Articles
Daily digests summarizing the vulnerabilities and incidents tracked by VulnWatch.
-
· 15 entries · daily · Subscribers only
VulnWatch Daily: Agent Autonomy Risks and LiteLLM Gateway Flaws Dominate July 8 Digest
Today's digest highlights critical vulnerabilities in autonomous coding agents and the LiteLLM proxy stack. Security teams must prioritize patching agent SDKs and enforcing strict authentication on AI gateways to prevent RCE and data exfiltration.
-
· 60 entries · daily · Subscribers only
VulnWatch Daily: Critical Auth Bypasses in Langflow & Cognee; vLLM RCE Surge
Today's digest highlights critical authentication failures in Langflow and Cognee, alongside a significant cluster of RCE and DoS vulnerabilities in vLLM and MLflow affecting model serving and pipeline integrity.
-
· 33 entries · daily · Subscribers only
VulnWatch Daily: Critical Agent Escapes and Platform Instability Surge
33 new vulnerabilities reported today, including critical RCE in Langroid and Crawl4AI, plus extensive authentication flaws in Coder. Immediate patching recommended for AI inference and agent frameworks.
-
· 79 entries · weekly
VulnWatch Weekly: Langflow Cascade & MCP Ecosystem Risks
Langflow faces a critical week with 10+ CVEs including RCE and secret leakage. MCP servers show systemic auth flaws. Action required on model loading.
-
· 2 entries · daily · Subscribers only
VulnWatch Daily: Auth Bypass in WeChat Agents & LangGraph Cache Risks
Today's digest covers a medium-severity authentication bypass in chatgpt-on-wechat and a low-severity weak hash vulnerability in LangGraph. Immediate patching is recommended for WeChat integrations.
-
· 4 entries · daily · Subscribers only
VulnWatch Daily: Critical Pickle Scanning Flaws and ONNX Runtime Risks
Today's digest highlights critical bypasses in model safety scanning and pickle detection, alongside runtime stability issues in ONNX and agentic memory handlers. Immediate patching is advised for serialization tools.
-
· 2 entries · daily · Subscribers only
VulnWatch Daily: Keras RCE and Kong MCP Injection Risks
Today's digest covers critical RCE in Keras deserialization and indirect prompt injection in Kong MCP servers. Immediate patching recommended for ML pipelines and agentic gateways.
-
· 10 entries · daily · Subscribers only
VulnWatch Daily: Critical MCP Auth Flaws and Azure OpenAI SSRF Lead July 2nd Digest
Today's digest highlights critical authentication bypasses in MCP servers and agent frameworks, alongside a severe SSRF in Azure OpenAI. Security teams should prioritize patching MLflow, Weaviate, and reviewing agent tool permissions immediately.
-
· 10 entries · daily · Subscribers only
VulnWatch Daily: MCP Servers Face Injection Risks; Triton DoS Patched
Today's digest highlights critical injection flaws in Model Context Protocol servers, alongside denial-of-service vectors in NVIDIA Triton and supply-chain risks in AI development tools.
-
· 18 entries · daily · Subscribers only
VulnWatch Daily: Langflow Critical Cluster and AI Supply Chain Risks
Critical Langflow vulnerabilities dominate today's digest alongside RCE risks in LLaMA-Factory and MCP auth bypasses. Immediate patching recommended for AI orchestration layers.
-
· 33 entries · daily · Subscribers only
VulnWatch Daily: Claude Code Sandbox Escapes and Serving RCE
Today's digest highlights critical sandbox escapes in Claude Code and a wave of RCE vulnerabilities in model serving frameworks like vLLM and MLflow. LiteLLM and LangChain also show significant auth and injection flaws requiring immediate patching.
-
· 120 entries · weekly
VulnWatch Weekly: Agentic RCE & Supply Chain Risks Surge
Critical vulnerabilities in Langflow, vLLM, and MCP servers highlight severe risks in AI tooling. Immediate patching required for agentic platforms and inference engines to prevent RCE and supply chain compromise.
-
· 3 entries · daily · Subscribers only
VulnWatch Daily: FFmpeg Heap Corruption and MLOps Governance Gaps
High-severity FFmpeg memory corruption threatens multimodal pipelines; MLflow and ComfyUI updates address authorization and workflow integrity.
-
· 2 entries · daily · Subscribers only
Critical pnpm Supply Chain Flaws Risk AI Tooling Integrity
Two high-severity pnpm vulnerabilities enable path traversal and file deletion. AI teams relying on Node.js orchestration layers must patch immediately to prevent supply chain compromise.
-
· 23 entries · daily · Subscribers only
VulnWatch Daily: Critical MCP Agent Flaws and Supply Chain Compromises
23 new vulnerabilities reported today including CVSS 10.0 MCP server flaws, compromised litellm wheels, and critical Incus RCEs. Immediate patching recommended for agent frameworks and container infrastructure.