A vulnerability was found in WinterChenS my-site up to 1f7525f15934d9d6a278de967f6ec9f1757738d8. It has been declared as critical. This vulnerability affects the function preHandle of the file /admin/ of the component Backend Interface. The manipulation of the argument uri leads to improper authentication.
This vulnerability was named CVE-2025-8838. The attack can be initiated remotely. Furthermore, there is an exploit available.
The real existence of this vulnerability is still doubted at the moment.
This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
The code maintainer responded to the issue that "[he] tried it, and using this link automatically redirects to the login page."
Today we have another post about OpenHands from All Hands AI. It is a popular agent, initially named “OpenDevin”, and recently the company also provides a cloud-based service. Which is all pretty cool and exciting.
Prompt Injection to Full System Compromise However, as you know, LLM powered apps and agents are vulnerable to prompt injection. That also applies to OpenHands and it can be hijacked by untrusted data, e.g. from a website.
A vulnerability was found in JasPer up to 4.2.5. It has been classified as critical. This affects the function jpc_dec_dump of the file src/libjasper/jpc/jpc_dec.c of the component JPEG2000 File Handler. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2025-8837. An attack has to be approached locally. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in JasPer up to 4.2.5 and classified as problematic. Affected by this issue is the function jpc_floorlog2 of the file src/libjasper/jpc/jpc_enc.c of the component JPEG2000 Encoder. The manipulation leads to reachable assertion.
This vulnerability is handled as CVE-2025-8836. The attack needs to be approached locally. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability has been found in JasPer up to 4.2.5 and classified as problematic. Affected by this vulnerability is the function jas_image_chclrspc of the file src/libjasper/base/jas_image.c of the component Image Color Space Conversion Handler. The manipulation leads to null pointer dereference.
This vulnerability is known as CVE-2025-8835. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.