Auth.js Email Normalizer Bypass Flaw
A critical vulnerability in Auth.js and NextAuth allows attackers to intercept magic-link sign-in flows by exploiting improper Unicode normalization.
From zero-day disclosures to routine patch Tuesdays, this is Xploitwire's feed on the vulnerabilities and advisories that security teams actually need to act on — what's exploitable, what's patched, and what to prioritize first.
A critical vulnerability in Auth.js and NextAuth allows attackers to intercept magic-link sign-in flows by exploiting improper Unicode normalization.
A configuration error in Auth.js v5 causes authentication checks to fail open, granting unauthorized access to protected resources.
Researchers identify a recurring security flaw where AI agents blindly execute commands based on predictable, hallucinated names.
A critical vulnerability in the Alibaba Fastjson library allows unauthorized code execution in specific Spring Boot configurations.
Researchers find top AI models consistently inventing identical, non-existent library names that attackers could potentially weaponize.
A critical authorization vulnerability in SiYuan before v3.7.2 allows unauthenticated remote attackers to gain full administrative control over the workspace.
A malicious campaign targeting Ukrainian organizations leverages legitimate software bundles to achieve persistent system access.
A newly public exploit targeting GitLab reveals how silent patches for library bugs can leave critical vulnerabilities exposed.
Rockwell Automation addresses four high-severity memory corruption bugs found in its Arena Simulation modeling software.
A deserialization vulnerability in OpenAM's WebAuthn module allows remote code execution through an object filter depth bypass.
A critical pre-authentication vulnerability allows attackers to execute arbitrary code on unpatched OpenAM instances.
A critical vulnerability in OpenDJ allows unauthenticated attackers to perform SSRF, read local files, and trigger memory-exhaustion denial-of-service attacks.
A critical shell injection vulnerability in the Shescape library allows attackers to bypass security filters when using CMD on Windows systems.
A critical authorization vulnerability in OpenDJ allows SASL PLAIN users to bypass intended scope checks for proxied identity.
A failure in the sm-crypto library's random number generation allows attackers to predict private keys, undermining the security of SM2 cryptographic operations.
A flaw in the Pheditor forced password-change flow allows unauthenticated attackers to hijack administrative accounts on systems using default credentials.
A configuration vulnerability in the platform's MySQL integration allows for unauthorized command execution and database takeover.
A critical vulnerability in Budibase allows attackers to hijack existing user accounts by exploiting improper email validation in the OIDC login process.
A critical vulnerability in Budibase allows unauthenticated attackers to steal stored REST datasource credentials via a cross-origin request leak.
A March network intrusion at logistics firm OnTrac has triggered data protection warnings for affected customers.