<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/ai-sandbox/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T07:35:45.000Z</news:publication_date>
      <news:title>AI Sandbox: Security Risks, Benefits &amp;#038; Best Practices</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://blog.securelayer7.net/continuous-penetration-testing/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T11:20:18.000Z</news:publication_date>
      <news:title>Continuous Penetration Testing: Process And Benefits</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56811-phoenix-unbounded-channel-join-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T20:50:31.125Z</news:publication_date>
      <news:title>CVE-2026-56811: Phoenix Unbounded Channel Join DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59832-siyuan-snippets-path-traversal-secret-leak</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T14:29:25.128Z</news:publication_date>
      <news:title>CVE-2026-59832: SiYuan Authenticated Path Traversal in /snippets/ Handler</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59834-siyuan-sql-injection-block-search-paths</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T14:30:39.049Z</news:publication_date>
      <news:title>CVE-2026-59834: SiYuan SQL Injection via Block Search paths Parameter</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61556-liquidjs-strip-html-infinite-loop-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T17:48:48.994Z</news:publication_date>
      <news:title>CVE-2026-61556: LiquidJS strip_html Infinite Loop (DoS)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61704-link-preview-js-dns-rebinding-ssrf-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T21:49:02.194Z</news:publication_date>
      <news:title>CVE-2026-61704: link-preview-js DNS Rebinding SSRF Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-62388-nltk-pathsec-enforce-false-security-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T15:56:00.468Z</news:publication_date>
      <news:title>CVE-2026-62388: NLTK pathsec Insecure Default Allows Security Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-62669-grav-cms-2fa-bypass-secret-rotation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T22:08:58.656Z</news:publication_date>
      <news:title>CVE-2026-62669: Grav CMS 2FA Bypass via Unauthenticated Secret Rotation</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-62675-omnigent-callable-tool-runner-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T22:16:45.022Z</news:publication_date>
      <news:title>CVE-2026-62675: Omnigent Authenticated Runner RCE via Python Callable Tool in Uploaded Agent Bundle</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-62676-omnigent-shell-parser-fails-open-policy-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T22:48:58.922Z</news:publication_date>
      <news:title>CVE-2026-62676: omnigent Shell-Command Parser Fails Open, Allowing Policy Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-62677-omnigent-os-env-cwd-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T22:10:12.178Z</news:publication_date>
      <news:title>CVE-2026-62677: Omnigent Path Traversal via Unvalidated os_env.cwd in Agent Bundle</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-62680-orval-ssrf-lfi-openapi-ref</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T15:01:59.336Z</news:publication_date>
      <news:title>CVE-2026-62680: Orval Generation-Time SSRF and Local File Inclusion via Unvalidated $ref</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-62682-orval-server-url-template-literal-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T19:09:04.581Z</news:publication_date>
      <news:title>CVE-2026-62682: Orval Remote Code Execution via Unescaped Server URL in Template Literal</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-63376-toml-node-prototype-pollution-proto-desync</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T21:11:04.599Z</news:publication_date>
      <news:title>CVE-2026-63376: toml Prototype Pollution via __proto__ Key-Path Desynchronization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-63490-handlebars-springmvc-arbitrary-file-read-fragment-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T22:14:56.466Z</news:publication_date>
      <news:title>CVE-2026-63490: handlebars-springmvc Arbitrary File Read via URL Fragment Suffix Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-64850-grav-blueprint-dynamicdata-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T14:57:33.711Z</news:publication_date>
      <news:title>CVE-2026-64850: Grav CMS Remote Code Execution via Unrestricted Callable in Blueprint::dynamicData()</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-65842-platejs-docx-io-ssrf-remote-image-fetch</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T22:28:58.816Z</news:publication_date>
      <news:title>CVE-2026-65842: @platejs/docx-io Server-Side Request Forgery via Remote Image Fetch</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-67445-mailpit-smtp-command-line-memory-exhaustion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T23:51:27.707Z</news:publication_date>
      <news:title>CVE-2026-67445: Mailpit SMTP Command Parser Unbounded Memory Allocation (DoS)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-67446-mailpit-thumbnail-image-decompression-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T23:58:06.989Z</news:publication_date>
      <news:title>CVE-2026-67446: Mailpit Thumbnail Handler Uncontrolled Memory Allocation via Oversized Image Dimensions</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-68584-siyuan-publish-password-auth-bypass-heading-dom</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T21:29:01.205Z</news:publication_date>
      <news:title>CVE-2026-68584: SiYuan Publish Password Authentication Bypass via Unprotected Content Endpoints</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-68586-siyuan-getbacklinkdoc-publish-access-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T21:30:18.174Z</news:publication_date>
      <news:title>CVE-2026-68586: SiYuan Missing Publish-Access Filter on Backlink Content Endpoints</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-68587-siyuan-getheading-transaction-publish-disclosure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T21:31:43.871Z</news:publication_date>
      <news:title>CVE-2026-68587: SiYuan getHeading*Transaction Publish-Disabled Document Disclosure</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69086-siyuan-attributeview-avid-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T20:49:08.090Z</news:publication_date>
      <news:title>CVE-2026-69086: SiYuan Attribute-View Path Traversal via Unvalidated avID</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71428-unstructured-ssrf-url-partition</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T17:09:04.126Z</news:publication_date>
      <news:title>CVE-2026-71428: unstructured Full-Read SSRF via url= Parameter</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71866-orval-zod-property-name-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T15:16:25.135Z</news:publication_date>
      <news:title>CVE-2026-71866: orval Import-time RCE via Zod Object Property Name Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-72920-seaweedfs-unauthenticated-iam-grpc</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T14:56:13.828Z</news:publication_date>
      <news:title>CVE-2026-72920: SeaweedFS Unauthenticated IAM gRPC Service</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-72921-seaweedfs-filer-jwt-allowed-prefixes-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T23:56:50.403Z</news:publication_date>
      <news:title>CVE-2026-72921: SeaweedFS Filer JWT allowed_prefixes Authorization Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-73222-claude-code-templates-studio-rce-command-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T20:10:23.148Z</news:publication_date>
      <news:title>CVE-2026-73222: claude-code-templates Unauthenticated OS Command Injection (RCE) in Studio Server</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-73292-semaphore-ui-csrf-password-takeover</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T19:30:11.523Z</news:publication_date>
      <news:title>CVE-2026-73292: Semaphore UI CSRF Password Takeover</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-73293-semaphore-ui-manager-owner-privilege-escalation-role-slug</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T19:29:08.482Z</news:publication_date>
      <news:title>CVE-2026-73293: Semaphore UI Manager-to-Owner Privilege Escalation via Custom Role Slug Collision</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-73841-openchoreo-cross-project-exec-wirelogs-authz-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T23:55:42.427Z</news:publication_date>
      <news:title>CVE-2026-73841: OpenChoreo Cross-Project Authorization Bypass in exec and wirelogs Endpoints</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-73843-openchoreo-cluster-gateway-unauthenticated-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T23:50:20.186Z</news:publication_date>
      <news:title>CVE-2026-73843: OpenChoreo cluster-gateway Unauthenticated Data-Plane RCE</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-75899-fast-uri-ssrf-double-percent-decoding</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T15:51:46.465Z</news:publication_date>
      <news:title>CVE-2026-75899: fast-uri SSRF via Double Hostname Percent-Decoding</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-75931-fast-uri-idn-scheme-relative-host-confusion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T15:49:07.232Z</news:publication_date>
      <news:title>CVE-2026-75931: fast-uri Host Confusion via Skipped IDN Canonicalization on Scheme-Relative References</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-75975-fast-uri-ipv6-ssrf-normalization</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T15:50:26.393Z</news:publication_date>
      <news:title>CVE-2026-75975: fast-uri SSRF via Malformed IPv6 Normalization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-76172-fast-uri-scheme-host-confusion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T15:54:49.588Z</news:publication_date>
      <news:title>CVE-2026-76172: fast-uri Host Confusion via Percent-Encoded Scheme Normalization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-77465-toml-node-uncontrolled-recursion-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T21:09:40.258Z</news:publication_date>
      <news:title>CVE-2026-77465: toml Uncontrolled Recursion (DoS)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-79921-amqp091-go-frame-max-memory-exhaustion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T20:30:01.194Z</news:publication_date>
      <news:title>CVE-2026-79921: amqp091-go Broker-Controlled Memory Exhaustion via Oversized Frame</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-80206-nltk-tgrep-redos-user-regex</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T15:17:40.652Z</news:publication_date>
      <news:title>CVE-2026-80206: nltk tgrep ReDoS via User-Supplied Regex</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-81726-nltk-model-artifact-pathsec-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T15:11:45.204Z</news:publication_date>
      <news:title>CVE-2026-81726: NLTK Model-Artifact APIs Path Traversal Bypass (pathsec sandbox escape)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-81891-elfinder-zip-extract-mime-bypass-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T14:51:16.647Z</news:publication_date>
      <news:title>CVE-2026-81891: elFinder ZIP Extraction MIME Filter Bypass Leading to RCE</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-81892-easyadmin-routename-access-control-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T14:48:57.457Z</news:publication_date>
      <news:title>CVE-2026-81892: EasyAdmin Custom-Action Dispatcher Authorization Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-82392-pnpm-virtual-store-lockfile-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T15:04:36.232Z</news:publication_date>
      <news:title>CVE-2026-82392: pnpm Virtual Store Linker Path Traversal via Crafted Lockfile</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-82393-pnpm-scoped-name-path-traversal-arbitrary-file-write</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T15:10:13.604Z</news:publication_date>
      <news:title>CVE-2026-82393: pnpm Scoped-Name Path Traversal Arbitrary File Write</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-82397-tornado-urlencoded-max-num-fields-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T14:50:03.611Z</news:publication_date>
      <news:title>CVE-2026-82397: tornado Urlencoded Body Parsing DoS via Unbounded Field Count</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-82404-toon-format-prototype-pollution-decode</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T20:09:05.457Z</news:publication_date>
      <news:title>CVE-2026-82404: @toon-format/toon Prototype Pollution via Untrusted Decode</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-84366-scrapy-s3downloadhandler-plaintext-aws-credentials</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T23:08:58.117Z</news:publication_date>
      <news:title>CVE-2026-84366: Scrapy S3DownloadHandler Cleartext Transmission of AWS Credentials</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/siyuan-svg-sanitizer-bypass-xss-desc-style-parser-mismatch</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T15:09:04.894Z</news:publication_date>
      <news:title>SiYuan: Stored and Reflected XSS via SVG Sanitizer Bypass (HTML/XML Parser Mismatch)</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
</urlset>