The newsroom — the machine composes, only a human advances the workflow
The make-list — pick an advisory, the desk composes it
CVE-2018-7750 — Paramiko not properly checking authentication before processing other requests…
CVE-2021-44906 — Prototype Pollution in minimist…
CVE-2026-75604 — Next.js: Unauthenticated Remote Code Execution on windows-hosted servers…
CVE-2018-1000805 — Paramiko Authentication Bypass vulnerability…
CVE-2022-0235 — node-fetch forwards secure headers to untrusted sites…
CVE-2022-23539 — jsonwebtoken unrestricted key type could lead to legacy keys usage …
On the press — draft → review → published
CVE-2026-4800: lodash vulnerable to Code Injection via `_.template` imports key names
Approved by a human editor — the machine composed, the human signed off
lodash (npm) is affected by CVE-2026-4800. The advisory records a CVSS base score of 8.1/10.
The structured profile reads: reached over network; no special privileges required: none; no user interaction.
Remediation is a version bump: upgrade to 4.18.0.
From the advisory record: Impact The fix for CVE-2021-23337 added validation for the `variable` option in `_.template` but did not apply the same validation to `options.imports` key names. Both paths flow into the same `Function()` constructor sink. When an application passes untrusted input as `options.imports` key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compil…
Published 27/09/2026 08:16:09
CVE-2018-7750: Paramiko not properly checking authentication before processing other requests
Composed by the ZéroJour press desk from structured fields — pending human review
paramiko (pip) is affected by CVE-2018-7750. The advisory records a CVSS base score of 9.8/10.
The structured profile reads: reached over network; no special privileges required: none; no user interaction.
Remediation is a version bump: upgrade to 2.0.8.
From the advisory record: transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.