LangChainGo vulnerability CVE-2025-9556 allows file reads
LangChainGo has a vulnerability, CVE-2025-9556, allowing arbitrary file reads through the Gonja template engine, exposing files.
Decision Insights Threat Desk • November 11, 2025
LangChainGo has a vulnerability, CVE-2025-9556, allowing arbitrary file reads through the Gonja template engine, exposing files.
Decision Insights Threat Desk • November 11, 2025
NPM supply chain compromise revealed on Sept. 15, 2025, impacts over 500 packages with malware Shai-Hulud and credential theft.
Decision Insights Threat Desk • November 11, 2025
Draytek reports a remote code execution vulnerability in Vigor routers' EasyVPN and LAN web interface, enabling command injection.
Decision Insights Threat Desk • November 11, 2025
Kiwire Captive Portal by SynchroWeb has three vulnerabilities, including SQL injection, open redirection, and XSS.
Decision Insights Threat Desk • November 11, 2025
An attacker could misuse Clevo's leaked keys to sign malicious firmware, compromising systems using Clevo's firmware.
Decision Insights Threat Desk • November 11, 2025
A DNS rebinding attack combined with CORS manipulation can lead to unauthorized access to sensitive data across private networks.