<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/shadow-ai/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T08:22:23.000Z</news:publication_date>
      <news:title>Shadow AI: Risks, How It Works and How to Protect</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54049-sakai-conversations-stored-xss-unsanitized-messages</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-24T19:50:19.285Z</news:publication_date>
      <news:title>CVE-2026-54049: Sakai Conversations Stored XSS via Unsanitized Topic and Post Messages</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54623-django-cms-move-plugin-cyclic-reparenting-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-24T20:28:49.690Z</news:publication_date>
      <news:title>CVE-2026-54623: django-cms Plugin Move Endpoint Cyclic Reparenting DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55477-3x-ui-arbitrary-file-write-xray-log-path</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-24T21:08:56.562Z</news:publication_date>
      <news:title>CVE-2026-55477: 3X-UI Authenticated Arbitrary File Write via Xray Log Path</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55523-praisonaiagents-web-crawl-ssrf-redirect-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T14:29:01.586Z</news:publication_date>
      <news:title>CVE-2026-55523: praisonaiagents web_crawl SSRF via Unvalidated Redirect Target</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55524-praisonaiagents-ssrf-web-crawl-redirect-dns-rebinding</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T14:49:14.600Z</news:publication_date>
      <news:title>CVE-2026-55524: praisonaiagents SSRF via Redirect and DNS Rebinding in web_crawl</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55525-praisonaiagents-web-crawl-ssrf-redirect-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T14:09:13.909Z</news:publication_date>
      <news:title>CVE-2026-55525: praisonaiagents web_crawl SSRF via Redirect Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55526-praisonaiagents-ssrf-dns-bypass-spider-tools</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T14:51:00.533Z</news:publication_date>
      <news:title>CVE-2026-55526: praisonaiagents SSRF Protection Bypass via Wildcard DNS Hostname</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55528-praisonaiagents-agentserver-missing-authentication</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T14:52:09.340Z</news:publication_date>
      <news:title>CVE-2026-55528: praisonaiagents AgentServer Missing Authentication</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55532-praisonai-mcp-origin-csrf-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T15:31:08.480Z</news:publication_date>
      <news:title>CVE-2026-55532: PraisonAI MCP HTTP Server Origin Validation Bypass (CSRF)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55536-praisonai-websocket-origin-regex-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T15:30:01.275Z</news:publication_date>
      <news:title>CVE-2026-55536: PraisonAI WebSocket Origin Validation Bypass via Unanchored Regex</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55537-praisonai-webhook-ssrf-dns-fail-open-toctou</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T15:10:11.732Z</news:publication_date>
      <news:title>CVE-2026-55537: PraisonAI Webhook SSRF via DNS Fail-Open and TOCTOU Race</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55538-praisonai-serve-agents-api-key-auth-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T15:11:31.693Z</news:publication_date>
      <news:title>CVE-2026-55538: PraisonAI serve agents --api-key Authentication Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55539-praisonai-jobs-api-missing-authentication</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T15:35:37.308Z</news:publication_date>
      <news:title>CVE-2026-55539: PraisonAI Jobs API Missing Authentication</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55541-praisonai-serve-api-key-missing-authorization</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T15:08:58.250Z</news:publication_date>
      <news:title>CVE-2026-55541: PraisonAI serve --api-key Flag Missing Authorization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55546-qwed-mcp-sympy-parse-expr-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T15:28:43.436Z</news:publication_date>
      <news:title>CVE-2026-55546: qwed-mcp Remote Code Execution via Unsafe SymPy parse_expr()</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55553-urllib-cross-origin-redirect-credential-leakage</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T16:30:13.085Z</news:publication_date>
      <news:title>CVE-2026-55553: urllib Cross-Origin Redirect Credential Leakage</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55571-djust-liveview-websocket-auth-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T16:14:52.083Z</news:publication_date>
      <news:title>CVE-2026-55571: djust LiveView WebSocket Authentication Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55580-mcp-shell-command-injection-security-disabled-default-shell-inter</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T15:49:03.237Z</news:publication_date>
      <news:title>CVE-2026-55580: mcp-shell OS Command Injection via Security-Disabled Default and Shell Interpreter in Allowlist</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55581-mcp-shell-allowlist-bypass-bash-command-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T15:50:13.471Z</news:publication_date>
      <news:title>CVE-2026-55581: mcp-shell Secure Mode Allowlist Bypass via /bin/bash -c</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55582-mcp-shell-git-alias-command-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T15:51:22.523Z</news:publication_date>
      <news:title>CVE-2026-55582: mcp-shell Secure Mode Allowlist Bypass via Git Shell Alias</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55585-qwed-authenticated-rce-sympy-parse-expr</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T16:28:58.191Z</news:publication_date>
      <news:title>CVE-2026-55585: qwed Authenticated Remote Code Execution via Unsafe SymPy parse_expr()</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55596-platejs-media-embed-stored-xss-provider-metadata</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T16:48:48.260Z</news:publication_date>
      <news:title>CVE-2026-55596: @platejs/media Media Embed Stored XSS via Serialized Provider Metadata</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55640-nextcloud-mcp-server-unauthenticated-webhook-vector-deletion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T16:09:19.454Z</news:publication_date>
      <news:title>CVE-2026-55640: nextcloud-mcp-server Unauthenticated Webhook Allows Arbitrary Vector Data Deletion</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55677-echo-encoded-slash-route-bypass-static-file-disclosure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T16:31:27.091Z</news:publication_date>
      <news:title>CVE-2026-55677: Echo v5 Encoded Slash Route-Bypass Exposes Static Files</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-9769-justhtml-uncontrolled-recursion-dos-nested-html</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T16:50:51.995Z</news:publication_date>
      <news:title>CVE-2026-9769: justhtml Uncontrolled Recursion DoS via Deeply Nested HTML</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/pickem-terminal-escape-sequence-injection-unsanitized-labels</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T16:10:32.974Z</news:publication_date>
      <news:title>pickem Terminal Escape-Sequence Injection via Unsanitized Item Labels</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/postgres-protocol-scram-iteration-count-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-24T19:49:03.531Z</news:publication_date>
      <news:title>postgres-protocol: Unbounded SCRAM Iteration Count CPU Exhaustion DoS</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/utcp-http-oauth2-tokenurl-ssrf-credential-theft</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T16:11:36.956Z</news:publication_date>
      <news:title>utcp-http OAuth2 tokenUrl Trust Boundary Bypass (SSRF and Credential Theft)</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/utcp-http-ssrf-unvalidated-redirect-call-tool</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T16:16:10.987Z</news:publication_date>
      <news:title>utcp-http SSRF via Unvalidated HTTP Redirect in call_tool</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
</urlset>