Articles
Daily digests summarizing the vulnerabilities and incidents tracked by VulnWatch.
-
· 21 entries · daily · Subscribers only
VulnWatch Daily: Critical Agentic RCE in ToolJet, Flowise, and Cursor
Today's digest highlights critical RCE vulnerabilities in AI agent platforms including ToolJet and Flowise, alongside supply chain risks in model loading and authentication bypasses in LibreChat.
-
· 20 entries · daily · Subscribers only
VulnWatch Daily: Agentic Terminal Flood & Critical CLI RCEs
20 new vulnerabilities disclosed today, including a critical Gemini CLI RCE and 10 high-severity flaws in Warp. Immediate patching recommended for AI development environments.
-
· 29 entries · daily · Subscribers only
VulnWatch Daily: Critical vLLM & Langflow Compromises Dominate June 22 Digest
29 new vulnerabilities reported today, including critical RCE in Langflow and multiple auth bypasses in vLLM. Immediate patching recommended for inference stacks.
-
· 120 entries · weekly
VulnWatch Weekly: PraisonAI Auth Collapse & MCP Server Exposure
This week saw a cascade of critical vulnerabilities in PraisonAI agents and widespread authentication failures in Model Context Protocol servers. Oracle Coherence and Langflow also shipped critical RCEs requiring immediate patching.
-
· 4 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in Flowise, vLLM Inference Risks
Today's digest covers a critical RCE in Flowise orchestration, multiple vLLM inference vulnerabilities, and a Cap-go pagination logic flaw. Immediate patching recommended for exposed services.
-
· 28 entries · daily · Subscribers only
VulnWatch Daily: MCP Server Risks Surge & Langflow Critical Flaws
28 new vulnerabilities reported today, highlighting critical risks in Model Context Protocol servers, Langflow platform integrity, and supply chain attacks via model loading.
-
· 43 entries · daily · Subscribers only
VulnWatch Daily: PraisonAI Critical RCE Cluster & MCP Auth Failures
Over 40 AI vulnerabilities disclosed today, led by critical RCE chains in PraisonAI and unauthenticated MCP servers. Immediate patching recommended for agentic frameworks.
-
· 29 entries · daily · Subscribers only
VulnWatch Daily: Critical Oracle Coherence RCE and Agent Control Plane Exposures
29 new vulnerabilities reported today including CVSS 10.0 Oracle Coherence flaws, widespread MCP agent misconfigurations, and inference engine robustness issues in vLLM and Open WebUI.
-
· 25 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in Langflow & Crawl4AI Docker APIs
25 new vulnerabilities reported today. Critical RCE risks in Langflow and Crawl4AI demand immediate patching. Model serving engines and web frameworks also affected.
-
· 4 entries · daily · Subscribers only
VulnWatch Daily: AI IDE Risks, Supply Chain Flaws, and Parser Overflows
Today's digest covers high-severity risks in AI-assisted IDEs, multimedia parsers, and critical web sanitization libraries used in AI dashboards.
-
· 52 entries · weekly
MCP Meltdown & Flowise Flood: Critical AI Infra Vulnerabilities Surge
Critical MCP auth bypasses and Flowise RCEs dominate this week. LiteLLM command injection is actively exploited. ChromaDB and vLLM also ship high-severity patches. Immediate action required on agent frameworks.
-
· 13 entries · daily · Subscribers only
VulnWatch Daily: ChromaDB RCE, Agent MCP Leaks, and Pipeline Traversal
Critical ChromaDB flaws enable cross-tenant RCE. New agent framework vulnerabilities expose MCP servers. ML pipelines face path traversal risks. Immediate patching recommended for vector stores.
-
· 6 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in LMDeploy and MCP Risks in CI/CD
Today's digest highlights critical RCE risks in LMDeploy due to hardcoded trust settings, alongside emerging threats in AI agent CI/CD pipelines and supply chain integrity issues in vLLM.
-
· 6 entries · daily · Subscribers only
VulnWatch Daily: Auth Bypasses in AI Memory and Identity Layers
Critical flaws in Mem0 and Dex expose AI platforms to configuration hijacking and identity spoofing. Plus updates on Copilot, MongoDB, and hardware risks.
-
· 17 entries · daily · Subscribers only
Critical Flowise RCE and Active LiteLLM Exploitation Dominate June 8 VulnWatch
Flowise patches critical RCE and mass assignment flaws in v3.1.2. LiteLLM command injection is actively exploited. Immediate patching required for LLMOps platforms.