Articles
Daily digests summarizing the vulnerabilities and incidents tracked by VulnWatch.
-
· 4 entries · daily · Subscribers only
VulnWatch Daily: Critical Pickle Scanning Flaws and ONNX Runtime Risks
Today's digest highlights critical bypasses in model safety scanning and pickle detection, alongside runtime stability issues in ONNX and agentic memory handlers. Immediate patching is advised for serialization tools.
-
· 2 entries · daily · Subscribers only
VulnWatch Daily: Keras RCE and Kong MCP Injection Risks
Today's digest covers critical RCE in Keras deserialization and indirect prompt injection in Kong MCP servers. Immediate patching recommended for ML pipelines and agentic gateways.
-
· 10 entries · daily · Subscribers only
VulnWatch Daily: Critical MCP Auth Flaws and Azure OpenAI SSRF Lead July 2nd Digest
Today's digest highlights critical authentication bypasses in MCP servers and agent frameworks, alongside a severe SSRF in Azure OpenAI. Security teams should prioritize patching MLflow, Weaviate, and reviewing agent tool permissions immediately.
-
· 10 entries · daily · Subscribers only
VulnWatch Daily: MCP Servers Face Injection Risks; Triton DoS Patched
Today's digest highlights critical injection flaws in Model Context Protocol servers, alongside denial-of-service vectors in NVIDIA Triton and supply-chain risks in AI development tools.
-
· 18 entries · daily · Subscribers only
VulnWatch Daily: Langflow Critical Cluster and AI Supply Chain Risks
Critical Langflow vulnerabilities dominate today's digest alongside RCE risks in LLaMA-Factory and MCP auth bypasses. Immediate patching recommended for AI orchestration layers.
-
· 33 entries · daily · Subscribers only
VulnWatch Daily: Claude Code Sandbox Escapes and Serving RCE
Today's digest highlights critical sandbox escapes in Claude Code and a wave of RCE vulnerabilities in model serving frameworks like vLLM and MLflow. LiteLLM and LangChain also show significant auth and injection flaws requiring immediate patching.
-
· 120 entries · weekly
VulnWatch Weekly: Agentic RCE & Supply Chain Risks Surge
Critical vulnerabilities in Langflow, vLLM, and MCP servers highlight severe risks in AI tooling. Immediate patching required for agentic platforms and inference engines to prevent RCE and supply chain compromise.
-
· 3 entries · daily · Subscribers only
VulnWatch Daily: FFmpeg Heap Corruption and MLOps Governance Gaps
High-severity FFmpeg memory corruption threatens multimodal pipelines; MLflow and ComfyUI updates address authorization and workflow integrity.
-
· 2 entries · daily · Subscribers only
Critical pnpm Supply Chain Flaws Risk AI Tooling Integrity
Two high-severity pnpm vulnerabilities enable path traversal and file deletion. AI teams relying on Node.js orchestration layers must patch immediately to prevent supply chain compromise.
-
· 23 entries · daily · Subscribers only
VulnWatch Daily: Critical MCP Agent Flaws and Supply Chain Compromises
23 new vulnerabilities reported today including CVSS 10.0 MCP server flaws, compromised litellm wheels, and critical Incus RCEs. Immediate patching recommended for agent frameworks and container infrastructure.
-
· 21 entries · daily · Subscribers only
VulnWatch Daily: Critical Agentic RCE in ToolJet, Flowise, and Cursor
Today's digest highlights critical RCE vulnerabilities in AI agent platforms including ToolJet and Flowise, alongside supply chain risks in model loading and authentication bypasses in LibreChat.
-
· 20 entries · daily · Subscribers only
VulnWatch Daily: Agentic Terminal Flood & Critical CLI RCEs
20 new vulnerabilities disclosed today, including a critical Gemini CLI RCE and 10 high-severity flaws in Warp. Immediate patching recommended for AI development environments.
-
· 29 entries · daily · Subscribers only
VulnWatch Daily: Critical vLLM & Langflow Compromises Dominate June 22 Digest
29 new vulnerabilities reported today, including critical RCE in Langflow and multiple auth bypasses in vLLM. Immediate patching recommended for inference stacks.
-
· 120 entries · weekly
VulnWatch Weekly: PraisonAI Auth Collapse & MCP Server Exposure
This week saw a cascade of critical vulnerabilities in PraisonAI agents and widespread authentication failures in Model Context Protocol servers. Oracle Coherence and Langflow also shipped critical RCEs requiring immediate patching.
-
· 10 entries · daily · Subscribers only
VulnWatch Daily: Ten Critical Flaws Hit BerriAI litellm Proxy
A coordinated disclosure reveals ten vulnerabilities in litellm, ranging from auth bypass to SSRF. Immediate patching is required for AI gateway deployments.