Articles
Daily digests summarizing the vulnerabilities and incidents tracked by VulnWatch.
-
· 19 entries · daily · Subscribers only
Agentic Chaos: Critical Auth Bypasses in n8n and LiteLLM Shake AI Ops
A surge of high-severity vulnerabilities in n8n and LiteLLM exposes critical flaws in AI agent authorization, allowing privilege escalation and credential theft via MCP and custom code paths.
-
· 60 entries · daily · Subscribers only
VulnWatch Digest: Oracle Coherence RCE Flood and PraisonAI Agent Risks
A massive batch of critical RCE vulnerabilities hits Oracle Coherence, threatening AI data grids. Simultaneously, PraisonAI agents face severe code execution risks via default insecure configurations.
-
· 11 entries · daily · Subscribers only
VulnWatch Daily: Critical Supply Chain Compromise and Agentic Logic Flaws
Today's digest highlights a critical npm supply chain attack targeting NestJS auth modules, severe logic flaws in AgenticMail enabling session hijacking, and new DoS vectors in Markdown parsers and vLLM.
-
· 120 entries · weekly
VulnWatch Weekly: The Langflow Catastrophe & MCP Supply Chain Risks
This week is dominated by a critical cluster of RCE and auth-bypass flaws in IBM Langflow, alongside severe multi-tenant isolation failures in the emerging Model Context Protocol (MCP) ecosystem. Immediate patching is required for Langflow instances and MCP servers handling sensitive workflows.
-
· 1 entry · daily · Subscribers only
Keras TorchModuleWrapper Flaw Enables RCE via Unsafe Pickle Deserialization
A critical high-severity vulnerability in Keras 3.15.0 allows arbitrary code execution through unsafe PyTorch pickle deserialization in TorchModuleWrapper, demanding immediate patching for ML platforms processing untrusted model configurations.
-
· 33 entries · daily · Subscribers only
Langflow Catastrophe: 15 Critical Flaws Enable Unauthenticated RCE
A massive cluster of critical vulnerabilities in IBM Langflow allows unauthenticated remote code execution via default configurations. Additional risks identified in AI IDEs, MCP servers, and inference engines require immediate attention.
-
· 15 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in SGLang, Kiota Path Traversal, and MCP Supply Chain Risks
Today's digest highlights critical RCE in SGLang's ZeroMQ interface, path traversal in Microsoft Kiota plugins, and multiple supply chain vulnerabilities affecting Model Context Protocol (MCP) servers and agents.
-
· 19 entries · daily · Subscribers only
VulnWatch Daily: Critical MCP Supply Chain & Agentic RCE Surge
A wave of critical vulnerabilities targets the Model Context Protocol (MCP) ecosystem, enabling tenant data leakage, unauthenticated RCE, and SSRF in major AI orchestration tools including n8n, LangBot, and Grafana.
-
· 38 entries · daily · Subscribers only
VulnWatch Daily: Critical MCP Flaws, NVIDIA Stack RCE, and Copilot Injections
Today's digest highlights critical vulnerabilities in the Model Context Protocol ecosystem, including cross-tenant data leaks and SSRF. We also cover a wave of RCE flaws in NVIDIA's inference stack and command injection risks in major Copilot products.
-
· 40 entries · daily · Subscribers only
VulnWatch Daily: Critical SQLi in AI Copilots and Agentic RCE Waves
Today's digest highlights a critical SQL injection in AIWU's copilot, widespread SSRF and RCE vulnerabilities in agentic frameworks like CrewAI and LiteLLM, and severe data leakage risks in vLLM and MLflow serving stacks.
-
· 15 entries · daily · Subscribers only
VulnWatch Daily: Agent Autonomy Risks and LiteLLM Gateway Flaws Dominate July 8 Digest
Today's digest highlights critical vulnerabilities in autonomous coding agents and the LiteLLM proxy stack. Security teams must prioritize patching agent SDKs and enforcing strict authentication on AI gateways to prevent RCE and data exfiltration.
-
· 60 entries · daily · Subscribers only
VulnWatch Daily: Critical Auth Bypasses in Langflow & Cognee; vLLM RCE Surge
Today's digest highlights critical authentication failures in Langflow and Cognee, alongside a significant cluster of RCE and DoS vulnerabilities in vLLM and MLflow affecting model serving and pipeline integrity.
-
· 33 entries · daily · Subscribers only
VulnWatch Daily: Critical Agent Escapes and Platform Instability Surge
33 new vulnerabilities reported today, including critical RCE in Langroid and Crawl4AI, plus extensive authentication flaws in Coder. Immediate patching recommended for AI inference and agent frameworks.
-
· 79 entries · weekly
VulnWatch Weekly: Langflow Cascade & MCP Ecosystem Risks
Langflow faces a critical week with 10+ CVEs including RCE and secret leakage. MCP servers show systemic auth flaws. Action required on model loading.
-
· 2 entries · daily · Subscribers only
VulnWatch Daily: Auth Bypass in WeChat Agents & LangGraph Cache Risks
Today's digest covers a medium-severity authentication bypass in chatgpt-on-wechat and a low-severity weak hash vulnerability in LangGraph. Immediate patching is recommended for WeChat integrations.