<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-15895-jsii-diff-command-injection-npm-argument</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-07T18:36:04.885Z</news:publication_date>
      <news:title>CVE-2026-15895: jsii-diff OS Command Injection via npm: Package Argument</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-63221-codeigniter4-deletebatch-where-sql-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-07T18:34:56.311Z</news:publication_date>
      <news:title>CVE-2026-63221: CodeIgniter4 Query Builder SQL Injection via deleteBatch() and where()</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-63222-codeigniter4-uploadedfile-move-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-07T18:31:16.170Z</news:publication_date>
      <news:title>CVE-2026-63222: CodeIgniter4 Path Traversal in UploadedFile::move()</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-63223-codeigniter4-is-image-mime-in-upload-bypass-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-07T18:30:06.398Z</news:publication_date>
      <news:title>CVE-2026-63223: CodeIgniter4 Uploaded File Extension Validation Bypass in is_image and mime_in Rules</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-67422-pymdown-extensions-redos-inline-processors</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-07T18:28:53.655Z</news:publication_date>
      <news:title>CVE-2026-67422: pymdown-extensions ReDoS in caret, tilde, betterem, and magiclink</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/gitpython-config-option-name-injection-sshcommand-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-07T15:48:55.947Z</news:publication_date>
      <news:title>GitPython: git-config Option-Name Injection via = and # Characters Enables RCE</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/gitpython-submodule-name-path-traversal-arbitrary-repo-creation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-07T15:50:19.375Z</news:publication_date>
      <news:title>GitPython Submodule Name Path Traversal to Arbitrary Git Repository Creation</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/gitpython-unsafe-option-guard-bypass-split-single-char-options-argument-injectio</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-07T16:08:59.610Z</news:publication_date>
      <news:title>GitPython unsafe-option guard bypass via split_single_char_options=False short-option smuggling</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
</urlset>