Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:npm/@tanstack/arktype-adapter

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builtins/code-mode.ts executes untrusted JavaScript with new Function() inside with(sandbox) and relies on a small source-code blocklist plus shadowed process and require properties. Code can use ({}).constructor.constructor to recover the real Function constructor, obtain process and process.mainModule.require, and reach host filesystem and subprocess APIs despite the advertised sandbox. Attackers who control codeMode input can read secrets, modify files, execute commands, or exhaust the host process. This issue is fixed in version 1.7.2.

Join the discussion

PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/sandbox-executor.ts validates only the first whitespace-delimited executable against allowedCommands, then SandboxExecutor passes the complete command string to sh -c. A command beginning with an allowed executable can append a non-allowlisted command through shell metacharacters, causing arbitrary commands to run with the PraisonAI process privileges. This issue is fixed in version 1.7.2.

Join the discussion

PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, createAgentLoop() in src/praisonai-ts/src/ai/agent-loop.ts passes executable tools to generateText() before invoking the onToolCall approval callback. Because the wrapped AI SDK executes tool handlers during generation, a callback that returns false records tool_rejected only after the denied tool has already produced side effects and populated toolResults. Applications using onToolCall as a human or policy approval boundary can therefore execute rejected file, command, API, or data-modifying operations. This issue is fixed in version 1.7.2.

Join the discussion

PraisonAI is a multi-agent teams system. Prior to 1.7.2, the codeMode tool in src/praisonai-ts/src/tools/builtins/code-mode.ts executes model-generated JavaScript with new Function() and with(sandbox), while a regular-expression blocklist can be bypassed with Function('return this')() to recover the global object and by constructing the child_process module name dynamically. An attacker who can influence the code argument can access host process capabilities, read or write files, obtain environment credentials, and execute operating-system commands with the PraisonAI process privileges. This issue is fixed in version 1.7.2.

Join the discussion

PraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 until 1.6.59 and PraisonAI 3.10.0 until 4.6.59, ToolsMCPServer.run_sse() in src/praisonai-agents/praisonaiagents/mcp/mcp_server.py mounts SseServerTransport on the legacy /sse and /messages/ endpoints without default Host, Origin, or authentication enforcement. A malicious website can use DNS rebinding against a reachable local or internal SSE server, supply attacker-controlled Host and Origin headers, enumerate registered tools, and invoke them with the server user's privileges. The Streamable HTTP transport rejects the same hostile Origin, which isolates the flaw to the legacy SSE wrapper. An initial remediation was released in praisonaiagents 1.6.59 and PraisonAI 4.6.59.

Join the discussion

OpenAM versions from 13.0.0 up to but not including 16.1.2 contain a cross-site scripting (XSS) vulnerability in the OAuth2 authorize endpoint's display=wap consent page. This flaw allows an attacker to craft a malicious authorization link that, when followed by a user with an active OpenAM session, executes JavaScript in the context of the OpenAM origin. Exploitation can lead to session or cookie theft, disclosure of CSRF tokens, and unauthorized actions performed with the victim's privileges. The vulnerability requires at least one registered OAuth2 client but does not require attacker control of that client. The issue is fixed in version 16.1.2.

Join the discussion

CVE-2025-13166 is an information exposure vulnerability in WSO2 Identity Server's SMS OTP flow. The system's error handling allows attackers to infer whether user accounts exist based on OTP initiation responses. This vulnerability particularly affects accounts without configured mobile numbers, enabling username enumeration. The exposure can aid attackers in brute force, social engineering, and information leakage attacks, potentially causing reputational and regulatory harm. The CVSS score is low, reflecting limited impact on confidentiality and no impact on integrity or availability.

Join the discussion

CVE-2025-5802 is an information disclosure vulnerability in WSO2 API Manager's self-registration flow. The system reveals whether a username already exists by returning explicit error messages during registration attempts. This allows attackers to enumerate valid usernames, which could aid in further attacks such as brute force or phishing. The vulnerability affects multiple versions of WSO2 API Manager prior to specific patch releases. The CVSS score is 5.3, indicating medium severity.

Join the discussion

CVE-2026-19515 is an OS command injection vulnerability in the WSO2 Integrator MI Visual Studio Code extension. The extension does not properly sanitize user input when processing Micro Integrator projects from untrusted sources, allowing crafted projects to execute arbitrary OS commands via the unit test execution flow. Exploitation requires the user to trust the malicious workspace and run unit tests. The impact depends on the privileges of the user running VS Code.

Join the discussion

CVE-2026-45051 is a critical deserialization vulnerability in OpenIdentityPlatform's OpenAM prior to version 16.1.1. The vulnerability arises because the WebAuthnAuthentication component loads a serialized AuthenticatorImpl object graph from a user attribute without applying an ObjectInputFilter. Exploitation requires the WebAuthn flow to be accessible and an attacker to have previously injected controlled serialized data via delegated administration, provisioning, directory access, legacy REST self-registration, or unsafe configuration. Successful exploitation can lead to execution of arbitrary code within the application server process. This issue is fixed in OpenAM version 16.1.1.

Join the discussion

Showing 1 to 10 of 131754 results

Filters:Package: pkg:npm/@tanstack/arktype-adapter
Page 1 of 13176
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses