“CSRF vulnerability” — 10 distilled results

ZAST.AI's engine flagged CVE-2026-19895 in OpenSourcePOS ≤ 3.4.2: login has no rate limiting, and CAPTCHA runs after the password check. That ordering turns credential correctness into an observable o

2: login has no rate limiting, and CAPTCHA runs after the password check. That ordering turns credential correctness into an observable oracle — a correct password returns a different error than a wrong one, so accounts get enumerated without solving a CAPTCHA.

SkillBloat: Token Amplification Attacks via Skill Injection in LLM Coding Agents

21929v1 Announce Type: new Abstract: Agent skills extend coding agents with task-specific instructions, scripts, and resources, but they also create a trusted instruction channel that can be abused beyond conventional security attacks. This paper studies token amplification through skill injection: an economic resource-abuse threat in which a malicious skill causes an agent to consume substantially more tokens than needed for normal task execution.