Security Center
安全情报屋
报告类型 当前榜单
情报总数 47 条
板块条数 47 条
生成时间 08-31 16:37
📚 安全情报馆 · 2026-08-31
4 块

🛡️ 每日安全情报

🛡️ AI 安全情报日报 · 2026-08-31

_2026-08-31 · 共筛出 6 条 ≥4★_

1. Claude安全机制大翻车,AI怒删开发者700GB主目录 🚨 ⚔️ ★★★★★

📋 Claude安全机制误删开发者700GB主目录,对抗性审查触发删除逻辑导致灾难性后果。

2. Exploit for CVE-2026-18963 🔓 ⚔️ ★★★★★

📋 CVE-2026-18963和CVE-2026-39816的PoC公开,CVSS评分9.1,高危漏洞。

3. Glass-Cage-iOS18-CVE-2025-24085-CVE-2025-24201 exploit 🔓 ⚔️ ★★★★★

📋 iOS 18漏洞CVE-2025-24085和CVE-2025-24201的PoC公开,CVSS评分10.0,严重漏洞。

4. Cisco 给 9 万员工配上个人 Agent:记住你的一切,还能替你跨系统办事 🚨 📄 ★★★★☆

📋 一名 Cisco 员工以后可能不必再依次打开 Outlook、Webex、Jira 和 SharePoint,自己翻邮件、找文件、建任务,再通知相关同事。 他只需要告诉一个 AI 自己希望得到什么结果。剩下的步骤,由 AI 判断应该调用哪些

5. Grok Bot王炸登场,深度接入X,全自动监测全球最新动态 🚨 📄 ★★★★☆

📋 Grok Bot 现在可以直接接入 X 了。 它不只是「能读 X 了」这么简单。你在 Grok Bot 里关联你的 X 账号,系统自动帮你创建开发者账号,付费用户还直接送你一笔 X API 的调用额度。 搜帖子,读时间线,查谁 @ 了你,汇

6. MongoDB 严重安全漏洞需立即修补 🔓 ★★★★☆

📋 MongoDB发现严重安全漏洞需立即修补,具体细节不详。

🚨 漏洞预警

🔴 CRITICAL · 20 条

1. CVE-2021-27850 🔥 ⚡近期活跃 `CVSS 10.0`

🎯 受影响:A critical unauthenticated remote code execution vulnerability was found all recent

📋 简介:A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry.

🔗 参考:

2. CVE-2026-60004 🔥 🆙 ⚡近期活跃 `CVSS 9.8`

🎯 受影响:Gitea

📋 简介:Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

🔗 参考:

3. CVE-2020-0618 🔥 ⚡近期活跃 `CVSS 9.8`

🎯 受影响:A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it inco

📋 简介:A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.

🔗 参考:

4. CVE-2026-82448 `CVSS 9.8`

🎯 受影响:Shinobi

📋 简介:Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries.

🔗 参考:

5. CVE-2019-10149 🔥 ⚡近期活跃 `CVSS 10.0`

🎯 受影响:A flaw was found in Exim

📋 简介:A flaw was found in Exim versions 4.87 to 4.91 (inclusive).

🔗 参考:

6. CVE-2023-20198 🔥 ⚡近期活跃 `CVSS 10.0`

🎯 受影响:Cisco

📋 简介:Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.

🔗 参考:

7. CVE-2026-82456 `CVSS 10`

🎯 受影响:argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions withou

📋 简介:argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured.

🔗 参考:

8. CVE-2023-50164 🔥 ⚡近期活跃 `CVSS 9.8`

🎯 受影响:An attacker can manipulate file upload params to enable paths traversal and under some circumstances

📋 简介:An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution.

🔗 参考:

9. CVE-2019-6453 🔥 ⚡近期活跃 `CVSS 8.1`

🎯 受影响:mIRC

📋 简介:mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers.

🔗 参考:

10. CVE-2020-0069 🔥 ⚡近期活跃 `CVSS 7.8`

🎯 受影响:ioctl handlers of the Mediatek Command Queue driver

📋 简介:In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions.

🔗 参考:

11. CVE-2026-82639 `CVSS 8.7`

🎯 受影响:NextChat

📋 简介:NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key.

🔗 参考:

12. CVE-2025-29927 🔥 🆙 ⚡近期活跃 `CVSS 9.1`

🎯 受影响:Next.js

📋 简介:Next.js is a React framework for building full-stack web applications.

🔗 参考:

13. CVE-2026-82466 `CVSS 9.4`

🎯 受影响:Rodauth

📋 简介:Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account.

🔗 参考:

14. CVE-2026-82645 `CVSS 9.2`

🎯 受影响:AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/vie

📋 简介:AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint.

🔗 参考:

15. CVE-2025-70290 🔥 ⚡近期活跃 `CVSS 9.8`

🎯 受影响:An issue was discovered in Denx U-Boot

📋 简介:An issue was discovered in Denx U-Boot before 2026.04.

🔗 参考:

16. CVE-2026-82452 `CVSS 9.8`

🎯 受影响:rust-iot-platform through commit 5df942ab

📋 简介:rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures.

🔗 参考:

17. CVE-2026-82454 `CVSS 9.3`

🎯 受影响:The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass i

📋 简介:The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification.

🔗 参考:

18. CVE-2026-82460 `CVSS 9.8`

🎯 受影响:Cloud Commander

📋 简介:Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization.

🔗 参考:

19. CVE-2026-82653 `CVSS 9.3`

🎯 受影响:SiYuan

📋 简介:SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments.

🔗 参考:

20. CVE-2026-82654 `CVSS 9.3`

🎯 受影响:SiYuan

📋 简介:SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions.

🔗 参考:

🟠 HIGH · 10 条

1. CVE-2026-56718 `CVSS 8.7`

🎯 受影响:AJCloud AJY IPC firmware

📋 简介:AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to read arbitrary files with root privileges by supplying path traversal sequences in the HTTP request URI.

🔗 参考:

2. CVE-2026-81636 `CVSS 8.7`

🎯 受影响:Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_graphql allows

📋 简介:Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_graphql allows an unauthenticated client to bypass the configured GraphQL query-complexity limit and force an unbounded database read.

🔗 参考:

3. CVE-2026-82638 `CVSS 8.7`

🎯 受影响:jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthe

📋 简介:jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery.

🔗 参考:

4. CVE-2026-82450 `CVSS 8.8`

🎯 受影响:BookStack

📋 简介:BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover.

🔗 参考:

5. CVE-2026-82473 `CVSS 8.8`

🎯 受影响:KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authe

📋 简介:KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification.

🔗 参考:

6. CVE-2026-82635 `CVSS 8.8`

🎯 受影响:Pake

📋 简介:Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization.

🔗 参考:

7. CVE-2026-82641 `CVSS 8.8`

🎯 受影响:keploy

📋 简介:keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data.

🔗 参考:

8. CVE-2026-82642 `CVSS 8.8`

🎯 受影响:Readest

📋 简介:Readest is an open-source e-book reader built on Tauri.

🔗 参考:

9. CVE-2026-82549 `CVSS 8.3`

🎯 受影响:A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to improper validation of integr

📋 简介:A vulnerability was identified in Linux Foundation Magma 1.9.0.

🔗 参考:

10. CVE-2026-82472 `CVSS 8.7`

🎯 受影响:Documenso

📋 简介:Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials.

🔗 参考:

---

新发现 52 条 · 热度升级 2 条 · 🔥=高热度/有 PoC · 🆙=昨日已推、今日热度升级

📊 GitHub 热榜

📈 GitHub 周榜 · 2026-08-31(本周热门)

1. freestylefly/awesome-gpt-image-2

📋 Prompt as Code | GPT-Image2 工业级提示词引擎与模板库,530+ 个案例逆向工程,20+ 套工业级模板,并提炼出Skills,持续更新中

2. anthropics/claude-plugins-community

📋 Community plugin marketplace for Claude Cowork and Claude Code. Read-only mirror — submit plugins at clau.de/plugin-directory-submission.

3. tt-a1i/archify

📋 Agent skill for beautiful, verifiable architecture, workflow, sequence, data-flow, and lifecycle diagrams—self-contained HTML with motion and crisp export.

4. omacom/omarchy

📋 Beautiful, Modern & Opinionated Linux

5. apache/maka

📋 Apache Maka (Incubating) is a local-first AI agent workspace. Model messages, tool calls, tool results, permission decisions, and termination events are recorded as an append-only log.

6. tashfeenahmed/freellmapi

📋 7.4 billion tokens per month. 34 free LLM providers. 635 free model endpoints. All behind one /v1 endpoint, plus any custom OpenAI-compatible endpoint. Smart routing, automatic failover, encrypted keys. Personal experimentation only.

7. MadsLorentzen/ai-job-search

📋 The job search that runs on your machine. AI job application framework built on Claude Code: evaluate postings, tailor CVs, write cover letters, prep interviews. Fork it and own it.

8. anthropics/claude-plugins-official

📋 Official, Anthropic-managed directory of high quality Claude Code Plugins.

9. AprilNEA/OpenLogi

📋 ⚡️A native, local-first alternative to Logitech Options+, written in Rust 🦀 — remap buttons, DPI, and SmartShift over HID++. No account, no telemetry.

10. rohitg00/ai-engineering-from-scratch

📋 Learn it. Build it. Ship it for others.

🤖 AI 总结分析

⚠️ AI 总结分析生成失败:APIConnectionError: litellm.APIConnectionError: litellm.APIError: APIError: OpenAIException - [trace_id: a4b4e6e4-bcc9-49fe-bd7a-e68b347ad964] Access forbidden: api key quota exceeded, key_id=uminferapikey-1on5ylfox8xk, daily_limit_amount=0 , monthly_limit_amount=2000 . All fallback attempts failed. Enable verbose logging with `litellm.set_verbose=True` for details.

Traceback (most recent call last):

File "/opt/security-center/trendradar/.venv/lib64/python3.12/site-packages/litellm/litellm_core_utils/asyncify.py", line 107, in run_async_function

_ = asyncio.get_running_loop()

^^^^^^^^^^^^^^^^^^^^^^^^^^

RuntimeError: no running event loop

During handling of the above exception, another exception occurred:

Traceback (most recent call last):

File "/opt/security-center/trendradar/.venv/lib64/python3.12/site-packages/litellm/main.py", line 1350, in completion

return completion_with_fallbacks(**args)

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

File "/opt/security-center/trendradar/.venv/lib64/python3.12/site-packages/litellm/litellm_core_utils/fallback_utils.py", line 80, in completion_with_fallbacks

return run_async_function(async_function=async_completion_with_fallbacks, **kwargs)

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

File "/opt/security-center/trendradar/.venv/lib64/python3.12/site-packages/litellm/litellm_core_utils/asyncify.py", line 116, in run_async_function

return run_in_new_loop()

^^^^^^^^^^^^^^^^^

File "/opt/security-center/trendradar/.venv/lib64/python3.12/site-packages/litellm/litellm_core_utils/asyncify.py", line 100, in run_in_new_loop

return new_loop.run_until_complete(async_function(*args, **kwargs))

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

File "/usr/lib64/python3.12/asyncio/base_events.py", line 691, in run_until_complete

return future.result()

^^^^^^^^^^^^^^^

File "/opt/security-center/trendradar/.venv/lib64/python3.12/site-packages/litellm/litellm_core_utils/fallback_utils.py", line 74, in async_completion_with_fallbacks

raise Exception(

Exception: litellm.APIError: APIError: OpenAIException - [trace_id: 49450b78-6179-46ea-b92f-2430666faf30] Access forbidden: api key quota exceeded, key_id=uminferapikey-1on5ylfox8xk, daily_limit_amount=0 , monthly_limit_amount=2000 LiteLLM Retried: 2 times. All fallback attempts failed. Enable verbose logging with `litellm.set_verbose=True` for details.

During handling of the above exception, another exception occurred:

Traceback (most recent call last):

File "/opt/security-center/trendradar/.venv/lib64/python3.12/site-packages/litellm/utils.py", line 1596, in wrapper

result = original_function(*args, **kwargs)

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

File "/opt/security-center/trendradar/.venv/lib64/python3.12/site-packages/litellm/main.py", line 4411, in completion

raise exception_type(

^^^^^^^^^^^^^^^

File "/opt/security-center/trendradar/.venv/lib64/python3.12/site-packages/litellm/litellm_core_utils/exception_mapping_utils.py", line 2456, in exception_type

raise e

File "/opt/security-center/trendradar/.venv/lib64/python3.12/site-packages/litellm/litellm_core_utils/exception_mapping_utils.py", line 2432, in exception_type

raise APIConnectionError(

litellm.exceptions.APIConnectionError: litellm.APIConnectionError: litellm.APIError: APIError: OpenAIException - [trace_id: 49450b78-6179-46ea-b92f-2430666faf30] Access forbidden: api key quota exceeded, key_id=uminferapikey-1on5ylfox8xk, daily_limit_amount=0 , monthly_limit_amount=2000 LiteLLM Retried: 2 times. All fallback attempts failed. Enable verbose logging with `litellm.set_verbose=True` for details.

Traceback (most recent call last):

File "/opt/security-center/trendradar/.venv/lib64/python3.12/site-packages/litellm/litellm_core_utils/asyncify.py", line 107, in run_async_function

_ = asyncio.get_running_loop()

^^^^^^^^^^^^^^^^^^^^^^^^^^

RuntimeError: no running event loop

During handling of the above exception, another exception occurred:

Traceback (most recent call last):

File "/opt/security-center/trendradar/.venv/lib64/python3.12/site-packages/litellm/main.py", line 1350, in completion

return completion_with_fallbacks(**args)

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

File "/opt/security-center/trendradar/.venv/lib64/python3.12/site-packages/litellm/litellm_core_utils/fallback_utils.py", line 80, in completion_with_fallbacks

return run_async_function(async_function=async_completion_with_fallbacks, **kwargs)

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

File "/opt/security-center/trendradar/.venv/lib64/python3.12/site-packages/litellm/litellm_core_utils/asyncify.py", line 116, in run_async_function

return run_in_new_loop()

^^^^^^^^^^^^^^^^^

File "/opt/security-center/trendradar/.venv/lib64/python3.12/site-packages/litellm/litellm_core_utils/asyncify.py", line 100, in run_in_new_loop

return new_loop.run_until_complete(async_function(*args, **kwargs))

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

File "/usr/lib64/python3.12/asyncio/base_events.py", line 691, in run_until_complete

return future.result()

^^^^^^^^^^^^^^^

File "/opt/security-center/trendradar/.venv/lib64/python3.12/site-packages/litellm/litellm_core_utils/fallback_utils.py", line 74, in async_completion_with_fallbacks

raise Exception(

Exception: litellm.APIError: APIError: OpenAIException - [trace_id: 49450b78-6179-46ea-b92f-2430666faf30] Access forbidden: api key quota exceeded, key_id=uminferapikey-1on5ylfox8xk, daily_limit_amount=0 , monthly_limit_amount=2000 LiteLLM Retried: 2 times. All fallback attempts failed. Enable verbose logging with `litellm.set_verbose=True` for details.

During handling of the above exception, another exception occurred:

Traceback (most recent call last):

File "/opt/security-center/trendradar/.venv/lib64/python3.12/site-packages/litellm/litellm_core_utils/asyncify.py", line 107, in run_async_function

_ = asyncio.get_running_loop()

^^^^^^^^^^^^^^^^^^^^^^^^^^

RuntimeError: no running event loop

During handling of the above exception, another exception occurred:

Traceback (most recent call last):

File "/opt/security-center/trendradar/.venv/lib64/python3.12/site-packages/litellm/main.py", line 1350, in completion

return completion_with_fallbacks(**args)

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

File "/opt/security-center/trendradar/.venv/lib64/python3.12/site-packages/litellm/litellm_core_utils/fallback_utils.py", line 80, in completion_with_fallbacks

return run_async_function(async_function=async_completion_with_fallbacks, **kwargs)

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

File "/opt/security-center/trendradar/.venv/lib64/python3.12/site-packages/litellm/litellm_core_utils/asyncify.py", line 116, in run_async_function

return run_in_new_loop()

^^^^^^^^^^^^^^^^^

File "/opt/security-center/trendradar/.venv/lib64/python3.12/site-packages/litellm/litellm_core_utils/asyncify.py", line 100, in run_in_new_loop

return new_loop.run_until_complete(async_function(*args, **kwargs))

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

File "/usr/lib64/python3.12/asyncio/base_events.py", line 691, in run_until_complete

return future.result()

^^^^^^^^^^^^^^^

File "/opt/security-center/trendradar/.venv/lib64/python3.12/site-packages/litellm/litellm_core_utils/fallback_utils.py", line 74, in async_completion_with_fallbacks

raise Exception(

Exception: litellm.APIError: APIError: OpenAIException - [trace_id: a4b4e6e4-bcc9-49fe-bd7a-e68b347ad964] Access forbidden: api key quota exceeded, key_id=uminferapikey-1on5ylfox8xk, daily_limit_amount=0 , monthly_limit_amount=2000 . All fallback attempts failed. Enable verbose logging with `litellm.set_verbose=True` for details.