Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Search: microsoft.net

Search Results: "microsoft.net"

Click on any threat for detailed analysis and mitigation recommendations

The npm package sme-rko-finance-front-payments-currency-payment-actions-operations-repeat-impl version 35.8.1 contains malicious code that downloads and executes an unsigned native binary from dynamically constructed Cloudflare Workers subdomains and a DNS-TXT covert-channel fallback. The binary is saved to temporary directories with names mimicking legitimate Microsoft.NET diagnostic tools and executed detached from the main process. The code attempts to disguise its behavior as telemetry with opt-out flags, but this is inconsistent with its actual malicious activity. No signature or integrity verification is performed on the downloaded binary, and the destination hosts are unrelated to the package's stated purpose.

Join the discussion

The npm package docsmate-docsmate-core version 35.9.3 contains malicious code that, upon import, downloads and executes an OS/architecture-specific binary from obfuscated Cloudflare Workers hostnames and fallback DNS-TXT resolver domains. The binary is saved under a disguised name mimicking a Microsoft.NET diagnostic tool and executed detached from the main process. This behavior is unexpected for a platform/core types library and indicates malicious intent to run unauthorized code on the host system.

Join the discussion

### Summary The array multiplication operator (`array * integer`) in Scriban allocates a result whose size is the product of the attacker-controlled integer and the array length, with **no `LoopLimit` / `LimitToString` check and no overflow-safe arithmetic**. A ~40-byte template forces a multi-gigabyte allocation, producing a denial-of-service. This is the unguarded sibling of operations that *were* hardened against the same class of abuse: `string * integer` (gated by a `LimitToString` pre-check), `array.insert_at` (gated by `StepLoop`/`LoopLimit` — the **GHSA-24c8-4792-22hx** fix shipped in 7.2.0, scored 8.7 High), and the range/iteration paths covered by **GHSA-c875-h985-hvrc** ("Built-in operations bypass LoopLimit", fixed 7.0.0). The same `LoopLimit`-based hardening pattern was applied to those operations but never to `array * integer`. This can be observed directly in 7.0.0, the release where GHSA-c875 was patched: `(1..5) * 50000000` (and `1..N | array.size`) correctly throws `Exceeding number of iteration limit '1000'`, while `[1,2,3,4,5] * 50000000` allocates ~2 GB with no limit. The `LoopLimit` control is enforced on the iteration path but not on the `array * int` allocation path, side by side, in the same version. The bug has been present since the operator was introduced in **3.0.0**, survives all of the 6.6.0 / 7.0.0 / 7.2.0 DoS-hardening passes, and is still present in 7.2.0 (current) — i.e. it is both a missed sibling of GHSA-24c8 and an incomplete coverage of GHSA-c875's `LoopLimit` hardening. ### Details The `array * int` operator is handled in `ScriptArray<T>.TryEvaluate`: ```csharp // src/Scriban/Runtime/ScriptArray.cs:504-508 (Multiply case) var newArray = new ScriptArray<T>(intModifier * array.Count); for (int i = 0; i < intModifier; i++) { newArray.AddRange(array); } ``` `intModifier` is the attacker-supplied integer (`context.ToInt(...)`, `ScriptArray.cs:399`). Two problems: 1. **No resource limit.** Neither `new ScriptArray<T>(intModifier * array.Count)` nor the `AddRange` loop consults `LoopLimit`, `LimitToString`, or calls `context.StepLoop(...)`. A grep of the entire `TryEvaluate` method (`ScriptArray.cs:360-560`) finds no `StepLoop` / `LoopLimit` / `Limit` reference. `LoopLimit` (default 1000) is therefore not enforced: a template that requests 250,000,000 elements creates them all without any "iteration limit" error. 2. **Integer overflow in the capacity.** `intModifier * array.Count` is unchecked `int` arithmetic. The overflow-safe `long` cast used by the string sibling is absent here. The DoS-hardening passes guarded the two sibling operations but not this one: ```csharp // src/Scriban/Syntax/Expressions/ScriptBinaryExpression.cs:341 (string * int — GUARDED) if (context.LimitToString > 0 && value > 0 && leftText.Length > 0 && (long)leftText.Length * value > context.LimitToString) // long arithmetic, pre-check { throw new ScriptRuntimeException(spanMultiplier, $"String multiplication exceeds LimitToString `{context.LimitToString}`."); } ``` ```csharp // src/Scriban/Functions/ArrayFunctions.cs:414 (array.insert_at — GUARDED, GHSA-24c8 fix in 7.2.0) for (int i = array.Count; i < index; i++) { context.StepLoop(span, ref loopStep); // LoopLimit enforced array.Add(null); } ``` `array * int` (`ScriptArray.cs:504`) received neither guard. When the oversized allocation fails as a managed exception, it is wrapped by the binary-expression evaluator: ```csharp // src/Scriban/Syntax/Expressions/ScriptBinaryExpression.cs:241-243 catch (Exception ex) when (!(ex is ScriptRuntimeException)) { throw new ScriptRuntimeException(span, ex.Message); } ``` So a host that wraps `Render()` in `try/catch` sees a `ScriptRuntimeException` carrying the original `OutOfMemoryException` message (or `ArgumentOutOfRangeException` on the integer-overflow path). ### PoC A single console project reproduces it on the released NuGet package. `poc.csproj`: ```xml <Project Sdk="Microsoft.NET.Sdk"> <PropertyGroup> <OutputType>Exe</OutputType> <TargetFramework>net8.0</TargetFramework> <!-- If only the .NET 9 SDK is installed, change to net9.0. Behavior is identical. --> </PropertyGroup> <ItemGroup> <PackageReference Include="Scriban" Version="7.2.0" /> </ItemGroup> </Project> ``` `Program.cs`: ```csharp using Scriban; // ~41-byte template requests 5 * 200,000,000 = 1,000,000,000 elements string tpl = "{{ x = [1,2,3,4,5] * 200000000; x.size }}"; System.Console.WriteLine("Rendering..."); var sw = System.Diagnostics.Stopwatch.StartNew(); var result = Template.Parse(tpl).Render(); // allocates ~7.7 GB System.Console.WriteLine($"size={result.Trim()} peakWS=" + System.Diagnostics.Process.GetCurrentProcess().PeakWorkingSet64 / (1024 * 1024) + "MB elapsed=" + sw.ElapsedMilliseconds + "ms"); ``` Run: ```sh dotnet run -c Release ``` Measured peak working set on Scriban 7.2.0 (net8.0, .NET 9 runtime, Linux), varying only the multip

Join the discussion

Showing 1 to 3 of 3 results

Filters:“microsoft.net”
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses