Articles
Daily digests summarizing the vulnerabilities and incidents tracked by VulnWatch.
-
· 19 entries · daily · Subscribers only
Critical RCE Wave Hits llama.cpp and MCP Frameworks
A surge of critical vulnerabilities targets core AI infrastructure, including sandbox escapes in Model Context Protocol and multiple memory corruption flaws in llama.cpp enabling remote code execution.
-
· 33 entries · daily · Subscribers only
Langflow Catastrophe: 20+ RCEs, Supply Chain Risks, and Agentic Flaws
A historic wave of vulnerabilities hits IBM Langflow with 20+ CVEs including unauthenticated RCE. Critical issues also found in PraisonAI CI/CD, Hugging Face PEFT deserialization, and Milvus DoS.
-
· 43 entries · daily · Subscribers only
Critical Flowise RCE Wave and Langflow Injection Compromise AI Supply Chain
A massive cluster of vulnerabilities in Flowise and a critical CISA-listed flaw in Langflow expose AI platforms to unauthenticated RCE, credential theft, and supply-chain compromise. Immediate patching and network isolation are required.
-
· 58 entries · weekly
VulnWatch Weekly: The Agentic Apocalypse & Supply Chain Meltdown
This week marks a turning point for AI security with critical RCEs in Langflow, Flyto2, and sentence-transformers. The dominant theme is the collapse of trust boundaries in agentic workflows, demanding immediate patching of model serving and orchestration layers.
-
· 9 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in Transformers & Agentic Supply Chain Risks
Today's digest highlights a critical trust bypass in sentence-transformers enabling RCE, a parser mismatch in pgAdmin allowing SQL injection via LLM, and multiple MCP server vulnerabilities exposing local files and workflow templates.
-
· 20 entries · daily · Subscribers only
Critical Agentic Vulnerabilities: Flyto2, Langflow, and MCP SDK Exploits
A surge of critical vulnerabilities in AI agent frameworks allows arbitrary code execution, secret exfiltration, and cross-tenant data leakage. Immediate patching is required for Flyto2 Core, IBM Langflow, and MCP SDKs.
-
· 14 entries · daily · Subscribers only
VulnWatch Daily: Critical SSRF in Flyto2, MCP SDK Flaws, and Agent Auth Bypasses
Today's digest covers critical SSRF vulnerabilities in Flyto2 Core exposing API keys, a cluster of DoS and session hijacking flaws in the MCP Ruby SDK, and auth bypasses in Quarkus and Pydantic AI affecting generative workflows.
-
· 120 entries · weekly
VulnWatch Weekly: Oracle Coherence Flood, Supply Chain Poisoning, and Agentic RCE
This week saw an unprecedented flood of Oracle Coherence RCEs, a critical npm supply chain compromise, and severe agentic vulnerabilities in M365 Copilot and PraisonAI. Immediate patching and supply chain audits are required.
-
· 20 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in Prompty, Copilot, and Agentic Supply Chains
Today's digest highlights critical remote code execution flaws in Prompty and M365 Copilot, alongside severe agentic vulnerabilities in Suna, Budibase, and AWS Bedrock that threaten multi-tenant isolation and credential security.
-
· 15 entries · daily · Subscribers only
VulnWatch Daily: Critical h2oGPT RCE and Agentic Supply Chain Risks
Today's digest highlights a critical path traversal in h2oGPT enabling full server compromise, alongside widespread agentic vulnerabilities in MCP servers and LiteLLM that threaten tool-use security boundaries.
-
· 19 entries · daily · Subscribers only
Agentic Chaos: Critical Auth Bypasses in n8n and LiteLLM Shake AI Ops
A surge of high-severity vulnerabilities in n8n and LiteLLM exposes critical flaws in AI agent authorization, allowing privilege escalation and credential theft via MCP and custom code paths.
-
· 11 entries · daily · Subscribers only
VulnWatch Daily: Critical Supply Chain Compromise and Agentic Logic Flaws
Today's digest highlights a critical npm supply chain attack targeting NestJS auth modules, severe logic flaws in AgenticMail enabling session hijacking, and new DoS vectors in Markdown parsers and vLLM.
-
· 120 entries · weekly
VulnWatch Weekly: The Langflow Catastrophe & MCP Supply Chain Risks
This week is dominated by a critical cluster of RCE and auth-bypass flaws in IBM Langflow, alongside severe multi-tenant isolation failures in the emerging Model Context Protocol (MCP) ecosystem. Immediate patching is required for Langflow instances and MCP servers handling sensitive workflows.
-
· 33 entries · daily · Subscribers only
Langflow Catastrophe: 15 Critical Flaws Enable Unauthenticated RCE
A massive cluster of critical vulnerabilities in IBM Langflow allows unauthenticated remote code execution via default configurations. Additional risks identified in AI IDEs, MCP servers, and inference engines require immediate attention.
-
· 15 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in SGLang, Kiota Path Traversal, and MCP Supply Chain Risks
Today's digest highlights critical RCE in SGLang's ZeroMQ interface, path traversal in Microsoft Kiota plugins, and multiple supply chain vulnerabilities affecting Model Context Protocol (MCP) servers and agents.