<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/autonomous-penetration-testing-complete-guide-2026/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T18:45:36.000Z</news:publication_date>
      <news:title>Autonomous Penetration Testing: Complete Guide 2026</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://blog.securelayer7.net/shadow-ai/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T08:22:23.000Z</news:publication_date>
      <news:title>Shadow AI: Risks, How It Works and How to Protect</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-45018-chainlit-mcp-stdio-command-injection-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T19:30:11.793Z</news:publication_date>
      <news:title>CVE-2026-45018: Chainlit Unauthenticated Remote Code Execution via MCP stdio Command Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-45019-chainlit-mcp-ssrf-internal-network</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T19:29:02.230Z</news:publication_date>
      <news:title>CVE-2026-45019: Chainlit SSRF via MCP SSE and Streamable-HTTP Transports</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-48853-elixir-grpc-erlpack-unsafe-deserialization-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T18:37:53.869Z</news:publication_date>
      <news:title>CVE-2026-48853: erlang/grpc Unsafe Deserialization Leading to RCE and DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-48854-elixir-grpc-unbounded-body-memory-exhaustion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T18:31:34.898Z</news:publication_date>
      <news:title>CVE-2026-48854: elixir-grpc Unbounded Request Body Memory Exhaustion</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-49757-ash-authentication-oauth2-oidc-account-takeover-email-spoofing</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T18:29:04.496Z</news:publication_date>
      <news:title>CVE-2026-49757: ash_authentication OAuth2/OIDC Account Takeover via Email Spoofing</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53430-elixir-grpc-gzip-decompression-bomb-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T18:30:13.786Z</news:publication_date>
      <news:title>CVE-2026-53430: elixir-grpc Unbounded gzip Decompression Bomb (DoS)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54049-sakai-conversations-stored-xss-unsanitized-messages</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-24T19:50:19.285Z</news:publication_date>
      <news:title>CVE-2026-54049: Sakai Conversations Stored XSS via Unsanitized Topic and Post Messages</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54623-django-cms-move-plugin-cyclic-reparenting-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-24T20:28:49.690Z</news:publication_date>
      <news:title>CVE-2026-54623: django-cms Plugin Move Endpoint Cyclic Reparenting DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55099-icalendar-component-equality-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T19:48:49.929Z</news:publication_date>
      <news:title>CVE-2026-55099: icalendar Algorithmic Complexity Denial of Service in Component Equality</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55477-3x-ui-arbitrary-file-write-xray-log-path</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-24T21:08:56.562Z</news:publication_date>
      <news:title>CVE-2026-55477: 3X-UI Authenticated Arbitrary File Write via Xray Log Path</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55523-praisonaiagents-web-crawl-ssrf-redirect-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T14:29:01.586Z</news:publication_date>
      <news:title>CVE-2026-55523: praisonaiagents web_crawl SSRF via Unvalidated Redirect Target</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55524-praisonaiagents-ssrf-web-crawl-redirect-dns-rebinding</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T14:49:14.600Z</news:publication_date>
      <news:title>CVE-2026-55524: praisonaiagents SSRF via Redirect and DNS Rebinding in web_crawl</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55525-praisonaiagents-web-crawl-ssrf-redirect-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T14:09:13.909Z</news:publication_date>
      <news:title>CVE-2026-55525: praisonaiagents web_crawl SSRF via Redirect Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55526-praisonaiagents-ssrf-dns-bypass-spider-tools</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T14:51:00.533Z</news:publication_date>
      <news:title>CVE-2026-55526: praisonaiagents SSRF Protection Bypass via Wildcard DNS Hostname</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55528-praisonaiagents-agentserver-missing-authentication</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T14:52:09.340Z</news:publication_date>
      <news:title>CVE-2026-55528: praisonaiagents AgentServer Missing Authentication</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55532-praisonai-mcp-origin-csrf-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T15:31:08.480Z</news:publication_date>
      <news:title>CVE-2026-55532: PraisonAI MCP HTTP Server Origin Validation Bypass (CSRF)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55536-praisonai-websocket-origin-regex-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T15:30:01.275Z</news:publication_date>
      <news:title>CVE-2026-55536: PraisonAI WebSocket Origin Validation Bypass via Unanchored Regex</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55537-praisonai-webhook-ssrf-dns-fail-open-toctou</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T15:10:11.732Z</news:publication_date>
      <news:title>CVE-2026-55537: PraisonAI Webhook SSRF via DNS Fail-Open and TOCTOU Race</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55538-praisonai-serve-agents-api-key-auth-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T15:11:31.693Z</news:publication_date>
      <news:title>CVE-2026-55538: PraisonAI serve agents --api-key Authentication Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55539-praisonai-jobs-api-missing-authentication</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T15:35:37.308Z</news:publication_date>
      <news:title>CVE-2026-55539: PraisonAI Jobs API Missing Authentication</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55541-praisonai-serve-api-key-missing-authorization</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T15:08:58.250Z</news:publication_date>
      <news:title>CVE-2026-55541: PraisonAI serve --api-key Flag Missing Authorization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55546-qwed-mcp-sympy-parse-expr-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T15:28:43.436Z</news:publication_date>
      <news:title>CVE-2026-55546: qwed-mcp Remote Code Execution via Unsafe SymPy parse_expr()</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55553-urllib-cross-origin-redirect-credential-leakage</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T16:30:13.085Z</news:publication_date>
      <news:title>CVE-2026-55553: urllib Cross-Origin Redirect Credential Leakage</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55571-djust-liveview-websocket-auth-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T16:14:52.083Z</news:publication_date>
      <news:title>CVE-2026-55571: djust LiveView WebSocket Authentication Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55580-mcp-shell-command-injection-security-disabled-default-shell-inter</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T15:49:03.237Z</news:publication_date>
      <news:title>CVE-2026-55580: mcp-shell OS Command Injection via Security-Disabled Default and Shell Interpreter in Allowlist</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55581-mcp-shell-allowlist-bypass-bash-command-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T15:50:13.471Z</news:publication_date>
      <news:title>CVE-2026-55581: mcp-shell Secure Mode Allowlist Bypass via /bin/bash -c</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55582-mcp-shell-git-alias-command-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T15:51:22.523Z</news:publication_date>
      <news:title>CVE-2026-55582: mcp-shell Secure Mode Allowlist Bypass via Git Shell Alias</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55585-qwed-authenticated-rce-sympy-parse-expr</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T16:28:58.191Z</news:publication_date>
      <news:title>CVE-2026-55585: qwed Authenticated Remote Code Execution via Unsafe SymPy parse_expr()</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55596-platejs-media-embed-stored-xss-provider-metadata</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T16:48:48.260Z</news:publication_date>
      <news:title>CVE-2026-55596: @platejs/media Media Embed Stored XSS via Serialized Provider Metadata</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55604-deepseek-mcp-server-session-hijack</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T18:48:47.330Z</news:publication_date>
      <news:title>CVE-2026-55604: @arikusi/deepseek-mcp-server Cross-Session Authorization Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55620-eml-parser-dos-nested-parens-received-header</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T18:36:08.765Z</news:publication_date>
      <news:title>CVE-2026-55620: eml_parser ReDoS via Deeply Nested Parentheses in Received Headers</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55629-whistle-arbitrary-file-read-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T18:34:53.706Z</news:publication_date>
      <news:title>CVE-2026-55629: whistle Arbitrary File Read via Path Traversal</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55637-genieacs-mcp-dns-rebinding-origin-validation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T18:08:49.899Z</news:publication_date>
      <news:title>CVE-2026-55637: genieacs-mcp DNS Rebinding via Missing Host and Origin Validation</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55640-nextcloud-mcp-server-unauthenticated-webhook-vector-deletion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T16:09:19.454Z</news:publication_date>
      <news:title>CVE-2026-55640: nextcloud-mcp-server Unauthenticated Webhook Allows Arbitrary Vector Data Deletion</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55677-echo-encoded-slash-route-bypass-static-file-disclosure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T16:31:27.091Z</news:publication_date>
      <news:title>CVE-2026-55677: Echo v5 Encoded Slash Route-Bypass Exposes Static Files</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56777-phpmyfaq-group-permissions-privilege-escalation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T17:50:34.647Z</news:publication_date>
      <news:title>CVE-2026-56777: phpMyFAQ GroupController Privilege Escalation via Missing Self-Rights Constraint</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-9769-justhtml-uncontrolled-recursion-dos-nested-html</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T16:50:51.995Z</news:publication_date>
      <news:title>CVE-2026-9769: justhtml Uncontrolled Recursion DoS via Deeply Nested HTML</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/mcp-contextforge-gateway-ssti-jinja2-rce-prompt-service</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T17:48:45.446Z</news:publication_date>
      <news:title>mcp-contextforge-gateway Server-Side Template Injection (SSTI) leading to RCE</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/pickem-terminal-escape-sequence-injection-unsanitized-labels</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T16:10:32.974Z</news:publication_date>
      <news:title>pickem Terminal Escape-Sequence Injection via Unsanitized Item Labels</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/postgres-protocol-scram-iteration-count-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-24T19:49:03.531Z</news:publication_date>
      <news:title>postgres-protocol: Unbounded SCRAM Iteration Count CPU Exhaustion DoS</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/utcp-http-oauth2-tokenurl-ssrf-credential-theft</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T16:11:36.956Z</news:publication_date>
      <news:title>utcp-http OAuth2 tokenUrl Trust Boundary Bypass (SSRF and Credential Theft)</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/utcp-http-ssrf-unvalidated-redirect-call-tool</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T16:16:10.987Z</news:publication_date>
      <news:title>utcp-http SSRF via Unvalidated HTTP Redirect in call_tool</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
</urlset>