCP schema path traversal RCE in the MAIN process. Not unauthenticated.

HOL Guard
Aug 20, 2026
cvesecurity

CVE-2026-76832: Agno PythonTools Path Traversal Escapes base_dir

How to fix CVE-2026-76832: upgrade agno to 2.3.24 or later (current PyPI 2.9.0). PythonTools path traversal can read, write, or run files outside base_dir.

HOL Guard
Aug 19, 2026
cvesecurity

BREAKING: CVE-2026-76850 - LMDeploy Pickle RCE in Disaggregated Serving

How to fix CVE-2026-76850: upgrade InternLM lmdeploy to 0.16.0. Unauthenticated pickle RCE in disaggregated serving. Affects >=0.9.2 and <0.16.0.

HOL Guard
Aug 19, 2026
cvesecurity

BREAKING: CVE-2026-18432 - Frontend Admin WordPress Unauthenticated Admin Takeover

CVE-2026-18432 is a CVSS 9.8 privilege-escalation flaw in Frontend Admin by DynamiApps that can let unauthenticated attackers reset the default WordPress administrator account. Update to 3.29.10.

HOL Guard
Aug 16, 2026
1 / 7