<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-72793-siyuan-getconf-credential-disclosure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T21:29:03.757Z</news:publication_date>
      <news:title>CVE-2026-72793: SiYuan /api/system/getConf Credential Disclosure</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-72798-siyuan-renderattributeview-publish-access-filter-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T21:08:54.280Z</news:publication_date>
      <news:title>CVE-2026-72798: SiYuan renderAttributeView Publish-Access Filter Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-72801-siyuan-notebook-crypto-disclosure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T23:09:03.480Z</news:publication_date>
      <news:title>CVE-2026-72801: SiYuan Encrypted Notebook Key Material Disclosed to Anonymous Readers</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-72804-siyuan-graph-password-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T23:10:13.237Z</news:publication_date>
      <news:title>CVE-2026-72804: SiYuan Graph Endpoints Missing Publish-Password Check</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-72810-siyuan-websocket-broadcast-publish-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T22:49:48.621Z</news:publication_date>
      <news:title>CVE-2026-72810: SiYuan WebSocket Broadcast Publish-Boundary Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-72811-siyuan-backlink-sql-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T22:51:05.245Z</news:publication_date>
      <news:title>CVE-2026-72811: SiYuan SQL Injection via Backlink and Mention Search</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-73842-openchoreo-cluster-gateway-missing-authentication-secret-disclosu</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T21:50:03.232Z</news:publication_date>
      <news:title>CVE-2026-73842: OpenChoreo cluster-gateway Missing Authentication on Internal Proxy</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-75856-codewhale-ssrf-dns-pinning-toctou</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T18:09:06.106Z</news:publication_date>
      <news:title>CVE-2026-75856: CodeWhale (deepseek-tui) SSRF via DNS Pinning TOCTOU Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-75857-codewhale-exec-shell-interact-approval-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T18:12:15.028Z</news:publication_date>
      <news:title>CVE-2026-75857: CodeWhale exec_shell_interact Approval Bypass Privilege Escalation</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-75858-codewhale-rlm-eval-approval-bypass-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T18:15:16.052Z</news:publication_date>
      <news:title>CVE-2026-75858: CodeWhale rlm_eval Approval Bypass Leading to Unsandboxed RCE</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-75859-codewhale-instructions-arbitrary-file-read</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T18:18:17.480Z</news:publication_date>
      <news:title>CVE-2026-75859: deepseek-tui (CodeWhale) Arbitrary File Read via Project Config instructions Override</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-75911-codewhale-allow-shell-project-config-code-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T18:21:54.648Z</news:publication_date>
      <news:title>CVE-2026-75911: deepseek-tui (CodeWhale) Project Config allow_shell Override Enables Arbitrary Shell Execution</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-75913-codewhale-git-show-argument-injection-file-write</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T18:17:06.289Z</news:publication_date>
      <news:title>CVE-2026-75913: CodeWhale Argument Injection in git_show Allows Arbitrary File Write</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-75914-codewhale-image-analyze-symlink-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T17:49:05.446Z</news:publication_date>
      <news:title>CVE-2026-75914: CodeWhale image_analyze Symlink Path Traversal</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-75915-codewhale-js-execution-env-leak</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T18:10:18.377Z</news:publication_date>
      <news:title>CVE-2026-75915: CodeWhale deepseek-tui js_execution Environment Variable Leak</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/typespec-spector-unauthenticated-admin-stop-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T21:48:42.840Z</news:publication_date>
      <news:title>@typespec/spector Unauthenticated Remote Shutdown via POST /.admin/stop</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
</urlset>