BlackTree Security · Infrastructure · Automation · AI

BlackTree — Independent Technology Analysis

BlackTree Editorial

Independent technology intelligence Analysis · Technical guides · Homelab · Legacy systems

Security, systems and emerging technology

Know the signal behind the incident.

Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

Evidence-linked Operational context Independent

A Prefix Check Could Let JavaScript Escape vm2

A missing path boundary turned an allowed module into a route to neighbouring code running inside the host process.

Read the article ↗

Current reporting

Latest intelligence

View all articles ↗

A Sylius Customer Login Could Open the Admin API

Sylius disclosed on 2 September that a shop customer’s token could be accepted by its Admin API. Two accompanying advisories cover password-reset links and payment totals. These are previously missed disclosures, revalidated after their records were indexed on 27 September.

For operators, the review has two tracks: who received administrative access, and whether the money captured matches the orders marked paid. Closing an authentication flaw does not reconcile historical orders.

CVE-2026-100871 affects Sylius releases before 1.12.25, 1.13.17, 1.14.20, 2.1.16 and 2.2.9. The vendor says the Admin and Shop API firewalls signed tokens with the same key, but the tokens did not include an audience or firewall identifier.

The attack prerequisites are that the API is enabled, shop registration is available and the targeted administrator has API access. An attacker who knows that administrator's email address can register an ordinary shop account with the same address, sign in using the attacker's own password and present the resulting token to the Admin API.

CVE-2026-100870 affects the same version ranges. The primary advisory says Sylius built an absolute administrator password-reset link using the request's Host header unless the deployment supplied its own trusted-host configuration.

The advisory's attack path lets an unauthenticated attacker request a reset for a known administrator address and supply a forged host. The resulting email is otherwise genuine, but its link sends the valid token to the attacker's domain. If the administrator follows it, the attacker can reuse the token against the real shop and set a new password.

CVE-2026-100872 affects Sylius 2.x releases…

27 Sep 2026 · 3 min read

A Wrong Password Could Run Code Inside hMailServer

A wrong password can become code before the login succeeds. Progressive Robot’s hMailServer 6.3.4 release on 27 September fixes that risk in its Windows 6.x project. The issue should not be generalised…

27 Sep 2026 · 2 min read

A Botnet Seller Is Offering to Drain Your AI Budget

Qrator Research Labs has examined an advertised Windows botnet called x47.c whose seller offers an AI API drain mode. It requires the operator to supply a valid account key and sends billable…

27 Sep 2026 · 3 min read

Revised reporting

Recently updated

View all articles

Geographic context

Regional intelligence

Browse all articles ↗

Coverage leaders

Vendor intelligence

Browse all articles ↗

Practical archive

Lab &
Legacy

Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.