<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>PlainCVE</title><description>把真實漏洞寫成看得懂、查得到來源的說明書:誰會受影響、攻擊怎麼發生、該怎麼修補與偵測。</description><link>https://plaincve.date/</link><language>zh-Hant-TW</language><item><title>CVE-2026-12537 Gemini CLI 在 CI 中自動信任工作目錄:外部 PR 裡的 .gemini/.env 可在沙箱啟動前於主機執行指令</title><link>https://plaincve.date/vulns/cve-2026-12537-gemini-cli-headless-workspace-trust/</link><guid isPermaLink="true">https://plaincve.date/vulns/cve-2026-12537-gemini-cli-headless-workspace-trust/</guid><description>Gemini CLI 在 CI 無人值守模式下自動信任工作目錄,外部 PR 夾帶的惡意 .gemini/.env 可在沙箱啟動前於主機上執行指令。</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>gemini-cli</category><category>github-actions</category><category>ci-cd</category><category>workspace-trust</category><category>ai-agent</category><category>command-injection</category><category>CVE-2026-12537</category></item><item><title>CVE-2026-33017 Langflow 公開流程端點遠端程式碼執行:不用登入就能在伺服器上執行任意 Python</title><link>https://plaincve.date/vulns/cve-2026-33017-langflow-public-flow-rce/</link><guid isPermaLink="true">https://plaincve.date/vulns/cve-2026-33017-langflow-public-flow-rce/</guid><description>Langflow 執行公開流程的端點不需登入,卻會執行呼叫者自己送來的 Python 程式碼,攻擊者可藉此接管伺服器。已遭實際利用。</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>langflow</category><category>rce</category><category>code-injection</category><category>missing-authentication</category><category>python</category><category>ai-pipeline</category><category>CVE-2026-33017</category></item><item><title>CVE-2026-45758 guardrails-ai 0.10.1 遭植入惡意程式:AI 安全函式庫的 PyPI 供應鏈入侵</title><link>https://plaincve.date/vulns/cve-2026-45758-guardrails-ai-pypi-compromise/</link><guid isPermaLink="true">https://plaincve.date/vulns/cve-2026-45758-guardrails-ai-pypi-compromise/</guid><description>攻擊者用偷來的上傳權杖把惡意的 guardrails-ai 0.10.1 發佈到 PyPI;在 Linux 上一 import 就會下載並執行遠端程式。</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>pypi</category><category>python</category><category>malicious-package</category><category>ci-cd</category><category>credential-theft</category><category>shai-hulud</category><category>llm-guardrails</category><category>CVE-2026-45758</category></item><item><title>CVE-2026-48501 GitHub CLI 驗證指令洩漏登入權杖:gh attestation 與 gh release verify 會把 token 送到 TUF 和檔案主機</title><link>https://plaincve.date/vulns/cve-2026-48501-github-cli-token-leak/</link><guid isPermaLink="true">https://plaincve.date/vulns/cve-2026-48501-github-cli-token-leak/</guid><description>GitHub CLI 2.93.0 以前,執行三個驗證指令時可能把你的 GitHub 登入權杖附在送往 TUF 與檔案主機的請求裡。</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>github-cli</category><category>credential-leak</category><category>token</category><category>sigstore</category><category>tuf</category><category>attestation</category><category>go</category><category>CVE-2026-48501</category></item><item><title>CVE-2026-50016 pnpm 相依套件別名路徑穿越:間接相依套件可在安裝時把專案資料夾換成符號連結,--ignore-scripts 也擋不住</title><link>https://plaincve.date/vulns/cve-2026-50016-pnpm-alias-path-traversal/</link><guid isPermaLink="true">https://plaincve.date/vulns/cve-2026-50016-pnpm-alias-path-traversal/</guid><description>pnpm 安裝時沒擋住別名裡的「..」,相依樹深處的惡意套件能把專案路徑換成指向自己的符號連結,--ignore-scripts 也無效。</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>pnpm</category><category>npm</category><category>javascript</category><category>path-traversal</category><category>symlink</category><category>ignore-scripts</category><category>transitive-dependency</category><category>CVE-2026-50016</category></item><item><title>CVE-2026-5241 Hugging Face Transformers LightGlue 載入流程:模型設定檔可以蓋掉 trust_remote_code=False,執行模型附帶的程式碼</title><link>https://plaincve.date/vulns/cve-2026-5241-transformers-lightglue-remote-code-override/</link><guid isPermaLink="true">https://plaincve.date/vulns/cve-2026-5241-transformers-lightglue-remote-code-override/</guid><description>Transformers 5.5.0 以前,LightGlue 模型自己的設定檔可以蓋掉呼叫者設的 trust_remote_code=False,讓模型附帶的 Python 程式碼被執行。</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>huggingface</category><category>transformers</category><category>trust-remote-code</category><category>model-supply-chain</category><category>python</category><category>code-execution</category><category>CVE-2026-5241</category></item><item><title>CVE-2026-82021 Hermes Agent 內建 MCP 目錄釘選分支而非 commit:上游若被接管,安裝就會執行別人的程式碼</title><link>https://plaincve.date/vulns/cve-2026-82021-hermes-agent-mcp-unpinned-branch/</link><guid isPermaLink="true">https://plaincve.date/vulns/cve-2026-82021-hermes-agent-mcp-unpinned-branch/</guid><description>Hermes Agent 內建 MCP 目錄的 n8n 橋接項目指向會變動的分支;若上游儲存庫被接管,安裝時就會執行對方放進去的程式碼。目前沒有遭利用的紀錄。</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>mcp</category><category>ai-agent</category><category>version-pinning</category><category>git</category><category>n8n</category><category>integrity-check</category><category>CVE-2026-82021</category></item><item><title>CVE-2026-90553 vLLM LlavaOnevision2 忽略 trust_remote_code:設定不執行模型程式碼,惡意模型的程式碼仍會執行</title><link>https://plaincve.date/vulns/cve-2026-90553-vllm-llavaonevision2-remote-code-ignored/</link><guid isPermaLink="true">https://plaincve.date/vulns/cve-2026-90553-vllm-llavaonevision2-remote-code-ignored/</guid><description>vLLM 0.28.0 以前載入 LlavaOnevision2 模型時會忽略 trust_remote_code=False,惡意模型附帶的 Python 程式碼仍會執行。</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>vllm</category><category>trust-remote-code</category><category>model-supply-chain</category><category>python</category><category>kwargs</category><category>multimodal</category><category>CVE-2026-90553</category></item><item><title>CVE-2026-26030 Microsoft Semantic Kernel(Python)InMemoryVectorStore 篩選條件被當成程式執行</title><link>https://plaincve.date/vulns/cve-2026-26030-semantic-kernel-filter-rce/</link><guid isPermaLink="true">https://plaincve.date/vulns/cve-2026-26030-semantic-kernel-filter-rce/</guid><description>AI 模型替搜尋外掛填的篩選參數,會被 Semantic Kernel 拼成一段 Python 程式再執行;透過提示注入誘導模型,就可能在伺服器上執行任意程式。</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate><category>prompt-injection</category><category>llm</category><category>agent</category><category>python</category><category>eval</category><category>rce</category><category>CVE-2026-26030</category></item><item><title>CVE-2026-33634 Trivy 供應鏈攻擊:資安掃描工具被植入竊密程式,一路擴散到 LiteLLM 與 Checkmarx</title><link>https://plaincve.date/vulns/cve-2026-33634-trivy-supply-chain/</link><guid isPermaLink="true">https://plaincve.date/vulns/cve-2026-33634-trivy-supply-chain/</guid><description>攻擊者取得 Trivy 的發布權限後,讓官方版本與 GitHub Action 夾帶竊密程式;用它掃描的 CI 流程金鑰被偷,再被拿去污染 LiteLLM 等其他專案。</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate><category>github-actions</category><category>ci-cd</category><category>credential-theft</category><category>pypi</category><category>docker-hub</category><category>trivy</category><category>litellm</category><category>CVE-2026-33634</category></item><item><title>CVE-2026-45321 TanStack npm 供應鏈入侵(Mini Shai-Hulud):發布流程被劫持,42 個 @tanstack 套件被植入竊取憑證的惡意程式</title><link>https://plaincve.date/vulns/cve-2026-45321-tanstack-npm-supply-chain-compromise/</link><guid isPermaLink="true">https://plaincve.date/vulns/cve-2026-45321-tanstack-npm-supply-chain-compromise/</guid><description>攻擊者劫持 TanStack 的 GitHub 發布流程,以官方身分在 42 個 @tanstack/* npm 套件發布 84 個會竊取憑證的惡意版本;已列入 CISA KEV。</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate><category>npm</category><category>github-actions</category><category>pull-request-target</category><category>cache-poisoning</category><category>oidc</category><category>worm</category><category>mini-shai-hulud</category><category>credential-theft</category><category>kev</category><category>CVE-2026-45321</category></item><item><title>CVE-2026-59822 LiteLLM Proxy MCP 閘道認證繞過:隨便一組 token 都能呼叫 MCP 工具</title><link>https://plaincve.date/vulns/cve-2026-59822-litellm-mcp-auth-bypass/</link><guid isPermaLink="true">https://plaincve.date/vulns/cve-2026-59822-litellm-mcp-auth-bypass/</guid><description>LiteLLM Proxy 的 MCP 端點在驗證失敗時沒有拒絕請求,反而以匿名身分放行;不需帳號就能列出並呼叫背後串接的 MCP 工具。已遭實際利用。</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate><category>mcp</category><category>llm-gateway</category><category>authentication</category><category>python</category><category>fail-open</category><category>CVE-2026-59822</category></item><item><title>CVE-2026-94127 F5 BIG-IP APM OAuth 授權伺服器堆積溢位:未登入即可遠端執行程式碼,已遭零時差利用</title><link>https://plaincve.date/vulns/cve-2026-94127-f5-big-ip-apm-oauth-heap-overflow/</link><guid isPermaLink="true">https://plaincve.date/vulns/cve-2026-94127-f5-big-ip-apm-oauth-heap-overflow/</guid><description>F5 BIG-IP APM 當作 OAuth 授權伺服器時有堆積緩衝區溢位,未登入的攻擊者可遠端執行程式碼;已被當成零時差漏洞實際利用。</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate><category>f5</category><category>big-ip</category><category>apm</category><category>oauth</category><category>heap-overflow</category><category>rce</category><category>zero-day</category><category>kev</category><category>edge-device</category><category>CVE-2026-94127</category></item><item><title>axios npm 套件遭投毒:維護者帳號被盜,1.14.1 與 0.30.4 夾帶遠端控制木馬</title><link>https://plaincve.date/vulns/ghsa-2026-axios-npm-compromise/</link><guid isPermaLink="true">https://plaincve.date/vulns/ghsa-2026-axios-npm-compromise/</guid><description>攻擊者盜用 axios 維護者的 npm 帳號,發布兩個夾帶惡意相依套件的版本;只要 npm install,就會在電腦上裝好一個遠端控制木馬。</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate><category>npm</category><category>javascript</category><category>account-takeover</category><category>postinstall</category><category>rat</category><category>north-korea</category></item></channel></rss>