Dettaglio notizia

Data 07/07/2026
Titolo Multiple Open Source Projects Disclose High-Impact RCE, Injection, and Traversal Flaws
Contesto Several open source projects disclosed serious vulnerabilities affecting developer and infrastructure tooling, including remote code execution, SQL injection, server-side request forgery, prompt-driven query injection, and path traversal. Coder Workspace Agent patched GHSA-QRWJ-VH9X-GW5V, a cross-agent SSRF flaw that let an authenticated attacker controlling one workspace agent abuse HTTP 307/308 redirects to replay privileged requests to another agent, enabling cross-tenant file access, file writes, and command execution; fixes were released in versions v2.34.4, v2.33.10, v2.32.9, and v2.29.19 ESR. Coolify disclosed a critical authenticated command injection issue tied to unsafe handling of deployment fields such as dockerfilelocation, allowing RCE and secrets exposure through deployment logs, while OpenRemote fixed GHSA-cgfv-jrfp-2r7v, an authenticated SQL injection bug in datapoint crosstab export that could expose other tenants’ data, Keycloak configuration, and encrypted credentials.

Additional disclosures affected AI and package-management components. Langroid fixed a prompt-injection-driven flaw in Neo4jChatAgent that executed LLM-generated Cypher without validation, allowing unauthorized graph operations and possible OS-level impact when dangerous Neo4j procedures were enabled; the issue was resolved in version 0.65.5 with new safety controls that were also extended to ArangoChatAgent. pnpm also reported a path traversal weakness in configDependencies processing from pnpm-lock.yaml, where a malicious repository could force symlink creation outside node
modules/.pnpm-config even with --ignore-scripts, creating a filesystem write primitive within or potentially beyond the project directory.
Fonte https://mallory.ai/stories/019f3a1e-9c92-7c90-a9b3-258ef7b78180
Discussione? Parliamone sul Forum