CISA issues advisory on ms-agent command injection
CISA reports a command injection flaw in ModelScope ms-agent that allows arbitrary OS commands via crafted prompt input.
Decision Insights Threat Desk • March 2, 2026
CISA reports a command injection flaw in ModelScope ms-agent that allows arbitrary OS commands via crafted prompt input.
Decision Insights Threat Desk • February 12, 2026
PyMuPDF 1.26.5 contains a path traversal that can write files to arbitrary local paths; PyMuPDF released version 1.26.7.
Decision Insights Threat Desk • February 10, 2026
CASL Ability 2.4.0–6.7.4 contains a prototype pollution flaw that can modify Object.prototype in Node.js.
Decision Insights Threat Desk • January 20, 2026
Open5GS WebUI defaults its JWT signing secret to "change-me," allowing attackers with WebUI access to forge administrative tokens.
Decision Insights Threat Desk • January 20, 2026
binary-parser for Node.js contains a code-injection flaw that can execute arbitrary JavaScript when parser definitions use untrusted input.
Decision Insights Threat Desk • January 20, 2026
CVE-2025-65586: libheif uncompressed decoder out-of-bounds read can crash applications that parse crafted HEIF images.