The security intelligence platform for AI teams
AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.
Independent research. No sponsors, no paywalls, no conflicts of interest.
Command Injection Flaw in Ollama-mcp Integration: CVE-2026-19334 affects NightTrek's Ollama-mcp, enabling command injection (execution of unauthorized system commands) via manipulated arguments, though exploitation requires local system access. The vulnerability remains unpatched as developers have not responded to disclosure.
Fix: Update LangChain to version 0.0.317 or later. Patches are available at https://github.com/langchain-ai/langchain/commit/9ecb7240a480720ec9d739b3877a52f76098a2b8 and https://github.com/langchain-ai/langchain/pull/11925.
NVD/CVE Database