Articles
Daily digests summarizing the vulnerabilities and incidents tracked by VulnWatch.
-
· 101 entries · weekly
VulnWatch Weekly: The Agentic Explosion & The LiteLLM Emergency
This week marks a turning point for AI security as agentic frameworks become the primary attack surface. With a known-exploited vulnerability in LiteLLM and critical RCEs in MCP hubs, immediate patching is required.
-
· 13 entries · daily · Subscribers only
VulnWatch Daily: Critical Agentic RCE and LiteLLM Auth Bypasses
Today's digest highlights critical vulnerabilities in agentic frameworks allowing shared bundle overwrites and RCE, alongside active exploitation of LiteLLM authentication flaws and supply-chain risks in model training data handlers.
-
· 7 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in Elasticsearch ML and Supply Chain Risks
Today's digest highlights a critical deserialization flaw in Elasticsearch ML enabling RCE, a recursion DoS in llama.cpp, and supply chain vulnerabilities in Scrapy and pnpm affecting AI data pipelines.
-
· 116 entries · weekly
VulnWatch Weekly: The Flowise Apocalypse & Active Langflow Exploitation
This week marks a critical turning point for AI platform security with a massive cluster of RCE vulnerabilities in Flowise and active exploitation of IBM Langflow. Immediate patching is required for model serving stacks and agentic frameworks.
-
· 33 entries · daily · Subscribers only
Langflow Catastrophe: 20+ RCEs, Supply Chain Risks, and Agentic Flaws
A historic wave of vulnerabilities hits IBM Langflow with 20+ CVEs including unauthenticated RCE. Critical issues also found in PraisonAI CI/CD, Hugging Face PEFT deserialization, and Milvus DoS.
-
· 60 entries · daily · Subscribers only
VulnWatch Daily: Critical Auth Bypasses in Langflow & Cognee; vLLM RCE Surge
Today's digest highlights critical authentication failures in Langflow and Cognee, alongside a significant cluster of RCE and DoS vulnerabilities in vLLM and MLflow affecting model serving and pipeline integrity.
-
· 52 entries · weekly
MCP Meltdown & Flowise Flood: Critical AI Infra Vulnerabilities Surge
Critical MCP auth bypasses and Flowise RCEs dominate this week. LiteLLM command injection is actively exploited. ChromaDB and vLLM also ship high-severity patches. Immediate action required on agent frameworks.
-
· 13 entries · daily · Subscribers only
VulnWatch Daily: ChromaDB RCE, Agent MCP Leaks, and Pipeline Traversal
Critical ChromaDB flaws enable cross-tenant RCE. New agent framework vulnerabilities expose MCP servers. ML pipelines face path traversal risks. Immediate patching recommended for vector stores.