arbitrary code execution
Coverage of arbitrary code execution in the Nexus archive.
- Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
Three high-severity security flaws in Hugging Face's Diffusers library could allow crafted model repositories to execute arbitrary code, bypassing the trust_remote_code safeguard designed to prevent unreviewed code execution. This poses a risk to the artificial intelligence (AI) supply chain.
- Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
Adobe has released security updates to address a critical flaw in Campaign Classic (ACC), allowing arbitrary code execution due to incorrect authorization. The vulnerability, CVE-2026-48449, has a maximum CVSS severity score of 10.0.
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
A maximum-severity command injection vulnerability (CVE-2026-16812) in on-premises versions of Arista VeloCloud Orchestrator is being actively exploited, allowing arbitrary code execution. The flaw, rated with a CVSS score of 10.0, enables attackers to execute operating system commands through the affected system.
- Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
Zimbra is urging customers to apply updates to address a critical security vulnerability in the Classic Web Client that could allow arbitrary code execution via stored cross-site scripting (XSS). The flaw could enable malicious scripts to run in user sessions through specially crafted emails and has not yet been assigned a CVE identifier.
- Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code
A critical remote code execution (RCE) vulnerability has been disclosed in Gogs, an open-source self-hosted Git service, allowing authenticated users to execute arbitrary code. The flaw is rated 9.4 on the CVSS scoring system and currently lacks a CVE identifier.
- Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution
Google has patched a critical security vulnerability (CVSS 10) in the Gemini CLI npm package and GitHub Actions workflow, which could have enabled unprivileged attackers to execute arbitrary code on host systems by injecting malicious configuration content.
- Google Fixes Critical RCE Flaw in AI-Based Antigravity Tool
Google addressed a critical remote code execution (RCE) vulnerability in its AI-based Antigravity Tool. The flaw, a prompt injection vulnerability in an agentic AI product for filesystem operations, stemmed from a sanitization issue enabling sandbox escape and arbitrary code execution.