VulnWatch VulnWatch
← Back to dashboard
#

Data Leakage

92 entries

Every Data Leakage entry VulnWatch has indexed, sorted by publication date.

Subscribe to this tag's RSS feed

Unknown rss_bleepingcomputer

Spain's data agency gets first report of AI-powered data breach

The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). [...]

Data Leakage Agentic / MCP large language model ai agent llm
6 days ago
Unknown rss_securityweek

First Agentic AI Data Breach Reported to Spanish Regulator

Spanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for autonomous cyberattacks. The post First Agenti...

6 days ago
High nvd

CVE-2026-81941: IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating

IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process...

8.8
CVSS
1 week ago
Low osv

vLLM: Cross-User Data Leak Vulnerability

### Summary An integer overflow in the act_and_mul_kernel kernel can cause the output of one user request to be incorporated into the response of another request within the same inference batch. Under...

3.1
CVSS
1 week ago
Low osv

vLLM: Cross-User Data Leak Vulnerability

### Summary An integer overflow in the act_and_mul_kernel kernel can cause the output of one user request to be incorporated into the response of another request within the same inference batch. Under...

3.1
CVSS
1 week ago
High nvd

CVE-2026-47625: NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization. A

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization. A successful exploit of this vulnerability might lead to information disclosure,...

7.5
CVSS
2 weeks ago
Low github

CKAN MCP Server: Information disclosure via verbose error reflection

## Summary Error paths reflect raw upstream response bodies and internal exception messages back to the caller instead of a sanitized, generic message. When the server is pointed at (or redirected/SS...

3.7
CVSS
2 weeks ago
Medium nvd

CVE-2026-78598: Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiti

Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authent...

5.4
CVSS
2 weeks ago
Medium nvd

CVE-2026-72654: Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosur

Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An operation available to users holding only...

Data Leakage machine learning
6.5
CVSS
2 weeks ago
High github

@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key

# Cross-Session Data Exposure via Caller-Controlled `session_id` Project / Repository: `arikusi/deepseek-mcp-server` Affected version / commit tested: `1.6.0` / `04f28be2c6e99d3d4e443a6ae37cc35f0a7...

8.6
CVSS
3 weeks ago
High github

LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure

# Executive Summary A NoSQL injection issue exists in the langgraph-checkpoint-mongodb and langgraph-store-mongodb libraries. MongoDBSaver.list() and MongoDBStore.search() methods accept a filter par...

Data Leakage langchain
7.7
CVSS
1 month ago
Medium nvd

CVE-2026-47606: NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path travers

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution and information disclosure...

6.5
CVSS
1 month ago
High nvd

CVE-2026-72675: Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modificat

Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its Ela...

Data Leakage machine learning
7.1
CVSS
1 month ago
Unknown rss_thehackernews

ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories

Some weeks have one big security story. Others bring many smaller updates that are easy to miss but still matter. This week has plenty of them, covering cloud services, AI tools, malware, data breache...

1 month ago
Low github

Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams

### Summary Ruby's JSON native C extension clears the consumed `JSON::ResumableParser` input buffer but leaves `state.start`, `state.cursor`, and `state.end` pointing into released storage. When `pa...

0.0
CVSS
1 month ago
High nvd

CVE-2026-9130: IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows a

IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users via session_id collisio...

7.1
CVSS
1 month ago
Medium nvd

CVE-2026-47487: NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repos

NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to, or modified by providing a path in the model name...

Data Leakage triton mlflow
4.4
CVSS
1 month ago
High github

Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history

### Summary The **GET `/api/v1/upsert-history`** endpoint returns the **entire server-wide upsert history** (response size **>100MB**) instead of being scoped to the requesting user/tenant/workspace....

0.0
CVSS
1 month ago
Low github

MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure

### Summary `MessagePack::Buffer#clear` shifts out every chunk and returns its 4 KiB rmem page to the shared pool, but does not reset the buffer's rmem cursor (`rmem_last`, `rmem_end`, `rmem_owner`)....

0.0
CVSS
1 month ago
High nvd

CVE-2026-13442: IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only

IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence later query results. This causes cross-user inform...

Data Leakage langflow faiss
7.1
CVSS
1 month ago
High nvd

CVE-2026-66759: A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the pl

A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the...

7.1
CVSS
1 month ago
High github

PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments

## Summary PostCSS's `PreviousMap` parses the `/*# sourceMappingURL=PATH */` comment from any CSS string passed to `process()` and dereferences `PATH` against the local filesystem with no scheme, all...

7.5
CVSS
1 month ago
Low nvd

CVE-2026-44187: A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with

A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with local access to the workstation, or malware running with the user's privileges,...

3.3
CVSS
2 months ago
Low osv

vLLM: Speech-to-text upload size limit is enforced after full UploadFile read

## Summary Current-head vLLM documents `VLLM_MAX_AUDIO_CLIP_FILESIZE_MB` as the maximum audio file size accepted by the speech-to-text APIs. The default is 25 MB. `vllm/envs.py` also describes files...

3.1
CVSS
2 months ago
Unknown rss_securityweek

In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint

Noteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data breach. The post In Other News: Iran...

2 months ago