







A CVSS 8.7 vulnerability in GitHub Enterprise Server allows remote code execution. Read the threat brief and find vulnerable GHES instances from Wiz.
How an Omitted Write Barrier in V8 Turns Into RCE in Chrome: CVE-2026-5865
In March, our system detected a severe vulnerability in V8, the JavaScript engine used by Chrome. This vulnerability enabled remote code execution against billions of Chrome users worldwide.

GitHub - msanft/CVE-2025-55182: Explanation and full RCE PoC for CVE-2025-55182
Explanation and full RCE PoC for CVE-2025-55182. Contribute to msanft/CVE-2025-55182 development by creating an account on GitHub.
Mitigating High Severity RunC Vulnerability (CVE-2019-5736)
A high severity (CVSS score 7.2) vulnerability (CVE-2019-5763) was found in runc, allowing attackers to compromise the container host. Patches are already available from most providers. Aqua customers can prevent this vulnerability from being exploited by applying the appropriate runtime policies.

How We Exploited CodeRabbit: From a Simple PR to RCE and Write Access on 1M Repositories - Kudelski Security Research Center
Aug 19, 2025 - Nils Amiet -
Linux distributions worldwide targeted by the Copy Fail exploit
An exploit for the "Copy Fail" security vulnerability (CVE-2026-31431) in the Linux kernel has been made public. The vulnerability affects all major Linux

Introducing the Open-Source Codex Security CLI
Codex Security helps security and engineering teams find, confirm, and fix vulnerabilities. Use its command-line interface (CLI) to scan repositories you own or have permission to assess, review findings over time, and check changes before they land. Quickstart Guide for an interactive scan Cloud set-up for connected GitHub repositories Link to the public repo: Codex Security This is an early release, and we’re listening to your feedback as we continue improving it. The Codex Security CLI ...

Summary of CVE-2025-55182 - Vercel
Vercel has provided a patch for CVE-2025-55182 affecting any frameworks allowing Server Components usage.
A GitHub Issue Title Compromised 4,000 Developer Machines
A prompt injection in a GitHub issue triggered a chain reaction that ended with 4,000 developers getting OpenClaw installed without consent. The attack composes well-understood vulnerabilities into something new: one AI tool bootstrapping another.

GitHub MCP Exploited: Accessing private repositories via MCP
We showcase a critical vulnerability with the official GitHub MCP server, allowing attackers to access private repository data. The vulnerability is among the first discovered by Invariant's security analyzer for detecting toxic agent flows.

oss-security - Re: CVE request: io_uring zcrx freelist OOB write
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Chocapikk/CVE-2026-21858
n8n Ni8mare - Unauthenticated Arbitrary File Read to RCE Chain (CVSS 10.0)
GitHub - ejpir/CVE-2025-55182-poc: CVE-2025-55182 POC
CVE-2025-55182 POC. Contribute to ejpir/CVE-2025-55182-poc development by creating an account on GitHub.
High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478) › Searchlight Cyber
This morning, an advisory was released for Next.js about a vulnerability that leads to RCE in default configurations, with no prerequisites. The root cause of this issue lies in React Server Components, which Next.js utilizes. Over the last day, we have noticed an incredible amount of incorrect PoCs floating around on GitHub that do not

AI-SLOP: Develop best current practises for Open Source maintainers · Issue #178 · ossf/wg-vulnerability-disclosures
Open source projects are increasingly facing a wave of low-quality, AI-generated vulnerability reports and contributions—commonly referred to as "AI-slop." This issue aims to develop best...
Railway on Twitter / X
A critical RCE vulnerability was discovered in React Server Components. Railway has collaborated with Meta/Vercel teams & deployed a platform-level patch that blocks malicious requests matching this exploit pattern at our Web Application Firewall.Your service is protected while… https://t.co/8a5WWYshzN— Railway (@Railway) December 3, 2025
GitHub - openai/codex-security at 150d6f6bba5a00d9e3fcccf053fc25b68cee5a57
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security - openai/codex-security