Articles
Daily digests summarizing the vulnerabilities and incidents tracked by VulnWatch.
-
· 11 entries · daily · Subscribers only
VulnWatch Daily: Critical Supply Chain Compromise and Agentic Logic Flaws
Today's digest highlights a critical npm supply chain attack targeting NestJS auth modules, severe logic flaws in AgenticMail enabling session hijacking, and new DoS vectors in Markdown parsers and vLLM.
-
· 120 entries · weekly
VulnWatch Weekly: The Langflow Catastrophe & MCP Supply Chain Risks
This week is dominated by a critical cluster of RCE and auth-bypass flaws in IBM Langflow, alongside severe multi-tenant isolation failures in the emerging Model Context Protocol (MCP) ecosystem. Immediate patching is required for Langflow instances and MCP servers handling sensitive workflows.
-
· 15 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in SGLang, Kiota Path Traversal, and MCP Supply Chain Risks
Today's digest highlights critical RCE in SGLang's ZeroMQ interface, path traversal in Microsoft Kiota plugins, and multiple supply chain vulnerabilities affecting Model Context Protocol (MCP) servers and agents.
-
· 38 entries · daily · Subscribers only
VulnWatch Daily: Critical MCP Flaws, NVIDIA Stack RCE, and Copilot Injections
Today's digest highlights critical vulnerabilities in the Model Context Protocol ecosystem, including cross-tenant data leaks and SSRF. We also cover a wave of RCE flaws in NVIDIA's inference stack and command injection risks in major Copilot products.
-
· 40 entries · daily · Subscribers only
VulnWatch Daily: Critical SQLi in AI Copilots and Agentic RCE Waves
Today's digest highlights a critical SQL injection in AIWU's copilot, widespread SSRF and RCE vulnerabilities in agentic frameworks like CrewAI and LiteLLM, and severe data leakage risks in vLLM and MLflow serving stacks.
-
· 15 entries · daily · Subscribers only
VulnWatch Daily: Agent Autonomy Risks and LiteLLM Gateway Flaws Dominate July 8 Digest
Today's digest highlights critical vulnerabilities in autonomous coding agents and the LiteLLM proxy stack. Security teams must prioritize patching agent SDKs and enforcing strict authentication on AI gateways to prevent RCE and data exfiltration.
-
· 60 entries · daily · Subscribers only
VulnWatch Daily: Critical Auth Bypasses in Langflow & Cognee; vLLM RCE Surge
Today's digest highlights critical authentication failures in Langflow and Cognee, alongside a significant cluster of RCE and DoS vulnerabilities in vLLM and MLflow affecting model serving and pipeline integrity.
-
· 33 entries · daily · Subscribers only
VulnWatch Daily: Critical Agent Escapes and Platform Instability Surge
33 new vulnerabilities reported today, including critical RCE in Langroid and Crawl4AI, plus extensive authentication flaws in Coder. Immediate patching recommended for AI inference and agent frameworks.
-
· 79 entries · weekly
VulnWatch Weekly: Langflow Cascade & MCP Ecosystem Risks
Langflow faces a critical week with 10+ CVEs including RCE and secret leakage. MCP servers show systemic auth flaws. Action required on model loading.
-
· 2 entries · daily · Subscribers only
VulnWatch Daily: Keras RCE and Kong MCP Injection Risks
Today's digest covers critical RCE in Keras deserialization and indirect prompt injection in Kong MCP servers. Immediate patching recommended for ML pipelines and agentic gateways.
-
· 10 entries · daily · Subscribers only
VulnWatch Daily: Critical MCP Auth Flaws and Azure OpenAI SSRF Lead July 2nd Digest
Today's digest highlights critical authentication bypasses in MCP servers and agent frameworks, alongside a severe SSRF in Azure OpenAI. Security teams should prioritize patching MLflow, Weaviate, and reviewing agent tool permissions immediately.
-
· 18 entries · daily · Subscribers only
VulnWatch Daily: Langflow Critical Cluster and AI Supply Chain Risks
Critical Langflow vulnerabilities dominate today's digest alongside RCE risks in LLaMA-Factory and MCP auth bypasses. Immediate patching recommended for AI orchestration layers.
-
· 33 entries · daily · Subscribers only
VulnWatch Daily: Claude Code Sandbox Escapes and Serving RCE
Today's digest highlights critical sandbox escapes in Claude Code and a wave of RCE vulnerabilities in model serving frameworks like vLLM and MLflow. LiteLLM and LangChain also show significant auth and injection flaws requiring immediate patching.
-
· 120 entries · weekly
VulnWatch Weekly: Agentic RCE & Supply Chain Risks Surge
Critical vulnerabilities in Langflow, vLLM, and MCP servers highlight severe risks in AI tooling. Immediate patching required for agentic platforms and inference engines to prevent RCE and supply chain compromise.
-
· 29 entries · daily · Subscribers only
VulnWatch Daily: Critical vLLM & Langflow Compromises Dominate June 22 Digest
29 new vulnerabilities reported today, including critical RCE in Langflow and multiple auth bypasses in vLLM. Immediate patching recommended for inference stacks.