<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9"
        xmlns:image="http://www.google.com/schemas/sitemap-image/1.1">
  <url>
    <loc>https://laautopsia.com/vulnerabilidad/escape-sandbox-via-constructor-function-codemode-paquete-npm</loc>
    <image:image>
      <image:loc>https://storage.googleapis.com/autopsia-45ba4.firebasestorage.app/vulnerabilities/GHSA-vmmj-pfw7-fjwp/apisdom-autopsia-alertas-a2-2026-06-19.webp</image:loc>
    </image:image>
    <news:news>
      <news:publication>
        <news:name>La AutopsIA</news:name>
        <news:language>es</news:language>
      </news:publication>
      <news:publication_date>2026-06-19T10:53:48.115Z</news:publication_date>
      <news:title>Escape de sandbox via constructor Function en codeMode del paquete npm praisonai</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://laautopsia.com/vulnerabilidad/openclaw-omite-validacion-argpattern-listas-blancas-exec-linux</loc>
    <image:image>
      <image:loc>https://storage.googleapis.com/autopsia-45ba4.firebasestorage.app/vulnerabilities/GHSA-v2ww-5rh7-2h5v/apisdom-autopsia-alertas-a1-2026-06-19.webp</image:loc>
    </image:image>
    <news:news>
      <news:publication>
        <news:name>La AutopsIA</news:name>
        <news:language>es</news:language>
      </news:publication>
      <news:publication_date>2026-06-19T10:48:58.397Z</news:publication_date>
      <news:title>OpenClaw omite validación de argPattern en listas blancas exec en Linux y macOS</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://laautopsia.com/vulnerabilidad/exfiltracion-datos-fuera-banda-claude-code-via-dominio</loc>
    <image:image>
      <image:loc>https://storage.googleapis.com/autopsia-45ba4.firebasestorage.app/vulnerabilities/GHSA-fg94-h982-f3mm/apisdom-autopsia-alertas-a2-2026-06-18.webp</image:loc>
    </image:image>
    <news:news>
      <news:publication>
        <news:name>La AutopsIA</news:name>
        <news:language>es</news:language>
      </news:publication>
      <news:publication_date>2026-06-18T00:54:04.045Z</news:publication_date>
      <news:title>Exfiltración de datos fuera de banda en Claude Code via dominio HuggingFace pre-aprobado en WebFetch</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://laautopsia.com/vulnerabilidad/langflow-subida-archivos-autenticacion-permite-dos-filtracion-rutas</loc>
    <image:image>
      <image:loc>https://storage.googleapis.com/autopsia-45ba4.firebasestorage.app/vulnerabilities/GHSA-x223-p2gf-v735/apisdom-autopsia-alertas-a1-2026-06-18.webp</image:loc>
    </image:image>
    <news:news>
      <news:publication>
        <news:name>La AutopsIA</news:name>
        <news:language>es</news:language>
      </news:publication>
      <news:publication_date>2026-06-18T00:25:16.401Z</news:publication_date>
      <news:title>Langflow: subida de archivos sin autenticación permite DoS y filtración de rutas absolutas</news:title>
    </news:news>
  </url>
</urlset>