Articles
Daily digests summarizing the vulnerabilities and incidents tracked by VulnWatch.
-
· 79 entries · weekly
VulnWatch Weekly: Langflow Cascade & MCP Ecosystem Risks
Langflow faces a critical week with 10+ CVEs including RCE and secret leakage. MCP servers show systemic auth flaws. Action required on model loading.
-
· 10 entries · daily · Subscribers only
VulnWatch Daily: MCP Servers Face Injection Risks; Triton DoS Patched
Today's digest highlights critical injection flaws in Model Context Protocol servers, alongside denial-of-service vectors in NVIDIA Triton and supply-chain risks in AI development tools.
-
· 18 entries · daily · Subscribers only
VulnWatch Daily: Langflow Critical Cluster and AI Supply Chain Risks
Critical Langflow vulnerabilities dominate today's digest alongside RCE risks in LLaMA-Factory and MCP auth bypasses. Immediate patching recommended for AI orchestration layers.
-
· 33 entries · daily · Subscribers only
VulnWatch Daily: Claude Code Sandbox Escapes and Serving RCE
Today's digest highlights critical sandbox escapes in Claude Code and a wave of RCE vulnerabilities in model serving frameworks like vLLM and MLflow. LiteLLM and LangChain also show significant auth and injection flaws requiring immediate patching.
-
· 120 entries · weekly
VulnWatch Weekly: Agentic RCE & Supply Chain Risks Surge
Critical vulnerabilities in Langflow, vLLM, and MCP servers highlight severe risks in AI tooling. Immediate patching required for agentic platforms and inference engines to prevent RCE and supply chain compromise.
-
· 23 entries · daily · Subscribers only
VulnWatch Daily: Critical MCP Agent Flaws and Supply Chain Compromises
23 new vulnerabilities reported today including CVSS 10.0 MCP server flaws, compromised litellm wheels, and critical Incus RCEs. Immediate patching recommended for agent frameworks and container infrastructure.
-
· 29 entries · daily · Subscribers only
VulnWatch Daily: Critical vLLM & Langflow Compromises Dominate June 22 Digest
29 new vulnerabilities reported today, including critical RCE in Langflow and multiple auth bypasses in vLLM. Immediate patching recommended for inference stacks.
-
· 120 entries · weekly
VulnWatch Weekly: PraisonAI Auth Collapse & MCP Server Exposure
This week saw a cascade of critical vulnerabilities in PraisonAI agents and widespread authentication failures in Model Context Protocol servers. Oracle Coherence and Langflow also shipped critical RCEs requiring immediate patching.
-
· 43 entries · daily · Subscribers only
VulnWatch Daily: PraisonAI Critical RCE Cluster & MCP Auth Failures
Over 40 AI vulnerabilities disclosed today, led by critical RCE chains in PraisonAI and unauthenticated MCP servers. Immediate patching recommended for agentic frameworks.
-
· 29 entries · daily · Subscribers only
VulnWatch Daily: Critical Oracle Coherence RCE and Agent Control Plane Exposures
29 new vulnerabilities reported today including CVSS 10.0 Oracle Coherence flaws, widespread MCP agent misconfigurations, and inference engine robustness issues in vLLM and Open WebUI.
-
· 25 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in Langflow & Crawl4AI Docker APIs
25 new vulnerabilities reported today. Critical RCE risks in Langflow and Crawl4AI demand immediate patching. Model serving engines and web frameworks also affected.
-
· 4 entries · daily · Subscribers only
VulnWatch Daily: AI IDE Risks, Supply Chain Flaws, and Parser Overflows
Today's digest covers high-severity risks in AI-assisted IDEs, multimedia parsers, and critical web sanitization libraries used in AI dashboards.
-
· 78 entries · weekly
VulnWatch Weekly: Agentic RCE Epidemic & MCP Trust Boundaries Collapse
78 vulnerabilities tracked this week. PraisonAI, SillyTavern, and MCP servers dominate critical RCE reports. Immediate patching required for agent frameworks.
-
· 28 entries · daily · Subscribers only
VulnWatch Daily: Agentic Frameworks Crisis & Local LLM UI Risks
Critical sandbox escapes in PraisonAI and auth bypasses in SillyTavern dominate today's digest. MCP ecosystem and RAG platforms also show significant supply chain risks requiring immediate patching.
-
· 16 entries · daily · Subscribers only
VulnWatch: NVIDIA Inference Stack Critical Flaws & AI Supply Chain Risks
Critical authentication bypasses in NVIDIA Triton and deserialization risks in TRT-LLM dominate today's digest. Plus, new supply chain threats in Diffusers and agent tooling.