<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T08:24:55.360838+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-263213</id>
    <title>EUVD-2026-263213</title>
    <updated>2026-10-10T08:24:55.408546+00:00</updated>
    <content>EUVD-2026-263213</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-263213"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-67509</id>
    <title>fkie_cve-2025-67509</title>
    <updated>2026-10-10T08:24:55.408588+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which is vulnerable to Read-Only Bypass.  MySQLSelectTool is intended to be a read-only SQL tool (e.g., for LLM agent querying, however, validation based on the first keyword (e.g., SELECT) and a forbidden-keyword list does not block file-writing constructs such as INTO OUTFILE / INTO DUMPFILE. As a result, an attacker who can influence the tool input (e.g., via prompt injection through a public agent endpoint) may write arbitrary files to the DB server if the MySQL/MariaDB account has the FILE privilege and server configuration permits writes to a useful location (e.g., a web-accessible directory). This issue is fixed in version 2.8.12.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-67509"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j8g6-5gqc-mq36</id>
    <title>GHSA-j8g6-5gqc-mq36 — Neuron MySQLSelectTool “read-only” bypass via `SELECT ... INTO OUTFILE` (file write → potential RCE)</title>
    <updated>2026-10-10T08:24:55.408643+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: neuron-core/neuron-ai</p>
<p>### Impact</p>
<p>`MySQLSelectTool` is intended to be a read-only SQL tool (e.g., for LLM agent querying). However, validation based on the first keyword (e.g., `SELECT`) and a forbidden-keyword list does not block file-writing constructs such as `INTO OUTFILE` / `INTO DUMPFILE`.</p>
<p>As a result, an attacker who can influence the tool input (e.g., prompt injection through a public agent endpoint) may be able to write arbitrary content to files on the DB server.</p>
<p>If the MySQL/MariaDB account has the `FILE` privilege and server configuration permits writes to a useful location (e.g., a web-accessible directory), the impact can escalate to remote code execution on the application host (for example, by writing a PHP web shell).</p>
<p>**Who is impacted:** Deployments that expose an agent using `MySQLSelectTool` to untrusted input and run with overly-permissive DB privileges/configuration.</p>
<p>### Patches</p>
<p>**Not patched in:** 2.8.11</p>
<p>**Fixed in:** 2.8.12</p>
<p>Recommended fix direction:</p>
<p>- Explicitly reject queries containing: `INTO`, `OUTFILE`, `DUMPFILE`, `LOAD_FILE`, and other file/IO-related functions/clauses.</p>
<p>- Prefer AST-based validation (SQL parser) over keyword checks.</p>
<p>- Constrain allowed tables/columns and disallow multi-statements.</p>
<p>### Workarounds</p>
<p>If you cannot upgrade immediately:</p>
<p>- Remove/disable `MySQLSelectTool` for any agent reachable from untrusted input.</p>
<p>- Ensure DB account used by the tool **does not** have `FILE` privilege.</p>
<p>- Ensure `secure_file_priv` is set to a directory…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j8g6-5gqc-mq36"/>
  </entry>
</feed>
