Articles
Daily digests summarizing the vulnerabilities and incidents tracked by VulnWatch.
-
· 13 entries · daily · Subscribers only
VulnWatch Daily: ChromaDB RCE, Agent MCP Leaks, and Pipeline Traversal
Critical ChromaDB flaws enable cross-tenant RCE. New agent framework vulnerabilities expose MCP servers. ML pipelines face path traversal risks. Immediate patching recommended for vector stores.
-
· 9 entries · daily · Subscribers only
VulnWatch Daily: Critical MCP Flaws & ML Framework Risks (2026-06-11)
Nine new vulnerabilities reported today, including critical authentication bypasses in Model Context Protocol servers and resource exhaustion risks in vLLM. Immediate patching recommended for MCP integrations and Keras pipelines.
-
· 6 entries · daily · Subscribers only
VulnWatch Daily: Auth Bypasses in AI Memory and Identity Layers
Critical flaws in Mem0 and Dex expose AI platforms to configuration hijacking and identity spoofing. Plus updates on Copilot, MongoDB, and hardware risks.
-
· 17 entries · daily · Subscribers only
Critical Flowise RCE and Active LiteLLM Exploitation Dominate June 8 VulnWatch
Flowise patches critical RCE and mass assignment flaws in v3.1.2. LiteLLM command injection is actively exploited. Immediate patching required for LLMOps platforms.
-
· 35 entries · weekly
VulnWatch Weekly: Agentic RCE Surge & Model Loading Risks
Critical vulnerabilities in Langroid, OpenMed, and MCP servers highlight escalating risks in AI agent tooling and model loading paths. Immediate patching required for agent frameworks and orchestration platforms.
-
· 5 entries · daily · Subscribers only
VulnWatch Daily: Agentic IDORs and MCP Injection Risks Surge
Today's digest highlights critical IDOR flaws in AI orchestration, Kubernetes flag injection via MCP, and browser isolation issues in OpenAI Atlas.
-
· 8 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in Langroid & MCP Auth Bypasses
Today's digest highlights critical RCE risks in AI agent frameworks via prompt injection and SQL execution, alongside significant authentication bypasses in MCP servers and workspace platforms.
-
· 78 entries · weekly
VulnWatch Weekly: Agentic RCE Epidemic & MCP Trust Boundaries Collapse
78 vulnerabilities tracked this week. PraisonAI, SillyTavern, and MCP servers dominate critical RCE reports. Immediate patching required for agent frameworks.
-
· 10 entries · daily · Subscribers only
VulnWatch Daily: Critical Agent Escapes and Model Serving RCE
Today's digest highlights critical vulnerabilities in CodeWhale agents, vllm model serving, and AnythingLLM. Immediate patching is recommended for agentic workflows.
-
· 19 entries · daily · Subscribers only
VulnWatch Daily: Critical Agent Control Bypasses and Twig RCE Cluster
19 new vulnerabilities reported today including active Langflow exploitation, critical MCP auth bypasses, and a massive cluster of Twig RCEs affecting AI rendering pipelines.
-
· 16 entries · daily · Subscribers only
VulnWatch: NVIDIA Inference Stack Critical Flaws & AI Supply Chain Risks
Critical authentication bypasses in NVIDIA Triton and deserialization risks in TRT-LLM dominate today's digest. Plus, new supply chain threats in Diffusers and agent tooling.
-
· 17 entries · daily · Subscribers only
VulnWatch Daily: MCP RCE, Supply Chain Worms, and MLflow Risks
Critical MCP RCEs and a renewed npm worm campaign dominate today's digest. MLflow and AutoGPT users must patch immediately to prevent agent compromise.
-
· 17 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in SGLangs and ChromaDB; Mistral Supply Chain
Today's digest highlights critical RCE vulnerabilities in SGLangs and ChromaDB, alongside a confirmed malicious dropper in the Mistral AI PyPI package. Immediate patching and supply chain verification are required.
-
· 102 entries · weekly
VulnWatch Weekly: MCP Security Crisis & Model Loading RCE Surge
This week exposes critical risks in Model Context Protocol implementations, unsafe model deserialization in PyTorch/Diffusers, and agentic RCE chains. Immediate patching required for SOCFortress, ART, and Open WebUI.
-
· 11 entries · daily · Subscribers only
VulnWatch Daily: Open WebUI Auth Bypasses and APM Supply Chain Risks
Today's digest highlights critical access control failures in Open WebUI and supply chain vulnerabilities in Microsoft APM. MLflow and AVideo also report high-severity issues.