Articles
Daily digests summarizing the vulnerabilities and incidents tracked by VulnWatch.
-
· 6 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in MindsDB and MCP Supply Chain Risks
Today's digest highlights a CVSS 10.0 unauthenticated RCE in MindsDB, command injection in Token Optimizer MCP, and a cluster of cache poisoning and SSRF issues in CKAN MCP Server affecting AI agent integrity.
-
· 28 entries · daily · Subscribers only
VulnWatch Daily: Critical Agentic RCE and Supply Chain Flaws in Trigger.dev, vLLM, and Flowise
Today's digest highlights critical remote code execution risks in agentic frameworks like Trigger.dev and AgenticSeek, alongside severe prompt injection bypasses in Flowise and SSRF vulnerabilities in MCP servers. Immediate patching is required for multi-tenant isolation failures.
-
· 6 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in Prompty Templates and MCP Supply Chain Risks
Today's digest highlights a critical template injection flaw in Prompty allowing host RCE, alongside severe command injection and path traversal vulnerabilities in emerging Model Context Protocol (MCP) servers affecting Stata and Atlassian integrations.
-
· 20 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in AI Agents and Supply Chain Leaks
Today's digest highlights a critical RCE in PapersGPT via prompt injection, unauthenticated CLI servers in Claude Code, and widespread credential exfiltration risks in AI workflow platforms.
-
· 6 entries · daily · Subscribers only
VulnWatch Daily: Critical File Reads in Firecrawl & Agent RCE in Goose
Today's digest covers critical vulnerabilities in AI data pipelines and agentic frameworks, including arbitrary file reads in Firecrawl, unauthorized file access in Flowise, and pre-prompt RCE in the Goose agent.
-
· 116 entries · weekly
VulnWatch Weekly: The Flowise Apocalypse & Active Langflow Exploitation
This week marks a critical turning point for AI platform security with a massive cluster of RCE vulnerabilities in Flowise and active exploitation of IBM Langflow. Immediate patching is required for model serving stacks and agentic frameworks.
-
· 19 entries · daily · Subscribers only
Critical RCE Wave Hits llama.cpp and MCP Frameworks
A surge of critical vulnerabilities targets core AI infrastructure, including sandbox escapes in Model Context Protocol and multiple memory corruption flaws in llama.cpp enabling remote code execution.
-
· 33 entries · daily · Subscribers only
Langflow Catastrophe: 20+ RCEs, Supply Chain Risks, and Agentic Flaws
A historic wave of vulnerabilities hits IBM Langflow with 20+ CVEs including unauthenticated RCE. Critical issues also found in PraisonAI CI/CD, Hugging Face PEFT deserialization, and Milvus DoS.
-
· 43 entries · daily · Subscribers only
Critical Flowise RCE Wave and Langflow Injection Compromise AI Supply Chain
A massive cluster of vulnerabilities in Flowise and a critical CISA-listed flaw in Langflow expose AI platforms to unauthenticated RCE, credential theft, and supply-chain compromise. Immediate patching and network isolation are required.
-
· 7 entries · daily · Subscribers only
VulnWatch Daily: Critical TLS Flaws and Agentic RCE Risks Surge
Today's digest highlights a critical TLS verification bypass in Emlog Pro, incomplete denylists in Ouroboros enabling RCE, and prompt injection vectors in Amazon Strands and MQ MCP Server.
-
· 58 entries · weekly
VulnWatch Weekly: The Agentic Apocalypse & Supply Chain Meltdown
This week marks a turning point for AI security with critical RCEs in Langflow, Flyto2, and sentence-transformers. The dominant theme is the collapse of trust boundaries in agentic workflows, demanding immediate patching of model serving and orchestration layers.
-
· 9 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in Transformers & Agentic Supply Chain Risks
Today's digest highlights a critical trust bypass in sentence-transformers enabling RCE, a parser mismatch in pgAdmin allowing SQL injection via LLM, and multiple MCP server vulnerabilities exposing local files and workflow templates.
-
· 20 entries · daily · Subscribers only
Critical Agentic Vulnerabilities: Flyto2, Langflow, and MCP SDK Exploits
A surge of critical vulnerabilities in AI agent frameworks allows arbitrary code execution, secret exfiltration, and cross-tenant data leakage. Immediate patching is required for Flyto2 Core, IBM Langflow, and MCP SDKs.
-
· 14 entries · daily · Subscribers only
VulnWatch Daily: Critical SSRF in Flyto2, MCP SDK Flaws, and Agent Auth Bypasses
Today's digest covers critical SSRF vulnerabilities in Flyto2 Core exposing API keys, a cluster of DoS and session hijacking flaws in the MCP Ruby SDK, and auth bypasses in Quarkus and Pydantic AI affecting generative workflows.
-
· 9 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in pglogical, ESP32 Overflow, and MCP DoS
Today's digest covers critical privilege escalation in PostgreSQL pglogical, a heap overflow in ESP32 audio libraries, and multiple availability issues in Model Context Protocol servers affecting AI agent deployments.