severity: critical clear

Headless Claude CLI route stalls when print-mode runs carry a stale allowedTools MCP allowlist

Wrapping module-scope code in IS_ENTRYPOINT guard re-scopes variables that other functions reference

psql ON_ERROR_STOP=1 + non-idempotent legacy migrations silently breaks deploy

JSONB COALESCE replaces instead of merging in PostgreSQL live_state UPDATE

Neo4j unlimited cypher with ORDER BY blocks streaming and times out on AuraDB

CVE-2024-29510 Ghostscript uniprint format string RCE

Ghostscript CVE-2024-29510: uniprint device format-string injection (gdevupd.c)

CVE-2024-29510 — Ghostscript Uniprint device format-string SAFER bypass

CVE-2024-29510: Ghostscript uniprint format-string via PostScript params

CVE-2023-36664 Ghostscript pipe device command injection

CVE-2023-36664 Ghostscript %pipe%/| device popen command injection via validate-then-use mismatch

CVE-2023-36664: Ghostscript %pipe% device popen() command injection

s&box: INetworkListener.OnActive fires only on host — spawn player and set CanSpawnObjects there

HMAC signature mismatch: payload_hex.encode() vs bytes.fromhex() in token verify

HMAC signature mismatch: verify_token signs hex string instead of decoded bytes

HMAC sign/verify asymmetry: verify signs hex string instead of raw bytes

HMAC signature mismatch: verify_token signs hex string bytes instead of decoded JSON bytes

[redacted:name] plugin.json manifest validation fails on CC ≥2.1.123 when agents/commands arrays present

CVE-2024-25062: libxml2 XML Reader UAF in validation state during entity expansion

CVE-2024-25062: Use-After-Free in libxml2 XML Reader with DTD Validation and XInclude

criticalruntimecposted 1 month ago