The Lab · 2026-03-28 02:26:58 · GitHub Issues
A critical, reachable vulnerability has been confirmed in the core codebase of OpenBao's official plugin repository. The security flaw, identified as GO-2026-4762, is an authorization bypass within the gRPC-Go library, stemming from a missing leading slash in the HTTP/2 `:path` pseudo-header. Automated analysis by `gov...
The Lab · 2026-03-28 07:27:01 · GitHub Issues
A critical security flaw has been exposed in the widely-used Handlebars.js templating engine, enabling remote code execution through JavaScript injection. The vulnerability, tracked with a CVSS score of 9.8, stems from an AST (Abstract Syntax Tree) type confusion issue. This allows an attacker to potentially execute ar...
The Lab · 2026-03-29 02:26:52 · GitHub Issues
A critical, reachable security vulnerability has been identified in the `release/2.4.x` branch of the OpenBao project. The flaw, tracked as GO-2026-4762, is an authorization bypass in the gRPC-Go library, stemming from a missing leading slash in the `:path` header. Govulncheck analysis confirms the vulnerability is not...
The Lab · 2026-03-30 02:27:00 · GitHub Issues
A critical, reachable security vulnerability has been identified in the `release/2.4.x` branch of the OpenBao project. The flaw, tracked as GO-2026-4762, is an authorization bypass within the gRPC-Go library, stemming from a missing leading slash in the `:path` header. Govulncheck analysis confirms the vulnerable code ...
The Lab · 2026-03-31 10:27:06 · GitHub Issues
A sophisticated supply chain attack has compromised the official GitHub Actions for Trivy, a critical open-source security scanner used by millions of repositories. Threat actors, using stolen credentials, successfully published malicious releases and force-pushed nearly all version tags for the `aquasecurity/trivy-act...
The Lab · 2026-03-31 13:27:21 · GitHub Issues
A critical supply chain attack has compromised the widely-used `axios` HTTP client library. On March 31, 2026, the npm accounts of the axios lead maintainer were hijacked, leading to the publication of two malicious package versions: `[email protected]` and `[email protected]`. These tainted releases contained a hidden dependenc...
The Lab · 2026-04-01 02:27:01 · GitHub Issues
A critical supply chain attack has compromised the widely-used Axios HTTP client library on the npm registry. Malicious versions 1.14.1 and 0.30.4 have been published, containing a remote access trojan (RAT) designed to steal sensitive environment variables from infected systems. This is not a typical dependency confus...
The Lab · 2026-04-02 23:27:09 · GitHub Issues
A GitHub security scan has flagged the npm package `ejs-2.7.4.tgz` with three vulnerabilities, including two rated with a critical CVSS score of 9.8. The findings, which were automatically closed, highlight a severe and persistent risk for any project still dependent on this outdated version of the popular Embedded Jav...
The Lab · 2026-04-11 16:22:32 · GitHub Issues
A critical security flaw in the popular software composition analysis tool cdxgen has been exposed, revealing a pathway for attackers to exfiltrate sensitive keys and data. The vulnerability, which centers on the tool's handling of YAML and JSON configuration files, allows maliciously crafted scripts to leverage the `s...
The Lab · 2026-04-14 11:22:52 · GitHub Issues
A critical security update has been deployed for the widely-used Rust programming language crate, `rand`. The update patches a vulnerability, prompting an immediate minor version bump from `0.8.4` to `0.9.0` for core dependencies and a patch update from `0.10.0` to `0.10.1` for workspace dependencies. The presence of t...
The Lab · 2026-04-16 23:22:55 · GitHub Issues
A critical path traversal vulnerability has been disclosed in the widely-used Mako templating engine for Python, tracked as GHSA-v92g-xgxw-vvmm. The flaw resides in the `TemplateLookup.get_template()` function, which fails to properly sanitize user-supplied template URIs. Specifically, an attacker can exploit an incons...
The Lab · 2026-04-17 02:22:34 · GitHub Issues
A sophisticated supply chain attack has compromised the core release infrastructure of Aqua Security's Trivy, a widely used open-source vulnerability scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release and executed a destructive force-push operation, over...
The Lab · 2026-05-05 21:31:38 · GitHub Issues
A critical SQL injection vulnerability (CWE-89) in the drizzle-orm library went unpatched for an extended period before being addressed in version 0.45.2, raising questions about exposure in production systems that have not yet updated. The flaw resided in the `sql.identifier()` and `sql.as()` functions, where input va...
The Lab · 2026-05-12 07:48:26 · GitHub Issues
A critical CSS injection vulnerability has been identified in Mermaid, the widely-used open-source diagram and charting library. Tracked as CVE-2026-41159 (GHSA-87f9-hvmw-gh4p), the flaw stems from improper sanitization of user-supplied configuration options, allowing injected styles to apply beyond the boundaries of r...
The Lab · 2026-05-12 09:48:22 · The Hacker News Echo RSS
A threat actor identified as TeamPCP has launched a sophisticated supply chain attack campaign, dubbed "Mini Shai-Hulud," targeting npm and PyPI packages from TanStack, UiPath, Mistral AI, OpenSearch, and Guardrails AI. The campaign represents a significant escalation in the actor's ongoing campaign against software de...
The Lab · 2026-05-12 17:18:27 · Mastodon:mastodon.social:#cybersecurity
Linux maintainers have issued emergency patches for a second severe vulnerability within weeks, raising fresh concerns about the security of one of the world's most widely deployed operating systems. The development signals mounting pressure on system administrators to accelerate patch deployment cycles amid an unusual...
The Lab · 2026-05-12 19:48:25 · GitHub Issues
RubyGems has suspended new account registrations after hundreds of malicious packages infiltrated the official registry in what security researchers are characterizing as a coordinated supply chain attack. The move represents an extraordinary step for one of the open-source community's most critical package infrastruct...
The Lab · 2026-05-12 21:18:23 · Mastodon:mastodon.social:#infosec
Security researchers at Wiz.io have identified a new wave of supply chain attacks targeting the Tanstack ecosystem, with the threat actor tracked as "mini-shai-hulud" injecting malicious code into multiple NPM packages. The attack follows a pattern consistent with sophisticated open-source supply chain intrusions, wher...