2026-06-24
2026-06-24 20:16Z
HIGH

CVE-2026-23879 — Python: Versions 1.1.2 and below contain an an arbitrary file write vulnerability, which allows symbolic

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-23879

py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Versions 1.1.2 and below contain an an arbitrary file write vulnerability, which allows symbolic links to be recreated outside the destination directory via crafted malicious symbolic link chains. When using extractall to extract an archive, the library restores these symbolic links, linking them to arbitrary directories on the host file system. During ex CVSSv3.1 8.0 (HIGH) · EPSS 32th percentile

CWECWE 59TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-24
2026-06-24 19:17Z
CRIT

CVE-2026-53943 — Ghost: From until 6.37.0, when Ghost is behind a shared caching layer that results in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53943

Ghost is a Node.js content management system. From until 6.37.0, when Ghost is behind a shared caching layer that results in cached content being shared between different visitors, an unauthenticated user could send an x-ghost-preview header that altered the rendered frontend response. In affected cache configurations, that response could be stored and served to subsequent visitors requesting the same page, allowing cache poisoning of request-specific preview output. When ru CVSSv3.1 9.6 (CRITICAL)

CWECWE 524VNDGhostTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-24
2026-06-24 19:17Z
CRIT

CVE-2026-49980 — Rclone: From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauthenticated GET and HEAD requests to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49980

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauthenticated GET and HEAD requests to paths of the form: /[remote:path]/object. The remote value is parsed from the URL and passed to normal backend initialization. Inline remote configuration can set backend options that execute local commands during initialization. As a result, a single unauthenticated GET o CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDRcloneTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-24
2026-06-24 19:17Z
HIGH

CVE-2026-49247 — Jellyfin: From 10.9.0 until 10.11.10, the POST /ClientLog/Document endpoint accepts the Authorization header's Client and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49247

Jellyfin is an open source self hosted media server. From 10.9.0 until 10.11.10, the POST /ClientLog/Document endpoint accepts the Authorization header's Client and Version fields and uses them unsanitized as components of the on-disk filename when persisting client-uploaded log documents. As a result, any authenticated non-admin user can include ../ sequences in the Client field to cause Jellyfin to write attacker-controlled content to arbitrary paths reachable by the Jellyf CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDJellyfinTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 19:17Z
HIGH

CVE-2026-48793 — Jellyfin: Prior to 10.11.10, a potential FFmpeg argument injection vulnerability exists in the subtitle conversion

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48793

Jellyfin is an open source self hosted media server. Prior to 10.11.10, a potential FFmpeg argument injection vulnerability exists in the subtitle conversion code path. SubtitleEncoder.ConvertTextSubtitleToSrtInternal (SubtitleEncoder.cs, line 382) interpolates the subtitle file path into FFmpeg command-line arguments without calling EncodingUtils.NormalizePath(). On Linux, filenames can contain double-quote characters, which break the argument quoting and allow injection of CVSSv3.1 8.8 (HIGH)

CWECWE 88VNDJellyfinTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 19:17Z
HIGH

CVE-2026-13038 — Use: after free in Autofill in Google Chrome on Windows prior to 149.0.7827.197 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13038

Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 19:17Z
HIGH

CVE-2026-13036 — Use: after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13036

Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-24
2026-06-24 19:17Z
HIGH

CVE-2026-13035 — Use: after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13035

Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a malicious peripheral. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 19:17Z
HIGH

CVE-2026-13033 — Out: of bounds read and write in Blink>InterestGroups in Google Chrome prior to 149.0.7827.197

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13033

Out of bounds read and write in Blink>InterestGroups in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 125CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 19:17Z
CRIT

CVE-2026-13032 — Use: after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13032

Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-24
2026-06-24 19:17Z
HIGH

CVE-2026-13031 — Use: after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13031

Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 19:17Z
CRIT

CVE-2026-13028 — Use: after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13028

Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-24
2026-06-24 19:17Z
HIGH

CVE-2026-13027 — Use: after free in FileSystem in Google Chrome prior to 149.0.7827.197 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13027

Use after free in FileSystem in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 19:17Z
HIGH

CVE-2026-13026 — Use: after free in Digital Credentials in Google Chrome on Mac prior to 149.0.7827.197

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13026

Use after free in Digital Credentials in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 19:17Z
HIGH

CVE-2026-13025 — Race: in DevTools in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13025

Race in DevTools in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 20VNDRaceTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-24
2026-06-24 18:17Z
HIGH

CVE-2026-48732 — Warp: From 0.2023.03.21.08.02.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection issue in the legacy SSH

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48732

Warp is an agentic development environment. From 0.2023.03.21.08.02.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection issue in the legacy SSH background command path. Warp used the remote working directory reported by the session when building helper commands for SSH-backed metadata collection. A remote host, repository, or directory name controlled by an attacker could cause that helper command to execute additional shell syntax on the remote ho CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDWarpTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 18:17Z
HIGH

CVE-2026-48725 — Warp: From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp allows terminal output to request access to the local

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48725

Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp allows terminal output to request access to the local system clipboard. A malicious remote host, remote program, or other attacker-controlled terminal output source can trigger clipboard reads or writes without a separate confirmation step. This crosses the trust boundary between untrusted terminal output and the user's local desktop clipboard. This vulnerabi CVSSv3.1 8.1 (HIGH)

CWECWE 276VNDWarpTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-24
2026-06-24 18:17Z
HIGH

CVE-2026-48721 — Warp: From 0.2025.10.08.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command execution permission-check bypass in the default

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48721

Warp is an agentic development environment. From 0.2025.10.08.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command execution permission-check bypass in the default unsandboxed CLI agent profile. The CLI profile is non-interactive and relies on a command denylist as a safety boundary for commands that should require confirmation. Because command strings were checked before canonicalizing leading environment-variable assignments, an attacker who can influ CVSSv3.1 8.6 (HIGH)

CWECWE 693CWECWE 180VNDWarpTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-24
2026-06-24 18:17Z
HIGH

CVE-2026-48720 — Warp: From 0.2025.03.05.08.02.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accepts non-inline `OSC 1337;File` payloads from terminal output and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48720

Warp is an agentic development environment. From 0.2025.03.05.08.02.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accepts non-inline `OSC 1337;File` payloads from terminal output and materialize the decoded payload as a local file without an additional confirmation step. This vulnerability is fixed in 0.2026.05.06.15.42.stable_01. CVSSv3.1 8.8 (HIGH)

CWECWE 73CWECWE 20VNDWarpTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 18:17Z
HIGH

CVE-2026-48719 — Warp: From 0.2025.08.06.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection in the prompt branch selector.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48719

Warp is an agentic development environment. From 0.2025.08.06.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection in the prompt branch selector. A user who can publish a branch to a Git repository opened in Warp can cause a crafted branch name to be interpreted by the victim's shell if the victim selects that branch from the UI. This vulnerability is fixed in 0.2026.05.06.15.42.stable_01. CVSSv3.1 8.0 (HIGH)

CWECWE 78VNDWarpTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-24
2026-06-24 18:17Z
HIGH

CVE-2026-48704 — Warp: From 0.2023.10.24.08.03.stable_00 until 0.2026.05.06.15.42.stable_01, Warp may open executable local files through the operating system

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48704

Warp is an agentic development environment. From 0.2023.10.24.08.03.stable_00 until 0.2026.05.06.15.42.stable_01, Warp may open executable local files through the operating system default file handler. A malicious Markdown document or project can contain a local-file link that appears as normal rendered content. If a user opens the Markdown in Warp and clicks the link, affected builds may route the resolved local file to a platform file opener instead of limiting the action t CVSSv3.1 8.8 (HIGH)

CWECWE 20VNDWarpTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 18:17Z
HIGH

CVE-2026-44016 — Docling: FIn versions >= 2.82.0, < 2.91.0, if the HTML backend was explicitly configured for

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44016

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. FIn versions >= 2.82.0, < 2.91.0, if the HTML backend was explicitly configured for rendering (rendering option by default deactivated), then the Playwright-based rendering feature could allow JavaScript execution and unrestricted network access when processing untrusted HTML documents. An attacker could craft malicious HTML that executes arbitrary Ja CVSSv3.1 8.2 (HIGH)

CWECWE 94CWECWE 918VNDDoclingTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-24
2026-06-24 17:29Z
INFO

Disposable Tooling: Building LLM-Generated Mythic Agents from Prompt to Deployment

SpecterOps·specterops.io

SpecterOps researcher Adam Chester documents a multi-month exploration of using LLMs (Claude Opus 4.6) to automatically generate fully functional Mythic C2 agents from natural-language prompts, progressing from initial failures through iterative harness engineering (mock servers, tiered testing, supporting tools like Oracle, LabKit, and Mythicd) to achieve end-to-end autonomous agent generation with minimal human intervention.

SRFApplicationSRFOsSWMythicSWClaudeTYPResearchTYPToolSTGExecutionSTGC2
72
Edit Score
2026-06-24
2026-06-24 17:17Z
CRIT

CVE-2026-54906 — Rubyconcurrency Concurrent_ruby: concurrent-ruby is a modern concurrency tools for Ruby.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54906

concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReadWriteLock#release_write_lock does not verify that the calling thread acquired the write lock. Any thread with access to the lock object can release an active write lock held by another thread. A second writer can then enter its critical section while the first writer is still running. Concurrent::ReadWriteLock#release_read_lock also decrements the shared counter even when no read lock is h CVSSv3.1 9.8 (CRITICAL) · EPSS 0th percentile

CWECWE 667CWECWE 414VNDRubyconcurrencyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-24
2026-06-24 17:17Z
HIGH

CVE-2026-53091 — Linux: In the Linux kernel, the following vulnerability has been resolved: net: pull headers in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53091

In the Linux kernel, the following vulnerability has been resolved: net: pull headers in qdisc_pkt_len_segs_init() Most ndo_start_xmit() methods expects headers of gso packets to be already in skb->head. net/core/tso.c users are particularly at risk, because tso_build_hdr() does a memcpy(hdr, skb->data, hdr_len); qdisc_pkt_len_segs_init() already does a dissection of gso packets. Use pskb_may_pull() instead of skb_header_pointer() to make sure drivers do not have to reim CVSSv3.1 8.4 (HIGH) · EPSS 5th percentile

TYPVulnerability
8.4
CVSS v3.1
92
Edit Score