Archive // 2026-09

September 2026

Everything the feeds carried with a date in September 2026: still live, or dropped out of the rolling window since. Changes to a CVE's severity, score or exploited status are listed under it.

CVE 30 Sep 2026
CVE-2026-51871 Devika v1.0 is vulnerable to Code Injection in the Runner.execute function in src/agents/runner/runner.py which allows an attacker to achieve arbitrary code execution by…
Critical 9.8first seen 04 Oct 2026live
CVE 30 Sep 2026
CVE-2026-103241 A flaw has been found in vllm-project vLLM up to 0.26.0. This vulnerability affects unknown code of the file rust/src/parser/src/unified/gemma4.rs of the component…
Medium 5.3first seen 04 Oct 2026live
CVE 29 Sep 2026
CVE-2026-77177 Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injection (with Jinja2…
Critical 9.8first seen 04 Oct 2026live
CVE 29 Sep 2026
CVE-2026-102697 Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experimental agent mode Bash tool approval mechanism that fails to properly…
High 7.8first seen 04 Oct 2026live
Model 29 Sep 2026
OpenAI · proprietaryfirst seen 04 Oct 2026live
Model 29 Sep 2026
OpenAI · proprietaryfirst seen 04 Oct 2026live
CVE 28 Sep 2026
CVE-2026-55157 Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge graph across 16 CLI clients. Prior to version 5.1.0…
High 8.4first seen 04 Oct 2026live
CVE 28 Sep 2026
CVE-2026-101861 Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows authenticated attackers to achieve code execution…
Medium 4.1first seen 04 Oct 2026live
Model 28 Sep 2026
Anthropic · proprietaryfirst seen 04 Oct 2026live
CVE 27 Sep 2026
CVE-2026-101065 Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the…
Critical 9.8first seen 04 Oct 2026live
CVE 27 Sep 2026
CVE-2026-100863 Heym versions 0.0.90 and earlier contain two server-side request forgery (SSRF) egress gaps, both remediated in app/services/ssrf_guard.py in 0.0.91. First, the LLM…
Medium 5.0first seen 04 Oct 2026live
CVE 26 Sep 2026
CVE-2026-100654 vLLM before 0.29.0 accepts user-controlled stop_token_ids on the OpenAI-compatible POST /v1/completions and POST /v1/chat/completions endpoints but validates only that…
Medium 6.5first seen 04 Oct 2026live
CVE 26 Sep 2026
CVE-2026-100653 vLLM is an inference and serving engine for large language models. In versions from 0.22.1 through 0.28.0, the operator-supplied model revision pin (--revision /…
Medium 6.5first seen 04 Oct 2026live
CVE 26 Sep 2026
CVE-2026-100652 vLLM versions 0.22.0 through 0.23.0 fail to validate stop_token_ids against vocabulary bounds in Rust HTTP and gRPC frontends, allowing out-of-vocabulary token IDs to…
Medium 5.9first seen 04 Oct 2026live
CVE 26 Sep 2026
CVE-2026-100651 vLLM before 0.29.0 fails to enforce decoder prompt-length validation on the disaggregated serving endpoint /inference/v1/generate. When the request contains a 'features'…
Medium 6.5first seen 04 Oct 2026live
CVE 26 Sep 2026
CVE-2026-100650 vLLM through 0.29.0 fetches and fully materializes remote or inline media before enforcing its documented media controls (the VLLM_MAX_AUDIO_CLIP_FILESIZE_MB…
Medium 6.5first seen 04 Oct 2026live
CVE 26 Sep 2026
CVE-2026-100649 vLLM before 0.29.0 contains a resource-limit bypass vulnerability in PyNvVideoCodec decoder allocation where sampler subclass shadowing allows independent counter…
Low 3.7first seen 04 Oct 2026live
CVE 26 Sep 2026
CVE-2026-100648 vllm before 0.29.0 fails to enforce VLLM_MAX_AUDIO_CLIP_FILESIZE_MB limit in multimodal chat audio decoding, allowing unauthenticated clients to bypass file size…
Medium 5.3first seen 04 Oct 2026live
CVE 26 Sep 2026
CVE-2026-100647 vLLM versions before 0.29.0 contain a denial-of-service vulnerability in the cache_salt parameter accepted on OpenAI-compatible and Anthropic API endpoints, which lacks…
Medium 5.3first seen 04 Oct 2026live
CVE 25 Sep 2026
CVE-2026-97869 A flaw has been found in langchain4j up to 1.5.3-beta10/1.11.10-beta18/1.18.1-beta27. This vulnerability affects the function AgenticScopeSerializer.fromJson of the file…
Medium 4.1first seen 04 Oct 2026live
CVE 25 Sep 2026
CVE-2026-97228 Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injection issue in the export-status component (`get_export_status` in…
Low 2.7first seen 04 Oct 2026live
CVE 25 Sep 2026
CVE-2026-84462 Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filter that protects Zammad's AI Agent configuration can be bypassed by…
Unscoredfirst seen 04 Oct 2026live
CVE 25 Sep 2026
CVE-2026-63216 Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, unsanitized option labels are rendered in the configuration dialogs of AI Agents…
Unscoredfirst seen 04 Oct 2026live
CVE 24 Sep 2026
CVE-2026-77294 TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authenticated user to store an attacker-controlled llm_base_url through the settings API when the…
High 8.1first seen 04 Oct 2026live
CVE 24 Sep 2026
CVE-2026-61742 DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Versions prior to 0.22.5 expose an unauthenticated HTTP MCP endpoint when…
Unscoredfirst seen 04 Oct 2026live
CVE 24 Sep 2026
CVE-2026-61732 Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output of agent reconnaissance against target services —…
Critical 10.0first seen 04 Oct 2026live
CVE 23 Sep 2026
CVE-2026-96804 MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control entirely in _load_model(), which allows a…
High 8.8first seen 04 Oct 2026live
CVE 23 Sep 2026
CVE-2026-96775 MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control only when the model_path ends in .pkl, which allows a…
High 8.8first seen 04 Oct 2026live
CVE 23 Sep 2026
CVE-2026-93529 Contributor Broken Access Control in WSP MCP &#8211; AI Agents Connector <= 2.7.0 versions.
Medium 6.5first seen 04 Oct 2026live
CVE 23 Sep 2026
CVE-2026-18875 IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server…
High 7.3first seen 04 Oct 2026live
Model 23 Sep 2026
Alibaba / Qwen · apifirst seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-84301 FastGPT is an open-source LLM platform for building AI applications on a knowledge base. Prior to 4.15.2, the safe Axios request interceptor in…
Medium 6.3first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77274 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, validate_url_for_ssrf has a backslash authority…
High 8.2first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77272 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth error query parameter is passed to…
Medium 5.4first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77271 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, validate_safe_path defaults its base directory to…
High 8.8first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77270 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Jira and Confluence attachment upload tools…
Medium 6.5first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77269 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the remediation for CVE-2026-27825 protects…
Medium 6.5first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77268 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth fallback token directory and JSON file…
Medium 5.5first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77267 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the X-Atlassian-Jira-Url and…
Medium 6.5first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77266 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment accepts absolute paths and…
Medium 6.5first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77265 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, header-supplied Jira or Confluence URLs are…
Medium 5.9first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77262 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment accepts an…
High 8.6first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77261 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, _make_ssrf_safe_hook is omitted from JiraFetcher…
High 7.1first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77260 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Confluence and Jira upload_attachment…
High 7.5first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77259 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment opens a…
High 7.7first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77258 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment in…
High 7.7first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77257 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, HTTP-exposed Jira and Confluence upload tools pass…
Medium 6.5first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77256 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the plaintext OAuth fallback file containing…
Medium 6.5first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77255 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Jira update_issue attachments argument is…
High 8.6first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77254 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, requests to the HTTP MCP endpoint without a…
Critical 9.1first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77253 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira and Confluence attachment upload tools accept…
High 7.1first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77252 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, caller-supplied projects_filter and spaces_filter…
Medium 6.5first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77251 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira search accepts a forbidden project clause…
Medium 6.5first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77250 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, OAuthConfig writes a plaintext fallback file…
Medium 6.1first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77249 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, JiraUserMixin._lookup_user_by_permissions uses the…
Medium 5.3first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77248 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the streamable HTTP transport accepts requests…
High 8.6first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77247 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira and Confluence upload tools interpret…
Medium 6.5first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77246 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, an HTTP transport deployment with…
High 7.4first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77244 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the HTTP transport accepts requests without a…
Critical 10.0first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77243 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, ENABLED_TOOLS and TOOLSETS are applied when tools…
High 8.8first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-77242 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, validate_url_for_ssrf checks a hostname's resolved…
High 7.5first seen 04 Oct 2026live
CVE 22 Sep 2026
CVE-2026-56681 9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper trust the…
High 7.3first seen 04 Oct 2026live
Model 22 Sep 2026
OpenAI · proprietaryfirst seen 04 Oct 2026live
Model 22 Sep 2026
OpenAI · proprietaryfirst seen 04 Oct 2026live
Model 22 Sep 2026
OpenAI · proprietaryfirst seen 04 Oct 2026live
Model 22 Sep 2026
OpenAI · proprietaryfirst seen 04 Oct 2026live
Model 22 Sep 2026
Cohere · proprietaryfirst seen 04 Oct 2026live
Model 22 Sep 2026
Anthropic · proprietaryfirst seen 04 Oct 2026live
CVE 21 Sep 2026
CVE-2026-94627 vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID in prefill/decode…
High 7.5first seen 04 Oct 2026live
CVE 21 Sep 2026
CVE-2026-94626 vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded…
High 7.5first seen 04 Oct 2026live
CVE 21 Sep 2026
CVE-2026-94625 vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders that are…
Medium 5.3first seen 04 Oct 2026live
CVE 21 Sep 2026
CVE-2026-94624 vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer…
High 7.5first seen 04 Oct 2026live
CVE 21 Sep 2026
CVE-2026-94623 vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across…
High 7.5first seen 04 Oct 2026live
CVE 21 Sep 2026
CVE-2026-94622 vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode disaggregated deployments. Attackers…
High 7.5first seen 04 Oct 2026live
CVE 21 Sep 2026
CVE-2026-88978 Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.106.1, the WorkerStatus gRPC polling path in…
Medium 4.3first seen 04 Oct 2026live
CVE 21 Sep 2026
CVE-2026-84298 Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.95.3, the V1 DurableTask stream handler stores…
Low 3.1first seen 04 Oct 2026live
CVE 21 Sep 2026
CVE-2026-63342 Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1…
Medium 6.3first seen 04 Oct 2026live
CVE 21 Sep 2026
CVE-2026-61687 Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ValidateOAuthState clears the oauth_state_ session…
High 7.1first seen 04 Oct 2026live
CVE 21 Sep 2026
CVE-2026-61681 Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, the SNS UnsubscribeConfirmation handler in…
Medium 4.1first seen 04 Oct 2026live
CVE 21 Sep 2026
CVE-2026-61647 NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content to local vault directories. Versions 1.6.0…
Unscoredfirst seen 04 Oct 2026live
Model 21 Sep 2026
xAI · proprietaryfirst seen 04 Oct 2026live
Model 21 Sep 2026
NVIDIA · apifirst seen 04 Oct 2026live
CVE 20 Sep 2026
CVE-2026-94111 Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension…
Medium 6.6first seen 04 Oct 2026live
CVE 19 Sep 2026
CVE-2026-93989 vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer(). Attackers…
Low 3.1first seen 04 Oct 2026live
CVE 19 Sep 2026
CVE-2026-93982 OpenPanel through 2.3.0 writes Model Context Protocol authentication tokens from URL query parameters to plaintext application logs without redaction. Attackers with…
Low 3.3first seen 04 Oct 2026live
CVE 18 Sep 2026
CVE-2026-93841 vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs index the penalty prompt-presence bitset without…
Low 3.7first seen 04 Oct 2026live
CVE 18 Sep 2026
CVE-2026-93840 vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in SamplingParams._validate_allowed_token_ids(). Attackers…
Low 3.7first seen 04 Oct 2026live
CVE 18 Sep 2026
CVE-2026-93592 vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the…
High 7.5first seen 04 Oct 2026live
CVE 18 Sep 2026
CVE-2026-58197 ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0…
High 8.8first seen 04 Oct 2026live
CVE 18 Sep 2026
CVE-2026-33625 LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.12.2 contain a code injection vulnerability in…
High 8.8first seen 04 Oct 2026live
CVE 18 Sep 2026
CVE-2025-66455 LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch…
Critical 9.8first seen 04 Oct 2026live
CVE 17 Sep 2026
CVE-2026-93436 vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggregated deployments. Remote attackers can…
High 7.5first seen 04 Oct 2026live
CVE 17 Sep 2026
CVE-2026-54520 AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step…
High 8.1first seen 04 Oct 2026live
CVE 17 Sep 2026
CVE-2026-54519 AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1…
High 8.8first seen 04 Oct 2026live
CVE 17 Sep 2026
CVE-2026-53557 SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated user can supply a crafted sheet["tableName"] value…
Unscoredfirst seen 04 Oct 2026live
CVE 17 Sep 2026
CVE-2026-53556 SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/previewData endpoint in…
Unscoredfirst seen 04 Oct 2026live
CVE 17 Sep 2026
CVE-2026-53555 SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated uploader can submit an image/svg+xml assistant UI…
Unscoredfirst seen 04 Oct 2026live
CVE 17 Sep 2026
CVE-2026-53554 SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/parseExcel endpoint in…
Unscoredfirst seen 04 Oct 2026live
CVE 17 Sep 2026
CVE-2026-50125 MKP is a Model Context Protocol server for Kubernetes. Prior to 0.4.1, cmd/server/main.go exposes the default HTTP endpoint and pkg/mcp/server.go registers the…
High 7.5first seen 04 Oct 2026live
CVE 16 Sep 2026
CVE-2026-92816 ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arbitrary paths outside the output directory…
High 7.8first seen 04 Oct 2026live
CVE 16 Sep 2026
CVE-2026-92365 A vulnerability was found in vllm-project vllm up to 0.29.0. Affected by this issue is some unknown functionality of the file vllm/v1/sample/thinking_budget_state.py…
Medium 4.3first seen 04 Oct 2026live
CVE 16 Sep 2026
CVE-2026-92220 A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected is the function…
Medium 5.3first seen 04 Oct 2026live
CVE 16 Sep 2026
CVE-2026-69147 vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions and Responses can set…
Medium 6.5first seen 04 Oct 2026live
CVE 16 Sep 2026
CVE-2026-64684 RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in…
Medium 6.8first seen 04 Oct 2026live
CVE 16 Sep 2026
CVE-2026-63128 RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's stateful Streamable HTTP server in…
High 7.5first seen 04 Oct 2026live
CVE 16 Sep 2026
CVE-2026-63127 RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in crates/rmcp/src/transport/auth.rs omits the RFC…
High 8.2first seen 04 Oct 2026live
CVE 16 Sep 2026
CVE-2026-59823 LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an authenticated LiteLLM Proxy caller with a valid virtual key can…
Unscoredfirst seen 04 Oct 2026live
CVE 16 Sep 2026
CVE-2026-57173 vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling path for /v1/chat/completions calls AudioMediaIO.load_bytes…
Medium 6.5first seen 04 Oct 2026live
CVE 16 Sep 2026
CVE-2025-59953 LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements…
Critical 9.8first seen 04 Oct 2026live
CVE 15 Sep 2026
CVE-2026-91935 Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect requests to arbitrary hosts. Attackers with…
High 8.3first seen 04 Oct 2026live
CVE 15 Sep 2026
CVE-2026-90878 A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template…
Medium 4.3first seen 04 Oct 2026live
CVE 15 Sep 2026
CVE-2026-61568 `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or…
Critical 9.6first seen 04 Oct 2026live
CVE 15 Sep 2026
CVE-2026-61560 `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`SSE=true`) exposes all MCP tools without any…
Critical 9.8first seen 04 Oct 2026live
CVE 15 Sep 2026
CVE-2026-61559 `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable…
Critical 9.6first seen 04 Oct 2026live
CVE 15 Sep 2026
CVE-2026-59973 FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). From mcp-from-openapi 2.3.0 until 2.5.0 and from frontmcp and @frontmcp/adapters 1.2.1…
High 8.5first seen 04 Oct 2026live
CVE 15 Sep 2026
CVE-2026-59971 MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes…
Critical 10.0first seen 04 Oct 2026live
CVE 15 Sep 2026
CVE-2026-58485 mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.7.1, web_url_read receives…
High 7.1first seen 04 Oct 2026live
CVE 15 Sep 2026
CVE-2026-58483 mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.7.1, web_url_read in…
High 7.5first seen 04 Oct 2026live
CVE 15 Sep 2026
CVE-2026-58201 Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services. Prior to 2.1.2, the Lokka-Microsoft tool in src/mcp/src/main.ts…
Unscoredfirst seen 04 Oct 2026live
CVE 15 Sep 2026
CVE-2026-58196 ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.31.0, remote.Handler.Authenticate in…
Medium 4.7first seen 04 Oct 2026live
CVE 15 Sep 2026
CVE-2026-57442 MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5, PathFilter in src/pathfilter.ts uses…
Unscoredfirst seen 04 Oct 2026live
CVE 15 Sep 2026
CVE-2026-57441 MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.4, PathFilter in src/pathfilter.ts compiles…
Unscoredfirst seen 04 Oct 2026live
CVE 15 Sep 2026
CVE-2026-54689 mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, the web_url_read URL…
Medium 6.3first seen 04 Oct 2026live
CVE 15 Sep 2026
CVE-2026-54561 MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants. Prior to 0.13.0, context_import in src/index.ts passes the…
Medium 6.2first seen 04 Oct 2026live
CVE 15 Sep 2026
CVE-2026-54549 Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, the upload_ad_image tool in…
High 8.3first seen 04 Oct 2026live
CVE 15 Sep 2026
CVE-2026-54547 Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, AuthInjectionMiddleware in…
High 7.4first seen 04 Oct 2026live
CVE 15 Sep 2026
CVE-2026-54450 ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.29.1, networking.IsPrivateIP in…
Unscoredfirst seen 04 Oct 2026live
CVE 15 Sep 2026
CVE-2026-53957 Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to @contentful/mcp-server 1.7.19 and @contentful/mcp-tools 0.4.5…
High 7.7first seen 04 Oct 2026live
News 14 Sep 2026
Google AIProviderfirst seen 04 Oct 2026live
CVE 14 Sep 2026
CVE-2026-90938 LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server on 0.0.0.0:5401 (/plugin/ws) whose authentication is gated on…
High 8.6first seen 04 Oct 2026live
CVE 14 Sep 2026
CVE-2026-90713 A security flaw has been discovered in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the file…
Low 3.3first seen 04 Oct 2026live
CVE 14 Sep 2026
CVE-2026-73497 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). From 0.17.0 until 0.22.0, validate_url_for_ssrf resolves the…
Medium 6.5first seen 04 Oct 2026live
CVE 14 Sep 2026
CVE-2026-73496 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and…
High 7.7first seen 04 Oct 2026live
CVE 14 Sep 2026
CVE-2026-57145 PraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py passes the LLM-controlled filepath parameter directly to open for…
Critical 9.1first seen 04 Oct 2026live
CVE 14 Sep 2026
CVE-2026-57130 PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/email_tools.py interpolates LLM-controlled…
High 8.1first seen 04 Oct 2026live
CVE 14 Sep 2026
CVE-2026-55837 dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.20.0, the local OAuth helper in src/dbt_mcp/oauth/fastapi_app.py exposes GET…
Medium 6.8first seen 04 Oct 2026live
CVE 14 Sep 2026
CVE-2026-55253 LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. Prior to langgraph-checkpoint-mongodb 0.3.0 and langgraph-store-mongodb 0.4.0…
High 7.7first seen 04 Oct 2026live
CVE 14 Sep 2026
CVE-2026-17628 IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to change the password of an account due to improper authentication.
Medium 5.4first seen 04 Oct 2026live
CVE 14 Sep 2026
CVE-2026-12944 IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components…
Critical 9.6first seen 04 Oct 2026live
CVE 14 Sep 2026
CVE-2026-12767 IBM Langflow OSS 1.0.0 through 1.11.5 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from…
Medium 6.5first seen 04 Oct 2026live
CVE 14 Sep 2026
CVE-2026-12766 IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from…
Medium 5.4first seen 04 Oct 2026live
CVE 14 Sep 2026
CVE-2026-12765 IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from…
Medium 6.5first seen 04 Oct 2026live
CVE 14 Sep 2026
CVE-2026-12763 IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP…
Medium 4.2first seen 04 Oct 2026live
Model 14 Sep 2026
NVIDIA · open-weightfirst seen 04 Oct 2026live
Model 14 Sep 2026
Alibaba / Qwen · open-weightfirst seen 04 Oct 2026live
CVE 12 Sep 2026
CVE-2026-90555 vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers…
Medium 6.5first seen 04 Oct 2026live
CVE 12 Sep 2026
CVE-2026-90554 vLLM versions >=0.10.2 and <0.28.0 do not apply any audio decode-size or duration limit when extracting audio from video input for NanoNemotronVL models. In…
Medium 6.2first seen 04 Oct 2026live
CVE 12 Sep 2026
CVE-2026-90553 vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading…
High 7.8first seen 04 Oct 2026live
CVE 12 Sep 2026
CVE-2026-90534 Flowise is a low-code platform for building LLM applications. In versions up to and including 3.1.3, the POST /api/v1/node-load-method/:name endpoint is mounted without…
Medium 6.5first seen 04 Oct 2026live
CVE 11 Sep 2026
CVE-2026-71416 Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket server does not validate the `Origin` header of…
High 8.8first seen 04 Oct 2026live
CVE 10 Sep 2026
CVE-2026-9225 IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access control in…
Medium 6.5first seen 04 Oct 2026live
CVE 10 Sep 2026
CVE-2026-88938 knowns through 0.33.0 fails to confine the path argument of the code.find MCP tool to the project root, allowing AI agent sessions to read source files anywhere on the…
Medium 6.5first seen 04 Oct 2026live
CVE 10 Sep 2026
CVE-2026-88055 AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.16.1 and earlier, the manager role can…
Medium 5.5first seen 04 Oct 2026live
CVE 10 Sep 2026
CVE-2026-85025 IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly…
Critical 9.8first seen 04 Oct 2026live
CVE 10 Sep 2026
CVE-2026-84889 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted…
High 8.8first seen 04 Oct 2026live
CVE 10 Sep 2026
CVE-2026-81941 IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege…
High 8.8first seen 04 Oct 2026live
CVE 10 Sep 2026
CVE-2026-81940 IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow…
High 8.8first seen 04 Oct 2026live
CVE 10 Sep 2026
CVE-2026-81268 IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session…
High 8.1first seen 04 Oct 2026live
CVE 10 Sep 2026
CVE-2026-81265 IBM Langflow OSS 1.0.0 through 1.11.5.
High 7.5first seen 04 Oct 2026live
CVE 10 Sep 2026
CVE-2026-81213 IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of…
High 8.6first seen 04 Oct 2026live
CVE 10 Sep 2026
CVE-2026-81211 IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in…
High 8.8first seen 04 Oct 2026live
CVE 10 Sep 2026
CVE-2026-81204 IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.
Critical 9.8first seen 04 Oct 2026live
CVE 10 Sep 2026
CVE-2026-79742 IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.
High 8.8first seen 04 Oct 2026live
CVE 10 Sep 2026
CVE-2026-79725 IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to improper access control.
Medium 6.5first seen 04 Oct 2026live
CVE 10 Sep 2026
CVE-2026-79724 IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS…
Critical 9.8first seen 04 Oct 2026live
CVE 10 Sep 2026
CVE-2026-79723 IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API…
Medium 5.0first seen 04 Oct 2026live
CVE 10 Sep 2026
CVE-2026-78575 IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in…
High 8.8first seen 04 Oct 2026live
CVE 10 Sep 2026
CVE-2026-78571 IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an unguarded eval() call on attacker-controlled input.
High 8.8first seen 04 Oct 2026live
CVE 10 Sep 2026
CVE-2026-78569 IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner.
High 8.8first seen 04 Oct 2026live
CVE 10 Sep 2026
CVE-2026-76059 IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom component source code could bypass the static security scanner by crafting an annotated…
High 8.8first seen 04 Oct 2026live
CVE 10 Sep 2026
CVE-2026-19136 A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating…
High 7.8first seen 04 Oct 2026live
Model 10 Sep 2026
Allen Institute · open-weightfirst seen 04 Oct 2026live
CVE 09 Sep 2026
CVE-2026-53937 MCP Kotlin SDK is the Kotlin Multiplatform software development kit for the Model Context Protocol. In versions 0.7.0 through 0.12.0, `ReadBuffer.append` in…
Medium 6.2first seen 04 Oct 2026live
CVE 08 Sep 2026
CVE-2026-79721 Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an…
Unscoredfirst seen 04 Oct 2026live
Model 08 Sep 2026
NVIDIA · open-weightfirst seen 04 Oct 2026live
CVE 07 Sep 2026
CVE-2026-86289 A vulnerability was found in Ollama up to 0.31.1. This issue affects the function readGGUFV1String of the file fs/ggml/gguf.go of the component GGUF Decoder. Performing…
Medium 4.3first seen 04 Oct 2026live
CVE 04 Sep 2026
CVE-2026-9186 IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For…
Medium 6.5first seen 04 Oct 2026live
CVE 04 Sep 2026
CVE-2026-9138 IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in the…
Medium 6.5first seen 04 Oct 2026live
CVE 04 Sep 2026
CVE-2026-85694 LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived…
High 8.1first seen 04 Oct 2026live
CVE 04 Sep 2026
CVE-2026-85675 OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content tool that fetches caller-supplied URLs with no…
High 7.5first seen 04 Oct 2026live
CVE 04 Sep 2026
CVE-2026-85674 aider (aider-chat) automatically loads a .aider.conf.yml configuration file from the root of the git repository it is launched in. A crafted repository can set test-cmd…
High 7.8first seen 04 Oct 2026live
CVE 04 Sep 2026
CVE-2026-8447 IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site scripting vulnerability in the Playground chat interface.
Medium 6.1first seen 04 Oct 2026live
CVE 04 Sep 2026
CVE-2026-31020 In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This…
Critical 9.8first seen 04 Oct 2026live
CVE 04 Sep 2026
CVE-2026-19645 IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a valid session cookie can submit arbitrarily large or computationallyexpensive requests that…
Medium 6.5first seen 04 Oct 2026live
CVE 04 Sep 2026
CVE-2026-19306 IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key…
High 7.7first seen 04 Oct 2026live
CVE 04 Sep 2026
CVE-2026-19305 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery.
High 8.6first seen 04 Oct 2026live
CVE 04 Sep 2026
CVE-2026-19304 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from internal services due to a URL parser discrepancy.
High 7.7first seen 04 Oct 2026live
CVE 04 Sep 2026
CVE-2026-19303 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname…
High 8.1first seen 04 Oct 2026live
CVE 04 Sep 2026
CVE-2026-19302 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.
Medium 6.5first seen 04 Oct 2026live
CVE 04 Sep 2026
CVE-2026-19301 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery.
Medium 5.0first seen 04 Oct 2026live
CVE 04 Sep 2026
CVE-2026-19300 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields.
High 7.5first seen 04 Oct 2026live
CVE 04 Sep 2026
CVE-2026-19299 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to path traversal.
Medium 6.5first seen 04 Oct 2026live
CVE 04 Sep 2026
CVE-2026-19298 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process.
High 8.8first seen 04 Oct 2026live
CVE 04 Sep 2026
CVE-2026-17631 IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF)…
Medium 5.0first seen 04 Oct 2026live
CVE 04 Sep 2026
CVE-2026-17627 IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to…
Medium 4.9first seen 04 Oct 2026live
CVE 04 Sep 2026
CVE-2026-17622 IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a…
Medium 6.5first seen 04 Oct 2026live
CVE 04 Sep 2026
CVE-2026-17621 IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request…
Medium 5.4first seen 04 Oct 2026live
CVE 04 Sep 2026
CVE-2026-14470 IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request…
Medium 6.5first seen 04 Oct 2026live
Model 04 Sep 2026
OpenAI · proprietaryfirst seen 04 Oct 2026live
Model 04 Sep 2026
OpenAI · proprietaryfirst seen 04 Oct 2026live
Model 04 Sep 2026
NVIDIA · open-weightfirst seen 04 Oct 2026live
CVE 03 Sep 2026
CVE-2026-85180 Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenticated attackers to redirect blob downloads to arbitrary hosts. An…
High 7.5first seen 04 Oct 2026live
CVE 03 Sep 2026
CVE-2026-84779 Subscriber Broken Access Control in Agentimus – AI SEO, llms.txt &amp; MCP for AI Agents <= 1.51.0 versions.
High 8.1first seen 04 Oct 2026live
CVE 02 Sep 2026
CVE-2026-84377 LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versions 1.88.6 and 1.96.2, any authenticated LiteLLM proxy user could…
Medium 6.5first seen 04 Oct 2026live
CVE 02 Sep 2026
CVE-2026-82404 TOON is a compact, human-readable serialization of JSON data for LLM prompts. Prior to 2.3.1, decoding attacker-controlled TOON with a __proto__, constructor, or…
High 8.3first seen 04 Oct 2026live
Model 02 Sep 2026
Google · proprietaryfirst seen 04 Oct 2026live
Model 01 Sep 2026
Anthropic · proprietaryfirst seen 04 Oct 2026live