remote-code-execution
Safeguard articles tagged "remote-code-execution" — guides, analysis, and best practices for software supply chain and application security.
63 articles
A 9.9-Severity Code Execution Bug in n8n Shows the Risk Built Into Workflow Automation
A flaw in n8n's expression evaluation system let authenticated users escape its execution sandbox entirely, confirmed exploited by malware documented targeting the platform.
Laravel Livewire's Hydration Flaw Let Attackers Skip Authentication Entirely
CVE-2025-54068 lets unauthenticated attackers achieve remote command execution in Laravel Livewire v3 through how component property updates are hydrated, with no known workaround.
HPE OneView and Fortra GoAnywhere MFT: Two Perfect-10 Unauthenticated RCEs
Infrastructure management and managed file transfer software rarely share a vulnerability post, but both HPE OneView and Fortra GoAnywhere MFT scored a maximum CVSS 10.0 for unauthenticated RCE.
Craft CMS's Perfect-Score CVE Was the Fix Behind an Older Fix
CVE-2025-32432 scores a maximum 10.0 and is confirmed exploited — and NVD's own record calls it an additional fix for a 2023 vulnerability that wasn't fully closed the first time.
CVE-2026-63077: Your Build Server Is a Credential Store With an Open Port
An unauthenticated attacker sends a crafted object to TeamCity's agent polling endpoint and gets OS command execution as the server process. Every credential the build server holds sits downstream.
CVE-2026-9198: Two Endpoints, No Password, Full Remote Code Execution
Langflow's auto-login endpoint mints a superuser token for anyone who asks. Its code-validation endpoint runs Python through exec(). Chained, that is unauthenticated RCE at CVSS 9.8.
H2 database console remote code execution (CVE-2021-42392)
CVE-2021-42392 lets attackers trigger RCE in H2's console and JDBC URL handling via a Log4Shell-style JNDI gadget. Here's what's affected and how to fix it.
Apache Solr XXE remote code execution (CVE-2017-12629)
CVE-2017-12629 chains XXE and Solr's RunExecutableListener into unauthenticated RCE. Affected versions, timeline, and concrete remediation steps.
Insecure deserialization vulnerabilities explained
Insecure deserialization vulnerabilities let attackers turn trusted classes into gadget chains for RCE. See real CVEs, affected languages, and fixes.
Server-side template injection (SSTI) explained
SSTI lets attackers turn template syntax into server-side RCE. See how it works, real CVEs like Confluence's, and how to prevent it.
CocoaPods Trunk Server Remote Code Execution (CVE-2024-38...
CVE-2024-38366 exposed a critical remote code execution flaw in the CocoaPods trunk server, threatening the iOS dependency supply chain for years undetected.
Git Remote Code Execution via Malicious .gitmodules Submo...
CVE-2018-11235 let a malicious .gitmodules file hijack Git submodule checkout, executing arbitrary code via post-checkout hooks on clone.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.