aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Browse All

All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.

to
Export CSV
9705 items

GHSA-jfrm-rx66-g536: NiceGUI: Local file disclosure via Docutils file insertion in ui.restructured_text()

highvulnerability
security
May 18, 2026
CVE-2026-45553

NiceGUI's `ui.restructured_text()` function renders user-supplied reStructuredText using Docutils without disabling file insertion directives, allowing attackers to read local files accessible to the server using standard Docutils directives like `include` and `raw`. This vulnerability only affects applications that pass untrusted or user-controlled content to this function, not those using only static trusted strings.

Fix: Disable unsafe Docutils features by modifying the `publish_parts()` call in `prepare_content()` to include these `settings_overrides`: `'file_insertion_enabled': False`, `'raw_enabled': False`, and `'_disable_config': True`. This blocks the `include`, `csv-table :file:`, and `raw :file:` directives as well as local `docutils.conf` overrides.

GitHub Advisory Database

GHSA-43g7-cwr8-q3jh: OpenTelemetry eBPF Instrumentation: Memcached payload length overflow can crash OBI

highvulnerability
security
May 18, 2026
CVE-2026-45686

OpenTelemetry eBPF Instrumentation (OBI) contains an integer overflow vulnerability in its memcached protocol parser that allows a remote attacker to crash the OBI process. When parsing memcached storage commands, the parser accepts extremely large byte values without checking if adding the delimiter length will overflow, causing a negative value that triggers a runtime panic (a sudden crash caused by an error the program cannot recover from).

GHSA-j8p6-96vp-f3r9: OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages

highvulnerability
security
May 18, 2026
CVE-2026-45685

Malformed MongoDB wire messages can crash the OpenTelemetry eBPF Instrumentation telemetry agent through uncaught panics in its MongoDB parser, allowing remote attackers to cause denial of service. The parser checks attacker-controlled network data without fully validating it first, so a single crafted message can stop telemetry collection until the agent restarts.

GHSA-vvmg-8mjr-g6q3: OpenTelemetry eBPF Instrumentation: Log enricher writev path can overread and overwrite user buffers

mediumvulnerability
security
May 18, 2026
CVE-2026-45684

OpenTelemetry eBPF Instrumentation (OBI) has a memory safety bug in its log enricher that mishandles writev calls (a system call that writes multiple buffer segments at once). When log injection is enabled, the code reads only the first buffer segment but copies as many bytes as all segments combined, causing it to read and overwrite memory beyond what it should access. This can corrupt application buffers, leak sensitive data into logs, or crash the instrumented process.

GHSA-962q-hwm5-52x5: OpenTelemetry eBPF Instrumentation: CappedConcurrentHashMap leaks keys after removals

mediumvulnerability
security
May 18, 2026
CVE-2026-45682

OpenTelemetry eBPF Instrumentation has a memory leak in its `CappedConcurrentHashMap` class, which is used to track Java TLS connections. When entries are deleted from the map, the keys are not removed from an internal queue, causing the queue to grow indefinitely in systems with many short-lived connections. This can eventually cause the Java process to run out of memory.

CVE-2026-47092: Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attac

highvulnerability
security
May 18, 2026
CVE-2026-47092

Claude HUD versions up to 0.0.12 contain a command injection vulnerability (a security flaw where an attacker can trick a program into running harmful commands) that affects Windows systems. An attacker with local access can manipulate the COMSPEC environment variable (a Windows setting that specifies which command interpreter to use) before the software checks its version, causing it to run malicious code with system permissions.

CVE-2026-47091: Claude HUD through 0.0.12, patched in commit 234d9aa, contains a path traversal vulnerability that allows attackers to r

lowvulnerability
security
May 18, 2026
CVE-2026-47091

Claude HUD versions up to 0.0.12 contain a path traversal vulnerability (a flaw where attackers can access files outside intended directories by manipulating file paths) that lets attackers read any file the program can access by sending a malicious transcript_path value. Additionally, the vulnerability creates a cache file with weak permissions that records which files were accessed, leaving evidence even after the program stops running.

CVE-2026-47090: Claude HUD through 0.0.12, patched in commit 234d9aa, constructs OSC 8 terminal hyperlink escape sequences using raw cwd

mediumvulnerability
security
May 18, 2026
CVE-2026-47090

Claude HUD version 0.0.12 and earlier has a vulnerability where it creates terminal hyperlinks (clickable links in terminal windows) using user-controlled data without properly cleaning it first, allowing attackers to inject malicious terminal codes (ANSI codes, which control formatting and behavior in terminals) that could change text colors, fake command prompts, steal clipboard data, or redirect users to attacker-controlled websites.

GHSA-fjq3-ffvr-vm46: OpenTelemetry eBPF Instrumentation: Java TLS ioctl kprobe allows kernel memory disclosure

lowvulnerability
security
May 18, 2026
CVE-2026-45683

OpenTelemetry eBPF Instrumentation (OBI) has a vulnerability where its Java TLS monitoring code uses the wrong function to read memory pointers from user processes. A local process can trick it into reading kernel memory (memory that should be protected) instead of user memory, and that kernel data gets leaked into telemetry (monitoring data). This affects systems with Java TLS support enabled.

GHSA-r6c9-g6q5-qrf9: OpenTelemetry eBPF Instrumentation: CPU-mismatch fallback uses 256-byte buffer with 8KB size

mediumvulnerability
security
May 18, 2026
CVE-2026-45681

OpenTelemetry eBPF Instrumentation (OBI) has a memory leak vulnerability where a CPU mismatch causes the system to use a 256-byte fallback buffer but still tries to read up to 8KB of data from it, reading beyond the buffer's boundaries and leaking adjacent memory into telemetry (data about system performance). This happens in the HTTP tracing path when context propagation is enabled and certain conditions are met.

GHSA-89c6-vpcj-7vj4: OpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPU

mediumvulnerability
security
May 18, 2026
CVE-2026-45680

OpenTelemetry eBPF Instrumentation (OBI) has a performance flaw where it replays BPF probe hits (measurements of how long code takes to run) by looping once for each recorded execution. On busy systems, this loop can become very large between metric collection intervals, causing the metrics exporter to waste CPU time in a tight loop rather than processing a fixed number of metric series.

Pope Leo to issue text on human dignity and AI with Anthropic co-founder

infonews
policy
May 18, 2026

Pope Leo is releasing an encyclical (a major teaching document from the Catholic Church) called Magnifica Humanitas that addresses how artificial intelligence affects human dignity, workers' rights, and society. The document will be presented at the Vatican on May 25 with Christopher Olah, co-founder of Anthropic (an AI company), and other speakers, marking a significant moment where the Church signals its engagement with rapid technological change similar to how Pope Leo XIII responded to the Industrial Revolution in 1891.

Musk v. Altman proved that AI is led by the wrong people

infonews
industry
May 18, 2026

Elon Musk sued Sam Altman over control of OpenAI, a major AI company they co-founded together, but a jury dismissed the case after just two hours due to legal time limits. The trial revealed concerns that many of the powerful tech leaders directing AI development may not be trustworthy or temperamentally suited for the responsibility.

5 Steps to Managing Shadow AI Tools Without Slowing Down Employees

infonews
securitypolicy

Tech firms face tougher UK rules on intimate image abuse

infonews
safetypolicy

Cyber Incident Prevention and Response for Small and Medium Sized Enterprises: A Scoping Review

inforesearchPeer-Reviewed
security

Elon Musk loses court battle against Sam Altman and OpenAI after 3-week trial

infonews
policy
May 18, 2026

Elon Musk lost a court case against OpenAI and Sam Altman because a jury decided he waited too long to file the lawsuit, not because his claims were false. Musk had accused Altman and OpenAI of breaking an agreement to keep the AI company as a nonprofit charity, but the court ruled the case fell outside the three-year deadline (statute of limitations) for bringing such claims. Musk plans to appeal the decision.

Jury tosses Elon Musk's lawsuit against OpenAI and its boss Sam Altman

infonews
policy
May 18, 2026

A California jury dismissed Elon Musk's lawsuit against OpenAI and CEO Sam Altman, ruling that Musk had waited too long to file his claims (the statute of limitations, a legal deadline for when lawsuits must be filed, had expired). Musk had accused Altman of breaching a non-profit agreement by converting OpenAI to a for-profit company after Musk donated $38 million early in the company's history. The jury's decision means the case was dismissed on timing grounds rather than on the actual merits of Musk's accusations.

GHSA-pgvv-q3wf-mm9m: OpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloads

highvulnerability
security
May 18, 2026
CVE-2026-45678

OpenTelemetry eBPF Instrumentation (OBI) has a vulnerability in its Postgres protocol parser that can crash when it receives a malformed BIND message (a type of Postgres network packet). The parser doesn't check if the message payload is complete before reading from it, so an attacker could send a specially crafted empty or truncated packet to cause the program to panic and stop collecting telemetry data.

GHSA-8rrq-wcg8-cv5q: OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages

mediumvulnerability
security
May 18, 2026
CVE-2026-45679

OpenTelemetry eBPF Instrumentation (OBI) exports unfiltered error messages from Redis directly into span status messages, which are then sent to telemetry backends (systems that collect and store trace data). This means sensitive information like tokens or passwords that appear in Redis errors could be leaked into monitoring systems, and attackers could inject malicious text into these systems.

Previous222 / 486Next
GitHub Advisory Database

Fix: The bounds-check panics affecting versions v0.1.0 through v0.3.0 were fixed by commit `3aa58cdaaa97fbb72f8ef4c3609ae425aacaf8bb` (`Fix MongoDB client panic`), which first appears in release `v0.4.0`. However, the unchecked BSON type assertion panic affecting versions v0.1.0 through v0.8.0 remains unfixed as of the advisory date.

GitHub Advisory Database
GitHub Advisory Database
GitHub Advisory Database

Fix: The vulnerability was patched in commit 234d9aa. Users should update to a version after 0.0.12 that includes this patch.

NVD/CVE Database

Fix: The vulnerability was patched in commit 234d9aa. Users should update to a version containing this commit or later.

NVD/CVE Database

Fix: Patched in commit 234d9aa.

NVD/CVE Database
GitHub Advisory Database
GitHub Advisory Database
GitHub Advisory Database
The Guardian Technology
The Verge (AI)
May 18, 2026

Shadow AI refers to unapproved AI tools that employees use at work without IT oversight, often gaining access to corporate data through quick login approvals that bypass traditional security monitoring. The article explains that 80% of employees use unapproved generative AI applications, and most companies lack formal AI governance policies, creating a visibility gap for security teams. The source describes a five-step program to manage this risk by discovering which tools are running, creating employee-friendly policies, and establishing approved alternatives.

Fix: The source explicitly recommends a five-step program: (1) discover all AI tools in use by auditing OAuth (authorization tokens that grant app access to data) connections, scanning for browser extensions, identifying AI features in already-approved tools, and surveying employees; (2) write a practical policy listing approved tools, specifying which data categories (customer records, source code, financial information) should never enter AI tools, confirming data training opt-out status for sensitive tools, and defining a process for requesting new tools; (3-5) [the source text is incomplete and does not provide steps 3-5]. Implement steps 1-2 to give security teams visibility while providing employees a clear approved path for AI tool adoption.

BleepingComputer
May 18, 2026

UK regulators (Ofcom) are requiring social media platforms, messaging services, and online forums to follow stricter rules to prevent the spread of intimate image abuse (sharing private sexual images without consent, sometimes called 'revenge porn') and AI-generated deepfakes (fake videos created with AI to show people doing things they didn't do). This comes after a rise in such harmful content, particularly targeting women and girls, including a spike in deepfakes created with AI tools like Elon Musk's Grok.

Fix: Ofcom said it would change its codes of practice to force service providers to detect and quash intimate image abuse and crack down on AI-generated deepfakes.

The Guardian Technology
May 18, 2026

This is a scoping review (a broad survey of existing research) that examines how small and medium-sized enterprises can prevent and respond to cyber incidents (security breaches and attacks). The paper synthesizes research findings to help SMEs understand best practices for protecting their systems and recovering when attacks occur.

Elsevier Security Journals
CNBC Technology
BBC Technology
GitHub Advisory Database
GitHub Advisory Database