Articles
Daily digests summarizing the vulnerabilities and incidents tracked by VulnWatch.
-
· 21 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in LMDeploy, MCP Supply Chain Risks, and Splunk Escalations
Today's digest highlights a critical pickle deserialization flaw in LMDeploy enabling RCE, widespread path traversal and SSRF issues in the emerging MCP ecosystem, and severe privilege escalation vectors in Splunk's AI tooling.
-
· 25 entries · daily · Subscribers only
VulnWatch Daily: Critical Agent Supply-Chain Poisoning and CodeWhale RCE
Today's digest highlights critical vulnerabilities in agentic workflows, including Kraken cache poisoning and CodeWhale auto-execution flaws. NVIDIA Triton and MONAI also require immediate attention for DoS and RCE risks.
-
· 68 entries · weekly
VulnWatch Weekly: Critical RCE in MindsDB & Agentic Supply Chain Risks
This week's digest highlights a CVSS 10.0 RCE in MindsDB allowing unauthenticated command execution via LLM prompts. We also analyze critical prototype pollution in Trigger.dev, template injection in Prompty, and widespread SSRF/RCE risks in the emerging Model Context Protocol (MCP) ecosystem.
-
· 28 entries · daily · Subscribers only
VulnWatch Daily: Critical Agentic RCE and Supply Chain Flaws in Trigger.dev, vLLM, and Flowise
Today's digest highlights critical remote code execution risks in agentic frameworks like Trigger.dev and AgenticSeek, alongside severe prompt injection bypasses in Flowise and SSRF vulnerabilities in MCP servers. Immediate patching is required for multi-tenant isolation failures.
-
· 20 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in AI Agents and Supply Chain Leaks
Today's digest highlights a critical RCE in PapersGPT via prompt injection, unauthenticated CLI servers in Claude Code, and widespread credential exfiltration risks in AI workflow platforms.
-
· 116 entries · weekly
VulnWatch Weekly: The Flowise Apocalypse & Active Langflow Exploitation
This week marks a critical turning point for AI platform security with a massive cluster of RCE vulnerabilities in Flowise and active exploitation of IBM Langflow. Immediate patching is required for model serving stacks and agentic frameworks.
-
· 19 entries · daily · Subscribers only
Critical RCE Wave Hits llama.cpp and MCP Frameworks
A surge of critical vulnerabilities targets core AI infrastructure, including sandbox escapes in Model Context Protocol and multiple memory corruption flaws in llama.cpp enabling remote code execution.
-
· 43 entries · daily · Subscribers only
Critical Flowise RCE Wave and Langflow Injection Compromise AI Supply Chain
A massive cluster of vulnerabilities in Flowise and a critical CISA-listed flaw in Langflow expose AI platforms to unauthenticated RCE, credential theft, and supply-chain compromise. Immediate patching and network isolation are required.
-
· 7 entries · daily · Subscribers only
VulnWatch Daily: Critical TLS Flaws and Agentic RCE Risks Surge
Today's digest highlights a critical TLS verification bypass in Emlog Pro, incomplete denylists in Ouroboros enabling RCE, and prompt injection vectors in Amazon Strands and MQ MCP Server.
-
· 58 entries · weekly
VulnWatch Weekly: The Agentic Apocalypse & Supply Chain Meltdown
This week marks a turning point for AI security with critical RCEs in Langflow, Flyto2, and sentence-transformers. The dominant theme is the collapse of trust boundaries in agentic workflows, demanding immediate patching of model serving and orchestration layers.
-
· 9 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in Transformers & Agentic Supply Chain Risks
Today's digest highlights a critical trust bypass in sentence-transformers enabling RCE, a parser mismatch in pgAdmin allowing SQL injection via LLM, and multiple MCP server vulnerabilities exposing local files and workflow templates.
-
· 4 entries · daily · Subscribers only
VulnWatch Daily: Llama.cpp DoS Risks and Kimi Code SSRF Flaws
Today's digest covers critical supply-chain risks in GIMP affecting AI data pipelines, denial-of-service vectors in llama.cpp's schema parsing, and a significant SSRF vulnerability in Kimi Code allowing internal network access via prompt injection.
-
· 120 entries · weekly
VulnWatch Weekly: Oracle Coherence Flood, Supply Chain Poisoning, and Agentic RCE
This week saw an unprecedented flood of Oracle Coherence RCEs, a critical npm supply chain compromise, and severe agentic vulnerabilities in M365 Copilot and PraisonAI. Immediate patching and supply chain audits are required.
-
· 20 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in Prompty, Copilot, and Agentic Supply Chains
Today's digest highlights critical remote code execution flaws in Prompty and M365 Copilot, alongside severe agentic vulnerabilities in Suna, Budibase, and AWS Bedrock that threaten multi-tenant isolation and credential security.
-
· 19 entries · daily · Subscribers only
Agentic Chaos: Critical Auth Bypasses in n8n and LiteLLM Shake AI Ops
A surge of high-severity vulnerabilities in n8n and LiteLLM exposes critical flaws in AI agent authorization, allowing privilege escalation and credential theft via MCP and custom code paths.