Articles
Daily digests summarizing the vulnerabilities and incidents tracked by VulnWatch.
-
· 2 entries · daily · Subscribers only
Critical Update Flaws in Ollama for Windows Enable Silent RCE
Two high-severity vulnerabilities in Ollama's Windows update mechanism allow attackers to bypass signature checks and write arbitrary files, enabling silent remote code execution on developer workstations.
-
· 3 entries · daily · Subscribers only
MCP Bridge Vulnerabilities Surge: Path Traversal and Command Injection Risks in AI Agent Tooling
Today's digest highlights critical risks in Model Context Protocol (MCP) implementations. Three new CVEs expose path traversal and command injection vulnerabilities in Claude agent bridges and SDKs, urging immediate review of agent tooling configurations.
-
· 5 entries · daily · Subscribers only
VulnWatch Daily: SSRF Waves Hit AI Gateways and MCP Servers
Critical SSRF flaws plague NextChat and MCP studios while aider faces command injection risks. vllm stability also compromised.
-
· 3 entries · daily · Subscribers only
VulnWatch Daily: MCP RCE, Ollama Path Traversal, and LLM Data Leaks
Today's digest covers critical supply-chain risks in MCP servers, path traversal in Ollama model transfers, and information disclosure in SmythOS connectors. Immediate patching and configuration reviews are advised.
-
· 12 entries · daily · Subscribers only
VulnWatch Daily: Critical RCEs in Gemini CLI, Ray, and LiteLLM Proxy
Critical RCEs impact Gemini CLI and Ray pipelines. LiteLLM faces SQLi and SSTI. LangChain SSRF and Stripe webhook bypasses also featured. Immediate patching recommended for CI/CD and serving layers.
-
· 24 entries · daily · Subscribers only
VulnWatch Daily: Flowise Critical Swarm and Agentic RCE Risks
April 23, 2026: Critical RCE in Paperclip, 18+ CVEs in Flowise, and agentic consent bypasses demand immediate patching and network isolation.
-
· 51 entries · weekly
Flowise Floods Critical RCEs; Agentic Frameworks Under Siege
This week saw an unprecedented cascade of critical vulnerabilities in Flowise, alongside severe agentic bypasses in Paperclip and Gemini CLI. Immediate patching is required for LLM orchestration layers.