<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/ai-sandbox/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T07:35:45.000Z</news:publication_date>
      <news:title>AI Sandbox: Security Risks, Benefits &amp;#038; Best Practices</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56811-phoenix-unbounded-channel-join-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T20:50:31.125Z</news:publication_date>
      <news:title>CVE-2026-56811: Phoenix Unbounded Channel Join DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61556-liquidjs-strip-html-infinite-loop-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T17:48:48.994Z</news:publication_date>
      <news:title>CVE-2026-61556: LiquidJS strip_html Infinite Loop (DoS)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-62682-orval-server-url-template-literal-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T19:09:04.581Z</news:publication_date>
      <news:title>CVE-2026-62682: Orval Remote Code Execution via Unescaped Server URL in Template Literal</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-63376-toml-node-prototype-pollution-proto-desync</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T21:11:04.599Z</news:publication_date>
      <news:title>CVE-2026-63376: toml Prototype Pollution via __proto__ Key-Path Desynchronization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-67445-mailpit-smtp-command-line-memory-exhaustion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T23:51:27.707Z</news:publication_date>
      <news:title>CVE-2026-67445: Mailpit SMTP Command Parser Unbounded Memory Allocation (DoS)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-67446-mailpit-thumbnail-image-decompression-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T23:58:06.989Z</news:publication_date>
      <news:title>CVE-2026-67446: Mailpit Thumbnail Handler Uncontrolled Memory Allocation via Oversized Image Dimensions</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-68584-siyuan-publish-password-auth-bypass-heading-dom</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T21:29:01.205Z</news:publication_date>
      <news:title>CVE-2026-68584: SiYuan Publish Password Authentication Bypass via Unprotected Content Endpoints</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-68586-siyuan-getbacklinkdoc-publish-access-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T21:30:18.174Z</news:publication_date>
      <news:title>CVE-2026-68586: SiYuan Missing Publish-Access Filter on Backlink Content Endpoints</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-68587-siyuan-getheading-transaction-publish-disclosure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T21:31:43.871Z</news:publication_date>
      <news:title>CVE-2026-68587: SiYuan getHeading*Transaction Publish-Disabled Document Disclosure</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69086-siyuan-attributeview-avid-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T20:49:08.090Z</news:publication_date>
      <news:title>CVE-2026-69086: SiYuan Attribute-View Path Traversal via Unvalidated avID</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71428-unstructured-ssrf-url-partition</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T17:09:04.126Z</news:publication_date>
      <news:title>CVE-2026-71428: unstructured Full-Read SSRF via url= Parameter</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-72793-siyuan-getconf-credential-disclosure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T21:29:03.757Z</news:publication_date>
      <news:title>CVE-2026-72793: SiYuan /api/system/getConf Credential Disclosure</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-72798-siyuan-renderattributeview-publish-access-filter-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T21:08:54.280Z</news:publication_date>
      <news:title>CVE-2026-72798: SiYuan renderAttributeView Publish-Access Filter Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-72801-siyuan-notebook-crypto-disclosure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T23:09:03.480Z</news:publication_date>
      <news:title>CVE-2026-72801: SiYuan Encrypted Notebook Key Material Disclosed to Anonymous Readers</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-72804-siyuan-graph-password-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T23:10:13.237Z</news:publication_date>
      <news:title>CVE-2026-72804: SiYuan Graph Endpoints Missing Publish-Password Check</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-72810-siyuan-websocket-broadcast-publish-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T22:49:48.621Z</news:publication_date>
      <news:title>CVE-2026-72810: SiYuan WebSocket Broadcast Publish-Boundary Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-72811-siyuan-backlink-sql-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T22:51:05.245Z</news:publication_date>
      <news:title>CVE-2026-72811: SiYuan SQL Injection via Backlink and Mention Search</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-72921-seaweedfs-filer-jwt-allowed-prefixes-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T23:56:50.403Z</news:publication_date>
      <news:title>CVE-2026-72921: SeaweedFS Filer JWT allowed_prefixes Authorization Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-73222-claude-code-templates-studio-rce-command-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T20:10:23.148Z</news:publication_date>
      <news:title>CVE-2026-73222: claude-code-templates Unauthenticated OS Command Injection (RCE) in Studio Server</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-73292-semaphore-ui-csrf-password-takeover</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T19:30:11.523Z</news:publication_date>
      <news:title>CVE-2026-73292: Semaphore UI CSRF Password Takeover</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-73293-semaphore-ui-manager-owner-privilege-escalation-role-slug</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T19:29:08.482Z</news:publication_date>
      <news:title>CVE-2026-73293: Semaphore UI Manager-to-Owner Privilege Escalation via Custom Role Slug Collision</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-73841-openchoreo-cross-project-exec-wirelogs-authz-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T23:55:42.427Z</news:publication_date>
      <news:title>CVE-2026-73841: OpenChoreo Cross-Project Authorization Bypass in exec and wirelogs Endpoints</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-73842-openchoreo-cluster-gateway-missing-authentication-secret-disclosu</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T21:50:03.232Z</news:publication_date>
      <news:title>CVE-2026-73842: OpenChoreo cluster-gateway Missing Authentication on Internal Proxy</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-73843-openchoreo-cluster-gateway-unauthenticated-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02T23:50:20.186Z</news:publication_date>
      <news:title>CVE-2026-73843: OpenChoreo cluster-gateway Unauthenticated Data-Plane RCE</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-75856-codewhale-ssrf-dns-pinning-toctou</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T18:09:06.106Z</news:publication_date>
      <news:title>CVE-2026-75856: CodeWhale (deepseek-tui) SSRF via DNS Pinning TOCTOU Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-75857-codewhale-exec-shell-interact-approval-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T18:12:15.028Z</news:publication_date>
      <news:title>CVE-2026-75857: CodeWhale exec_shell_interact Approval Bypass Privilege Escalation</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-75858-codewhale-rlm-eval-approval-bypass-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T18:15:16.052Z</news:publication_date>
      <news:title>CVE-2026-75858: CodeWhale rlm_eval Approval Bypass Leading to Unsandboxed RCE</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-75859-codewhale-instructions-arbitrary-file-read</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T18:18:17.480Z</news:publication_date>
      <news:title>CVE-2026-75859: deepseek-tui (CodeWhale) Arbitrary File Read via Project Config instructions Override</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-75911-codewhale-allow-shell-project-config-code-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T18:21:54.648Z</news:publication_date>
      <news:title>CVE-2026-75911: deepseek-tui (CodeWhale) Project Config allow_shell Override Enables Arbitrary Shell Execution</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-75913-codewhale-git-show-argument-injection-file-write</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T18:17:06.289Z</news:publication_date>
      <news:title>CVE-2026-75913: CodeWhale Argument Injection in git_show Allows Arbitrary File Write</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-75914-codewhale-image-analyze-symlink-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T17:49:05.446Z</news:publication_date>
      <news:title>CVE-2026-75914: CodeWhale image_analyze Symlink Path Traversal</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-75915-codewhale-js-execution-env-leak</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T18:10:18.377Z</news:publication_date>
      <news:title>CVE-2026-75915: CodeWhale deepseek-tui js_execution Environment Variable Leak</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-77465-toml-node-uncontrolled-recursion-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T21:09:40.258Z</news:publication_date>
      <news:title>CVE-2026-77465: toml Uncontrolled Recursion (DoS)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-79921-amqp091-go-frame-max-memory-exhaustion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T20:30:01.194Z</news:publication_date>
      <news:title>CVE-2026-79921: amqp091-go Broker-Controlled Memory Exhaustion via Oversized Frame</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-82404-toon-format-prototype-pollution-decode</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T20:09:05.457Z</news:publication_date>
      <news:title>CVE-2026-82404: @toon-format/toon Prototype Pollution via Untrusted Decode</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/siyuan-svg-sanitizer-bypass-xss-desc-style-parser-mismatch</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T15:09:04.894Z</news:publication_date>
      <news:title>SiYuan: Stored and Reflected XSS via SVG Sanitizer Bypass (HTML/XML Parser Mismatch)</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/typespec-spector-unauthenticated-admin-stop-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T21:48:42.840Z</news:publication_date>
      <news:title>@typespec/spector Unauthenticated Remote Shutdown via POST /.admin/stop</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
</urlset>