Archive // 2026-07

July 2026

Everything the feeds carried with a date in July 2026: still live, or dropped out of the rolling window since. Changes to a CVE's severity, score or exploited status are listed under it.

CVE 31 Jul 2026
CVE-2026-68771 ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python…
Critical 9.8first seen 04 Oct 2026live
CVE 31 Jul 2026
CVE-2026-56673 ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_paths.get_annotated_filepath and…
High 7.5first seen 04 Oct 2026live
CVE 31 Jul 2026
CVE-2026-56672 ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived…
High 8.2first seen 04 Oct 2026live
CVE 31 Jul 2026
CVE-2026-56671 ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_preview in app/model_manager.py joins an unrestricted…
High 7.5first seen 04 Oct 2026live
CVE 31 Jul 2026
CVE-2026-56670 ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint served uploaded SVG files inline because…
High 8.2first seen 04 Oct 2026live
CVE 31 Jul 2026
CVE-2026-54785 gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 until 1.3.1, consult_gemini_with_files in inline mode…
Medium 6.2first seen 04 Oct 2026live
CVE 31 Jul 2026
CVE-2026-18394 Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via…
High 7.4first seen 04 Oct 2026live
CVE 31 Jul 2026
CVE-2026-17351 The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one…
Critical 9.0first seen 04 Oct 2026live
CVE 30 Jul 2026
CVE-2026-62663 Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filters (image, audio, video, document) in banks…
High 7.5first seen 04 Oct 2026live
CVE 30 Jul 2026
CVE-2026-61536 Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered body of {%…
High 7.5first seen 04 Oct 2026live
CVE 30 Jul 2026
CVE-2026-13444 IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creating their own flow with matching Chroma…
High 8.1first seen 04 Oct 2026live
CVE 30 Jul 2026
CVE-2026-13435 IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.
Critical 9.9first seen 04 Oct 2026live
CVE 30 Jul 2026
CVE-2026-12946 IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.
Critical 9.9first seen 04 Oct 2026live
CVE 30 Jul 2026
CVE-2026-12945 IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on log retrieval and…
High 7.1first seen 04 Oct 2026live
CVE 30 Jul 2026
CVE-2026-12942 IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request…
High 7.5first seen 04 Oct 2026live
CVE 30 Jul 2026
CVE-2026-12940 IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol)…
Critical 9.8first seen 04 Oct 2026live
CVE 30 Jul 2026
CVE-2026-10700 IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API that allow unauthorized access to user files.The…
Medium 6.5first seen 04 Oct 2026live
CVE 29 Jul 2026
CVE-2026-67432 MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem…
High 7.5first seen 04 Oct 2026live
CVE 29 Jul 2026
CVE-2026-67431 MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem…
Unscoredfirst seen 04 Oct 2026live
CVE 29 Jul 2026
CVE-2026-67430 MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem…
Medium 5.3first seen 04 Oct 2026live
CVE 29 Jul 2026
CVE-2026-67428 Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules including…
High 8.5first seen 04 Oct 2026live
CVE 29 Jul 2026
CVE-2026-67425 Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as OPENAI_API_KEY and ANTHROPIC_API_KEY from…
High 8.6first seen 04 Oct 2026live
CVE 29 Jul 2026
CVE-2026-65975 Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.88.0 up to but not including 1.107.1 and 2.0.0b1 up to…
Medium 6.5first seen 04 Oct 2026live
CVE 29 Jul 2026
CVE-2026-63119 MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StdioTransport and MCP::Client::Stdio in…
Medium 6.2first seen 04 Oct 2026live
CVE 29 Jul 2026
CVE-2026-63118 MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem…
Unscoredfirst seen 04 Oct 2026live
CVE 29 Jul 2026
CVE-2026-54249 Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and 2.0.0b1 through 2.0.0b5, a client that submits…
Medium 6.8first seen 04 Oct 2026live
CVE 29 Jul 2026
CVE-2026-46678 Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.56.0 through 1.98.0, when an application opts a URL into…
Medium 6.8first seen 04 Oct 2026live
CVE 28 Jul 2026
CVE-2026-13442 IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence later query…
High 7.1first seen 04 Oct 2026live
CVE 27 Jul 2026
CVE-2026-17534 Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal denylist in assertSafeFetchTarget, without…
Medium 5.5first seen 04 Oct 2026live
Model 27 Jul 2026
Alibaba / Qwen · apifirst seen 04 Oct 2026live
Model 25 Jul 2026
Microsoft · open-weightfirst seen 04 Oct 2026live
CVE 24 Jul 2026
CVE-2026-66027 Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources…
High 8.3first seen 04 Oct 2026live
CVE 24 Jul 2026
CVE-2026-66004 BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that allows attackers to write arbitrary files by…
Medium 5.3first seen 04 Oct 2026live
Model 24 Jul 2026
Anthropic · proprietaryfirst seen 04 Oct 2026live
CVE 23 Jul 2026
CVE-2026-65699 AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent…
Medium 4.2first seen 04 Oct 2026live
CVE 23 Jul 2026
CVE-2026-65698 Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjacent attackers to read arbitrary host files outside…
Medium 5.3first seen 04 Oct 2026live
CVE 22 Jul 2026
CVE-2026-65589 n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow…
Medium 6.5first seen 04 Oct 2026live
CVE 22 Jul 2026
CVE-2026-65015 n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A…
High 8.8first seen 04 Oct 2026live
CVE 22 Jul 2026
CVE-2026-44192 A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This vulnerability, known as path traversal, allows an attacker to manipulate an AI agent…
Medium 6.6first seen 04 Oct 2026live
CVE 21 Jul 2026
CVE-2026-65315 Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows remote attackers to crash the server by supplying…
High 7.5first seen 04 Oct 2026live
CVE 21 Jul 2026
CVE-2026-65056 mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local…
High 8.2first seen 04 Oct 2026live
CVE 21 Jul 2026
CVE-2026-47393 PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-generator…
Critical 9.8first seen 04 Oct 2026live
CVE 21 Jul 2026
CVE-2026-47391 PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an unauthenticated A2A JSON-RPC endpoint and…
Critical 9.8first seen 04 Oct 2026live
Model 21 Jul 2026
Google · proprietaryfirst seen 04 Oct 2026live
Model 21 Jul 2026
NVIDIA · open-weightfirst seen 04 Oct 2026live
CVE 20 Jul 2026
CVE-2026-57495 AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39, @agenticmail/codex prior to version 0.1.33…
Unscoredfirst seen 04 Oct 2026live
CVE 20 Jul 2026
CVE-2026-57494 AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-privileged authenticated AgenticMail agent can…
Unscoredfirst seen 04 Oct 2026live
CVE 20 Jul 2026
CVE-2026-47255 AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness…
High 8.2first seen 04 Oct 2026live
CVE 20 Jul 2026
CVE-2026-47128 nono is software that allows users to run AI agents in a zero-latency sandbox. Prior to version 0.55.0, the nono Landlock/seccomp policies allow access to local Unix…
Medium 6.1first seen 04 Oct 2026live
CVE 20 Jul 2026
CVE-2026-46555 WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1, the…
High 7.7first seen 04 Oct 2026live
CVE 17 Jul 2026
CVE-2026-9202 IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true…
Critical 9.8first seen 04 Oct 2026live
CVE 17 Jul 2026
CVE-2026-9198 IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with…
Critical 9.8Exploitedfirst seen 04 Oct 2026live
CVE 17 Jul 2026
CVE-2026-9135 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the…
Critical 9.9first seen 04 Oct 2026live
CVE 17 Jul 2026
CVE-2026-9103 IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint…
Critical 9.8first seen 04 Oct 2026live
CVE 17 Jul 2026
CVE-2026-8859 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the…
Critical 9.9first seen 04 Oct 2026live
CVE 17 Jul 2026
CVE-2026-8635 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system…
Critical 9.9first seen 04 Oct 2026live
CVE 17 Jul 2026
CVE-2026-8505 IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow…
Critical 9.8first seen 04 Oct 2026live
CVE 17 Jul 2026
CVE-2026-8481 IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint…
Critical 9.9first seen 04 Oct 2026live
CVE 17 Jul 2026
CVE-2026-8476 IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's…
Critical 9.9first seen 04 Oct 2026live
CVE 17 Jul 2026
CVE-2026-8056 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API. A critical security flaw exists in the…
High 8.8first seen 04 Oct 2026live
CVE 17 Jul 2026
CVE-2026-7872 IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any user.
High 7.5first seen 04 Oct 2026live
CVE 17 Jul 2026
CVE-2026-7755 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration files.
High 8.8first seen 04 Oct 2026live
CVE 17 Jul 2026
CVE-2026-7754 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure default configuration and incomplete enforcement of…
High 7.7first seen 04 Oct 2026live
CVE 17 Jul 2026
CVE-2026-7667 IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns a specially crafted…
High 8.8first seen 04 Oct 2026live
CVE 17 Jul 2026
CVE-2026-58195 Agentic-Flow is an AI agent orchestration platform. Prior to 2.0.14, agentic-flow MCP server tools in src/mcp/standalone-stdio.ts…
High 8.8first seen 04 Oct 2026live
CVE 17 Jul 2026
CVE-2026-15995 IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an attacker to obtain incorrect report summary results or cause…
Medium 5.4first seen 04 Oct 2026live
CVE 17 Jul 2026
CVE-2026-14499 IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper…
High 8.8first seen 04 Oct 2026live
CVE 17 Jul 2026
CVE-2026-13448 IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint (…
High 8.1first seen 04 Oct 2026live
CVE 17 Jul 2026
CVE-2026-13446 IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication…
Critical 9.8first seen 04 Oct 2026live
CVE 17 Jul 2026
CVE-2026-13445 IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploaded files by…
High 8.1first seen 04 Oct 2026live
Model 17 Jul 2026
Microsoft · open-weightfirst seen 04 Oct 2026live
Model 17 Jul 2026
Microsoft · open-weightfirst seen 04 Oct 2026live
CVE 16 Jul 2026
CVE-2026-53598 Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:...} references in .prompty frontmatter without…
High 7.5first seen 04 Oct 2026live
CVE 16 Jul 2026
CVE-2026-53597 Prompty is a markdown file format (.prompty) for LLM prompts. From 2.0.0-alpha.1 until 2.0.0-beta.3, the @prompty/core TypeScript loader in…
Unscoredfirst seen 04 Oct 2026live
CVE 16 Jul 2026
CVE-2026-46341 The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior to…
Medium 6.1first seen 04 Oct 2026live
CVE 16 Jul 2026
CVE-2026-44970 dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DefaultUsageTracker.emit_tool_called_event() in src/dbt_mcp/tracking/tracking.py…
Low 3.1first seen 04 Oct 2026live
CVE 16 Jul 2026
CVE-2026-44969 dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/mcp/server.py logged the raw arguments dictionary…
Low 2.5first seen 04 Oct 2026live
CVE 16 Jul 2026
CVE-2026-44968 dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, _run_dbt_command() in src/dbt_mcp/dbt_cli/tools.py appended unsanitized…
Medium 6.3first seen 04 Oct 2026live
CVE 16 Jul 2026
CVE-2026-15737 AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore…
Medium 5.7first seen 04 Oct 2026live
CVE 16 Jul 2026
CVE-2026-11371 The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and outputting it, and the feature that generates it…
Medium 6.1first seen 04 Oct 2026live
Model 16 Jul 2026
Mistral AI · open-weightfirst seen 04 Oct 2026live
CVE 15 Jul 2026
CVE-2026-59950 The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated…
High 8.1first seen 04 Oct 2026live
CVE 15 Jul 2026
CVE-2026-52870 The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by…
High 7.6first seen 04 Oct 2026live
CVE 15 Jul 2026
CVE-2026-52869 The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports…
High 7.1first seen 04 Oct 2026live
CVE 15 Jul 2026
CVE-2026-15746 Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including…
Medium 6.5first seen 04 Oct 2026live
CVE 14 Jul 2026
CVE-2026-15643 AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLake FHIR…
High 7.3first seen 04 Oct 2026live
CVE 13 Jul 2026
CVE-2026-15685 Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service…
High 7.5first seen 04 Oct 2026live
CVE 13 Jul 2026
CVE-2026-15574 A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorization headers and full chat payloads, which may…
High 7.5first seen 04 Oct 2026live
CVE 12 Jul 2026
CVE-2026-56259 Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to redirect LLM API calls to attacker-controlled…
High 8.2first seen 04 Oct 2026live
CVE 11 Jul 2026
CVE-2026-61447 PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation…
Critical 10.0first seen 04 Oct 2026live
CVE 11 Jul 2026
CVE-2026-61445 PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command…
Critical 9.9first seen 04 Oct 2026live
CVE 11 Jul 2026
CVE-2026-61439 PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats…
High 7.5first seen 04 Oct 2026live
CVE 10 Jul 2026
CVE-2026-60086 PraisonAI before 4.6.78 contains a prompt injection defense bypass vulnerability where the injection defense only blocks threats classified as CRITICAL, requiring three…
Medium 5.3first seen 04 Oct 2026live
CVE 10 Jul 2026
CVE-2026-56676 9Router is an AI router & token saver. Prior to 0.5.2, 9router validates image URLs by resolving the host before fetching, but open-sse/translator/concerns/image.js…
High 7.4first seen 04 Oct 2026live
CVE 10 Jul 2026
CVE-2026-55641 9Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by reading the client-controlled Host header, allowing…
High 8.2first seen 04 Oct 2026live
CVE 10 Jul 2026
CVE-2026-55638 9Router is an AI router & token saver. Prior to 0.5.2, 9router protects /v1, /v1beta, /api/v1, and /api/v1beta in src/dashboardGuard.js but omits /codex before…
High 8.6first seen 04 Oct 2026live
CVE 10 Jul 2026
CVE-2026-55615 Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.5, Neo4jChatAgent passes LLM-generated Cypher queries straight to…
Unscoredfirst seen 04 Oct 2026live
CVE 10 Jul 2026
CVE-2026-55405 LangChain4j is a Java library for building LLM-powered applications on the JVM. Prior to 1.2.1-beta8, 1.5.1-beta11, 1.11.8-beta19, and 1.16.3-beta26, the MariaDB and…
High 7.6first seen 04 Oct 2026live
CVE 10 Jul 2026
CVE-2026-54769 Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote…
Critical 10.0first seen 04 Oct 2026live
CVE 10 Jul 2026
CVE-2026-50181 Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, Langroid's `ReadFileTool` and `WriteFileTool` appear to treat…
High 7.1first seen 04 Oct 2026live
CVE 10 Jul 2026
CVE-2026-50180 Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, `SQLChatAgent` in `langroid` ships a `_validate_query`…
Unscoredfirst seen 04 Oct 2026live
CVE 10 Jul 2026
CVE-2026-13237 Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from…
Medium 4.8first seen 04 Oct 2026live
CVE 10 Jul 2026
CVE-2026-13236 Missing Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from…
Medium 4.2first seen 04 Oct 2026live
CVE 09 Jul 2026
CVE-2026-59207 n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not enforce the Allowed HTTP Request Domains restriction…
Medium 6.5first seen 04 Oct 2026live
CVE 09 Jul 2026
CVE-2026-58122 Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on…
Critical 9.1first seen 04 Oct 2026live
CVE 09 Jul 2026
CVE-2026-43752 An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature…
Medium 4.9first seen 04 Oct 2026live
Model 09 Jul 2026
OpenAI · proprietaryfirst seen 04 Oct 2026live
Model 09 Jul 2026
OpenAI · proprietaryfirst seen 04 Oct 2026live
Model 09 Jul 2026
OpenAI · proprietaryfirst seen 04 Oct 2026live
Model 09 Jul 2026
OpenAI · proprietaryfirst seen 04 Oct 2026live
Model 09 Jul 2026
OpenAI · proprietaryfirst seen 04 Oct 2026live
Model 09 Jul 2026
OpenAI · proprietaryfirst seen 04 Oct 2026live
CVE 08 Jul 2026
CVE-2026-59822 LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated…
High 8.2Exploitedfirst seen 04 Oct 2026live
CVE 08 Jul 2026
CVE-2026-59821 LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's Custom Code Guardrails production create and…
High 7.2first seen 04 Oct 2026live
CVE 08 Jul 2026
CVE-2026-59820 LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did not sufficiently…
Medium 6.5first seen 04 Oct 2026live
CVE 08 Jul 2026
CVE-2026-59819 LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's /health/test_connection endpoint resolved…
Medium 4.9first seen 04 Oct 2026live
CVE 08 Jul 2026
CVE-2026-59807 Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and exfiltrate sensitive files by exploiting a missing…
Medium 6.8first seen 04 Oct 2026live
CVE 08 Jul 2026
CVE-2026-15154 A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (ReDoS), allows a…
Medium 6.5first seen 04 Oct 2026live
Model 08 Jul 2026
xAI · proprietaryfirst seen 04 Oct 2026live
CVE 07 Jul 2026
CVE-2026-59706 mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request forgery via attacker-controlled ollama_base_url…
Critical 9.3first seen 04 Oct 2026live
CVE 07 Jul 2026
CVE-2026-58473 Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite the global LLM provider configuration by…
Critical 9.1first seen 04 Oct 2026live
CVE 07 Jul 2026
CVE-2026-54602 FastGPT is a knowledge-based AI application platform. Prior to 4.15.0, GET /api/core/ai/record/getRecord authenticates the caller but loads LLM request and response…
Unscoredfirst seen 04 Oct 2026live
CVE 06 Jul 2026
CVE-2026-57573 Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF destination check on the non-streaming /crawl…
High 8.6first seen 04 Oct 2026live
CVE 06 Jul 2026
CVE-2026-57572 Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed…
Critical 10.0first seen 04 Oct 2026live
CVE 06 Jul 2026
CVE-2026-57571 Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename was taken from…
Critical 9.6first seen 04 Oct 2026live
CVE 06 Jul 2026
CVE-2026-55646 vLLM is an inference and serving engine for large language models. From 0.22.0 to 0.23.0, the /v1/audio/transcriptions and /v1/audio/translations routes call…
Medium 6.5first seen 04 Oct 2026live
CVE 06 Jul 2026
CVE-2026-55574 vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the structured_outputs.regex API parameter passes a user-supplied…
High 7.5first seen 04 Oct 2026live
CVE 06 Jul 2026
CVE-2026-55514 vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a /v1/completions request with a model using…
Medium 6.5first seen 04 Oct 2026live
CVE 06 Jul 2026
CVE-2026-54234 vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal multi-request speculative decoding workload can…
High 7.5first seen 04 Oct 2026live
CVE 06 Jul 2026
CVE-2026-44934 A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM response text with potential sensitive data into…
Unscoredfirst seen 04 Oct 2026live
CVE 06 Jul 2026
CVE-2026-14898 The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. An attacker who could place an indirect prompt injection in content…
Medium 6.5first seen 04 Oct 2026live
CVE 05 Jul 2026
CVE-2026-14742 A vulnerability was determined in langchain-ai langgraph up to 1.2.4. The affected element is the function _freeze of the file…
Low 3.1first seen 04 Oct 2026live
CVE 03 Jul 2026
CVE-2026-13341 A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could allow a remote attacker to perform an indirect prompt…
High 7.4first seen 04 Oct 2026live
CVE 02 Jul 2026
CVE-2026-8147 In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators. This allows any authenticated…
High 8.1first seen 04 Oct 2026live