PROBABLYPWNED
Home/Tag/Rce

Rce

48 articles tagged with "Rce"

PraisonAI Sandbox Bypass Scores Perfect CVSS 10
Vulnerabilities3 min read

PraisonAI Sandbox Bypass Scores Perfect CVSS 10

CVE-2026-34938 lets attackers escape PraisonAI's three-layer Python sandbox to execute arbitrary OS commands. CVSS 10 — patch to version 1.5.90 immediately.

Marcus ChenApr 4, 2026
n8n Merge Node Flaw Exposes 615K Instances to RCE
Vulnerabilities4 min read

n8n Merge Node Flaw Exposes 615K Instances to RCE

CVE-2026-33660 (CVSS 9.4) lets authenticated users escape n8n's AlaSQL sandbox via the Merge node. Over 615,000 public instances potentially vulnerable.

Marcus ChenMar 31, 2026
Four Critical n8n Flaws Enable Unauthenticated RCE
Vulnerabilities3 min read

Four Critical n8n Flaws Enable Unauthenticated RCE

n8n patches CVE-2026-27577, CVE-2026-27493, and two more sandbox escapes. One flaw allows unauthenticated attackers to execute commands via public form endpoints.

Marcus ChenMar 24, 2026
AVideo RCE Chain Gives Attackers Full Server Access Without Auth
Vulnerabilities3 min read

AVideo RCE Chain Gives Attackers Full Server Access Without Auth

Three vulnerabilities in AVideo's CloneSite plugin chain together for unauthenticated remote code execution. CVE-2026-33478 has no patch available as attackers can extract admin credentials and inject OS commands.

Marcus ChenMar 23, 2026
BeyondTrust Pre-Auth RCE Exposes 11,000 Systems
Vulnerabilities3 min read

BeyondTrust Pre-Auth RCE Exposes 11,000 Systems

CVE-2026-1731 allows unauthenticated remote code execution on BeyondTrust Remote Support and Privileged Remote Access products. CVSS 9.9 vulnerability affects 11,000+ exposed instances.

Marcus ChenFeb 12, 2026
Google Looker Flaws Let Attackers Hijack BI Servers
Vulnerabilities4 min read

Google Looker Flaws Let Attackers Hijack BI Servers

Tenable discloses 'LookOut' vulnerabilities in Google Looker enabling remote code execution and full database theft. Self-hosted deployments at 60,000+ organizations exposed.

Marcus ChenFeb 4, 2026
Redis RCE Exploit More Severe Than Initially Rated
Vulnerabilities3 min read

Redis RCE Exploit More Severe Than Initially Rated

JFrog researchers develop working remote code execution exploit for CVE-2025-62507, a stack buffer overflow in Redis discovered by Google's AI security agent.

Marcus ChenFeb 1, 2026
OpenSSL Stack Overflow Enables Remote Code Execution
Vulnerabilities5 min read

OpenSSL Stack Overflow Enables Remote Code Execution

CVE-2025-15467 allows attackers to crash or compromise systems by sending malicious CMS messages. All AI-discovered in OpenSSL's largest coordinated security release.

Marcus ChenJan 29, 2026
Coolify Command Injection Flaws Grant Root Access
Vulnerabilities4 min read

Coolify Command Injection Flaws Grant Root Access

Five critical vulnerabilities in the self-hosting platform allow authenticated users to execute arbitrary commands as root. Over 52,000 instances are exposed globally.

Marcus ChenJan 10, 2026