<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-11745-centraldogma-ssh-host-key-mitm</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T20:49:10.532Z</news:publication_date>
      <news:title>CVE-2026-11745: centraldogma-server-mirror-git SSH Host Key Verification Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-11746-centraldogma-hardcoded-zookeeper-secret-cluster-takeover</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T20:50:30.535Z</news:publication_date>
      <news:title>CVE-2026-11746: Central Dogma Hard-coded ZooKeeper Replication Secret Enables Cluster Takeover</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55416-pimcore-custom-reports-sql-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T19:28:53.283Z</news:publication_date>
      <news:title>CVE-2026-55416: Pimcore Custom Reports SQL Injection via Report Configuration Fields</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55864-geonetwork-sld-unauthenticated-ssrf</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-09T23:48:50.813Z</news:publication_date>
      <news:title>CVE-2026-55864: GeoNetwork Unauthenticated SSRF in SLD Tool</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56825-shopper-collection-products-missing-authorization</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T21:50:26.289Z</news:publication_date>
      <news:title>CVE-2026-56825: Shopper CollectionProducts Missing Authorization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56827-shopper-filament-bulk-action-missing-authorization</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T21:08:55.804Z</news:publication_date>
      <news:title>CVE-2026-56827: Shopper Framework Missing Authorization on Filament Bulk Actions</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56828-shopper-framework-livewire-privilege-escalation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T21:54:58.838Z</news:publication_date>
      <news:title>CVE-2026-56828: shopper/framework Privilege Escalation via Livewire Misconfigured Authorization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56829-shopper-variantstock-missing-authorization-inventory-manipulation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T21:51:37.206Z</news:publication_date>
      <news:title>CVE-2026-56829: Shopper VariantStock Missing Authorization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59148-mockoon-unauthenticated-admin-api-csrf</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T22:09:15.823Z</news:publication_date>
      <news:title>CVE-2026-59148: @mockoon/commons-server Unauthenticated Admin API + Wildcard CORS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59151-prowler-saml-cross-tenant-account-takeover</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T21:49:20.475Z</news:publication_date>
      <news:title>CVE-2026-59151: Prowler SAML Cross-Tenant Account Takeover</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59158-nuxt-ollama-api-key-ssr-exposure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T00:22:43.196Z</news:publication_date>
      <news:title>CVE-2026-59158: nuxt-ollama API Key Exposed in SSR HTML Payload</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59160-turbo-graph-unauthenticated-task-execution</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T00:21:50.099Z</news:publication_date>
      <news:title>CVE-2026-59160: @yeger/turbo-graph Unauthenticated Remote Task Execution</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59161-excelize-getrows-streaming-row-bound-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T15:49:48.816Z</news:publication_date>
      <news:title>CVE-2026-59161: Excelize GetRows Streaming Row-Bound Bypass Leads to Attacker-Controlled Memory Allocation</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59172-joker-linter-local-code-execution</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T00:16:11.122Z</news:publication_date>
      <news:title>CVE-2026-59172: Joker Linter Project-Local Code Execution</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59176-functype-mcp-server-set-functype-version-package-alias-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T00:11:45.194Z</news:publication_date>
      <news:title>CVE-2026-59176: functype-mcp-server set_functype_version Package Alias RCE</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59177-esphome-device-builder-unauthenticated-ingress-lan-access</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T00:10:37.328Z</news:publication_date>
      <news:title>CVE-2026-59177: esphome-device-builder Unauthenticated Dashboard Access via Unrestricted Ingress Bind</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59179-openhop-server-path-traversal-flow-id</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T00:09:24.252Z</news:publication_date>
      <news:title>CVE-2026-59179: @openhop/server Path Traversal in Flow ID File Operations</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59185-identrail-cross-tenant-idor-github-installation-id</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T00:15:05.162Z</news:publication_date>
      <news:title>CVE-2026-59185: Identrail Cross-Tenant IDOR via Unverified GitHub App installation_id</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59960-argos-ci-core-branch-os-command-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T23:05:10.011Z</news:publication_date>
      <news:title>CVE-2026-59960: @argos-ci/core CI Branch Name OS Command Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59965-payload-alt-text-plugin-authorization-bypass-overrideaccess</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T22:57:41.306Z</news:publication_date>
      <news:title>CVE-2026-59965: @jhb.software/payload-alt-text-plugin Authorization Bypass via overrideAccess Omission</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59971-mysql-mcp-server-unauth-sql-execution-dns-rebinding</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T20:51:56.620Z</news:publication_date>
      <news:title>CVE-2026-59971: mysql-mcp-server Unauthenticated SQL Execution via Missing Origin and Host Validation</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59973-mcp-from-openapi-ssrf-filter-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T22:10:28.749Z</news:publication_date>
      <news:title>CVE-2026-59973: mcp-from-openapi OpenAPI $ref SSRF Filter Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61534-yayson-prototype-pollution-jsonapi-store</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T22:28:51.427Z</news:publication_date>
      <news:title>CVE-2026-61534: yayson Prototype Pollution via JSON:API Type Deserialization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-86075-n8n-oauth-registration-storage-exhaustion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T15:31:13.334Z</news:publication_date>
      <news:title>CVE-2026-86075: n8n Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-86076-n8n-expression-sandbox-escape-sanitizer-rebinding</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T15:36:07.995Z</news:publication_date>
      <news:title>CVE-2026-86076: n8n Expression Sandbox Escape via Class-Field Sanitizer Rebinding</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-86081-n8n-redos-git-node-clone-path</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T15:29:55.133Z</news:publication_date>
      <news:title>CVE-2026-86081: n8n Regular Expression Denial of Service via Git Node Clone Path</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-86082-n8n-openai-model-search-ssrf-domain-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T15:41:55.218Z</news:publication_date>
      <news:title>CVE-2026-86082: n8n OpenAI Chat Model Node SSRF via Unguarded Model-Search Endpoint</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-86083-n8n-json-stringify-code-injection-sandbox-escape</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T20:49:11.403Z</news:publication_date>
      <news:title>CVE-2026-86083: n8n Expression Sandbox Escape via JSON.stringify Hijacking</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-87011-open-webui-backchannel-logout-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T23:03:55.015Z</news:publication_date>
      <news:title>CVE-2026-87011: open-webui OIDC Back-Channel Logout Unauthenticated DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-87016-open-webui-oauth-subject-wildcard-auth-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T21:29:01.615Z</news:publication_date>
      <news:title>CVE-2026-87016: Open WebUI OAuth Subject Wildcard Authentication Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-87995-open-webui-port-preview-same-origin-xss-account-takeover</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T15:37:25.814Z</news:publication_date>
      <news:title>CVE-2026-87995: Open WebUI Same-Origin XSS to Account Takeover via Terminal Port-Preview iframe</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-87996-open-webui-playwright-dns-rebinding-ssrf</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T15:43:14.791Z</news:publication_date>
      <news:title>CVE-2026-87996: open-webui DNS Rebinding SSRF in Playwright Web Loader</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-87999-open-webui-ssrf-azure-platform-channel</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T15:44:57.022Z</news:publication_date>
      <news:title>CVE-2026-87999: Open WebUI SSRF via Azure Platform Channel Address Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-88004-traefik-trailer-header-sanitization-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T23:10:23.458Z</news:publication_date>
      <news:title>CVE-2026-88004: Traefik Entrypoint Header Sanitization Bypass via HTTP Trailers</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-88007-traefik-http3-ntlm-connection-reuse</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T23:11:35.952Z</news:publication_date>
      <news:title>CVE-2026-88007: Traefik HTTP/3 NTLM Backend Connection Reuse</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-88008-traefik-h2c-upgrade-middleware-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T23:09:12.428Z</news:publication_date>
      <news:title>CVE-2026-88008: Traefik h2c Upgrade Middleware Bypass via HTTP Request Smuggling</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-88009-traefik-opaque-request-target-routing-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T23:15:07.343Z</news:publication_date>
      <news:title>CVE-2026-88009: Traefik HTTP Request Smuggling via Rootless Opaque Request-Target</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-88017-rclone-ftp-auth-proxy-cross-session-credential-overwrite</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T22:49:51.854Z</news:publication_date>
      <news:title>CVE-2026-88017: rclone FTP Auth-Proxy Cross-Session Credential Overwrite</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-88018-rclone-serve-s3-sigv4-auth-bypass-empty-secret</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T23:02:20.476Z</news:publication_date>
      <news:title>CVE-2026-88018: rclone serve s3 SigV4 Authentication Bypass via Empty Secret</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-88044-rclone-rc-auth-proxy-bypass-ftp-s3</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T22:55:44.464Z</news:publication_date>
      <news:title>CVE-2026-88044: rclone RC Per-Server Auth-Proxy Bypass (FTP/S3)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-88045-rclone-serve-s3-multipart-memory-exhaustion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T22:51:06.483Z</news:publication_date>
      <news:title>CVE-2026-88045: rclone serve s3 Multipart Memory Exhaustion via Declared Content-Length</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-88056-angular-platform-server-ssrf-unicode-whitespace</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T20:30:30.824Z</news:publication_date>
      <news:title>CVE-2026-88056: @angular/platform-server SSRF via Unicode Whitespace Trim Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-88060-angular-platform-server-ssr-template-documentfragment-xss</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T20:29:10.394Z</news:publication_date>
      <news:title>CVE-2026-88060: @angular/platform-server SSR XSS via Unescaped Template Content Across DocumentFragment Boundaries</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-88062-omniroute-acp-agent-unauthenticated-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T21:30:22.248Z</news:publication_date>
      <news:title>CVE-2026-88062: omniroute Unauthenticated Remote Code Execution via Custom ACP Agent</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/eigenpal-docx-editor-core-css-injection-print-xss-font-family</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T15:09:05.723Z</news:publication_date>
      <news:title>@eigenpal/docx-editor-core: CSS Injection and Print-Time XSS via Unescaped Font Name</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/komari-csrf-admin-rce-cookie-samesite</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T00:17:18.547Z</news:publication_date>
      <news:title>Komari: Management Interface CSRF Leading to Remote Code Execution</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/mistralrs-server-core-unbounded-media-fetch-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T22:08:56.939Z</news:publication_date>
      <news:title>mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
</urlset>