Blog

Insights, updates, and deep dives on AI agents, decentralized standards, and the future of HOL.

53 articles
148 topics
RSS Feed
CVE-2026-9318: tablib Stored XSS via HTML Export Dataset Title
cvesecurityvulnerability

CVE-2026-9318: tablib Stored XSS via HTML Export Dataset Title

tablib, a Python tabular data library with over 147 million PyPI downloads, contains a stored cross-site scripting vulnerability in its HTML export functionality. Attackers can embed JavaScript payloads in dataset titles that execute when the exported HTML file is opened in a browser. Fixed in version 3.10.0.

Michael KantorAug 12, 2026
cvesecurity

CVE-2026-44763: Path Traversal in SAP MII Writes Files Outside Intended Directories

SAP Manufacturing Integration and Intelligence fails to validate file paths in certain functions. A privileged attacker can write files outside the intended directory, with high impact across confidentiality, integrity, and availability.

Michael Kantor
Aug 11, 2026
cvesecurity

CVE-2026-66763: SAP BusinessObjects CMS Stores Credentials Behind a Hardcoded Cryptographic Key

SAP BusinessObjects BI Platform CMS encrypts sensitive credentials with a hardcoded cryptographic key baked into the source code. Anyone with high privileges and local server access can extract and decrypt every stored password.

Michael Kantor
Aug 11, 2026
cvesecurity

CVE-2026-72693: kbd openvt Privilege Escalation Enables Passwordless Root Login

The kbd package, shipped on virtually every Linux distribution, contains a local privilege escalation in openvt -u. A flaw in how authenticate_user() verifies process ownership lets an unprivileged user trigger a passwordless login -f root on a new virtual terminal.

Michael Kantor
Aug 11, 2026
cvesecurity

CVE-2026-6791: glibc wordexp Stack Clash via Tilde Expansion

CVE-2026-6791 is a stack-based buffer overflow in glibc's wordexp() function. The parse_tilde internal function uses strndupa to allocate stack memory sized by attacker input with no bounds check, enabling a stack clash.

Michael Kantor
Aug 11, 2026
npmsupply chain

Keyv Supply Chain Attack: 2 Billion Monthly Downloads Compromised in npm Worm

Attackers compromised the GitHub account of keyv maintainer jaredwray, injecting a credential-stealing worm into 434+ npm packages with 2B+ monthly downloads.

HOL Guard
Aug 4, 2026
cvesecurity

CVE-2026-69240: Sequelize Oracle Dialect Allows SQL Injection via TO_TIMESTAMP Escape Bypass (CVSS 9.8)

Sequelize versions before 6.37.4 fail to escape single quotes for string values starting with TO_TIMESTAMP or TO_DATE when using the Oracle dialect. An attacker can inject arbitrary SQL through any application value that reaches this escape path.

HOL Guard
Aug 4, 2026
cvesecurity

CVE-2026-69240: Sequelize Oracle Dialect SQL Injection (CVSS 9.8)

SQL injection in Sequelize Oracle dialect via TO_TIMESTAMP escape bypass. Fixed in 6.37.4.

HOL Guard
Aug 4, 2026
cvesecurity

CVE-2026-38447: osTicket Generates Predictable API Keys via MD5 Hashing (CVSS 9.8)

osTicket 1.18.3 generates API keys using MD5 with predictable inputs (timestamp and client IP). An attacker can approximate the key generation time and brute-force the key space. Affects 5 million+ users and 15,000+ businesses worldwide.

HOL Guard
Aug 4, 2026
cvesecurity

CVE-2026-18108: Net::SAML2 Authentication Bypass via Unsigned Encrypted Assertions (CVSS 9.8)

Net::SAML2 before 0.86 accepts decrypted SAML assertions that carry no XML signature. Any party can encrypt an unsigned assertion to an SP's published certificate and authenticate as an arbitrary user. Affects Azure AD, Okta, Google, ADFS, and all other IdPs.

HOL Guard
Aug 4, 2026
cvesecurity

CVE-2026-53609: ApostropheCMS Prototype Pollution Leads to Authorization Bypass (CVSS 9.1)

ApostropheCMS's apos.util.set() allows authenticated editors to pollute Object.prototype via patch operators, bypassing authorization on all REST API endpoints for subsequent unauthenticated requests. CVSS 9.1. Fixed in version 4.31.0.

HOL Guard
Aug 3, 2026
cvesecurity

CVE-2026-52855: Pterodactyl Wings Leaks Daemon Configuration Secrets via Egg Templates (CVSS 9.9)

Pterodactyl Wings exposes its entire daemon configuration through egg configuration-file templating, leaking API keys, SFTP credentials, and database connection strings. CVSS 9.9. Fixed in version 1.12.3.

HOL Guard
Aug 3, 2026
pluginsplori

Introducing plori

A maintainer's guide to the plori plugin: what it does, who it helps, and how it pairs with Guard.

liu170045
Jul 29, 2026
1 / 5