VulnWatch VulnWatch

Today's Entries

AI/ML security vulnerabilities, advisories, and breaches from the last 24 hours, sorted by severity.

6
New entries
2
Critical
0
Actively exploited
Critical nvd

CVE-2026-61808: LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds t

LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an un...

llm
9.8
CVSS
9 hours ago
Critical nvd

CVE-2026-48039: Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `A

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` uncondition...

Agentic / MCP model context protocol
9.1
CVSS
9 hours ago
High nvd

CVE-2026-71847: Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consume

Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consumed JSON::ResumableParser input buffer but leaves state.start, state.cursor, and s...

cursor
8.7
CVSS
10 hours ago
5.3
CVSS
22 hours ago
Low github

Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams

### Summary Ruby's JSON native C extension clears the consumed `JSON::ResumableParser` input buffer but leaves `state.start`, `state.cursor`, and `state.end` pointing into released storage. When `pa...

0.0
CVSS
10 hours ago
Unknown rss_thehackernews

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough...

claude code anthropic openai claude gemini
21 hours ago

Get the weekly digest

Top AI security stories every Monday. Free, no spam. Want it daily? See Daily Briefing.