aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Browse All

All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.

to
Export CSV
9705 items

GHSA-57g9-58c2-xjg3: n8n Has an Arbitrary File Read via Git Node

criticalvulnerability
security
May 14, 2026
CVE-2026-44790

A vulnerability in n8n (a workflow automation tool) allows authenticated users with permission to create or modify workflows to read arbitrary files from the server by injecting malicious commands into the Git node's Push operation. This could potentially give an attacker complete control over the n8n server.

Fix: Upgrade to n8n versions 1.123.43, 2.20.7, or 2.22.1 or later. If upgrading immediately is not possible, temporarily limit workflow creation and editing permissions to trusted users only, or disable the Git node by adding `n8n-nodes-base.git` to the `NODES_EXCLUDE` environment variable (though these workarounds do not fully fix the risk and should only be used short-term).

GitHub Advisory Database

GHSA-c8xv-5998-g76h: n8n: HTTP Request Node Pagination Prototype Pollution to RCE

criticalvulnerability
security
May 14, 2026
CVE-2026-44789

An authenticated user in n8n (a workflow automation tool) could exploit an unvalidated pagination parameter in the HTTP Request node to achieve prototype pollution (a type of attack that corrupts an object used by many parts of a program), potentially leading to RCE (remote code execution, where an attacker can run commands on a system they don't control). This vulnerability requires the attacker to have permission to create or modify workflows.

Defense in depth for autonomous AI agents

infonews
securitysafety

CVE-2026-44484: PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introdu

criticalvulnerability
security
May 14, 2026
CVE-2026-44484

PyTorch Lightning (a framework for training and adjusting AI models) versions 2.6.2 have introduced a credential harvesting mechanism (a way to steal login information), rated as critical severity with a CVSS score (a 0-10 rating of how severe a vulnerability is) of 9.3. The vulnerability allows attackers to gain complete control over the affected system without needing special access or user interaction.

GHSA-7g73-99r4-m4mj: FlowiseAI Vulnerable to Credential Data Leak

highvulnerability
security
May 14, 2026

FlowiseAI has a vulnerability where encrypted credential data (like API keys and passwords) is accidentally exposed when users request credentials using a filter parameter. The code correctly hides this sensitive data when no filter is used, but fails to remove it when filtering by credential name, allowing authenticated users to steal encrypted credentials if they also access the encryption key file stored on the system.

GHSA-9rvc-vf7m-pgm2: FlowiseAI: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape

criticalvulnerability
security
May 14, 2026

FlowiseAI's custom JavaScript function endpoint lacks proper authorization checks, allowing any authenticated user to submit arbitrary code that executes on the server. When the E2B sandbox (an external code execution service) is not configured, the code runs in a NodeVM sandbox (a JavaScript isolation tool) that can be escaped through error object manipulation, giving attackers access to the host system's process and ability to run commands via child_process (the Node.js module for executing system commands).

GHSA-hp26-q66v-q2w7: FlowiseAI has Mass Assignment in Assistant Update Endpoint that Allows Cross-Workspace Resource Reassignment

highvulnerability
security
May 14, 2026

FlowiseAI has a mass assignment vulnerability (a flaw where a server accepts fields it shouldn't let users modify) in its assistant update endpoint that lets authenticated users change server-controlled properties like workspaceId, createdDate, and updatedDate. Because the server lacks proper validation and authorization checks, an attacker can reassign assistants to different workspaces, potentially breaking the isolation between separate workspaces in multi-tenant environments (systems serving multiple independent organizations).

GHSA-m99r-2hxc-cp3q: Flowise has an MCP Security Bypass that Enables RCE

highvulnerability
security
May 14, 2026

Flowise, a tool for building AI applications, has a security vulnerability in its MCP feature (model context protocol, which lets AI tools run system commands) that allows attackers to bypass command restrictions and execute arbitrary code. The vulnerability has three bypass methods: the 'docker build' command isn't blocked (allowing remote code execution through malicious Dockerfiles), the 'npx --yes' long parameter isn't blocked (allowing installation of malicious packages), and a third unspecified method. Any Flowise user can exploit this if the system has docker or npx installed.

GHSA-php6-83fg-gw3g: FlowiseAI Exposes Basic Auth Credentials via API

highvulnerability
security
May 14, 2026

FlowiseAI's checkBasicAuth endpoint (a feature that checks login credentials) has a security flaw where it accepts plaintext passwords without rate limiting (restrictions on how many login attempts are allowed), making it vulnerable to brute-force attacks (where attackers try many password combinations rapidly). The endpoint also reveals whether a username exists by returning different success and failure messages, and uses direct string comparison instead of constant-time comparison (a timing-attack-resistant method that takes the same time regardless of where strings differ).

GHSA-5wxp-qjgq-fx6m: FlowiseAI has Mass Assignment in Chatflow Update Endpoint that Allows Cross-Workspace AgentFlow Reassignment

highvulnerability
security
May 14, 2026
CVE-2026-42863

FlowiseAI has a mass assignment vulnerability (a flaw where an attacker can modify server-controlled fields by including them in their input) in its chatflow update endpoint that allows authenticated users to change protected properties like workspaceId, deployed status, and visibility settings. An attacker can reassign chatflows to other workspaces and modify deployment or visibility settings without authorization because the server doesn't validate which fields should be editable.

GHSA-x5v6-pj28-cwwm: FlowiseAI has Mass Assignment in Tool Update Endpoint that Allows Cross-Workspace Resource Reassignment

highvulnerability
security
May 14, 2026
CVE-2026-42862

FlowiseAI has a mass assignment vulnerability (a security flaw where an attacker can modify fields they shouldn't be able to change) in its tool update endpoint that allows authenticated users to reassign tools to different workspaces by manipulating the workspaceId field in their requests. The server fails to validate which properties users can modify, allowing attackers to change server-controlled fields like workspaceId, createdDate, and updatedDate, which breaks tenant isolation (the security boundary that keeps different users' data separate) in multi-workspace environments.

GHSA-6fw7-3q8r-m5vj: FlowiseAI has Mass Assignment in Variable Update Endpoint that Allows Cross-Workspace Resource Reassignment

highvulnerability
security
May 14, 2026
CVE-2026-42861

FlowiseAI has a mass assignment vulnerability (a flaw where an application accepts unintended user input to modify server-controlled data) in its variable update endpoint that lets authenticated users change internal fields like workspaceId, createdDate, and updatedDate. Because the server doesn't properly validate or check permissions, attackers can reassign variables to different workspaces, potentially breaking tenant isolation (the separation that keeps different organizations' data separate in shared systems).

GHSA-9vcr-g537-3w5v: Fleet vulnerable to OS command injection in software packages

mediumvulnerability
security
May 14, 2026
CVE-2026-26191

Fleet has a vulnerability in how it handles software packages (.pkg, .deb, .rpm, .exe, .msi files) during uninstall. When a malicious package is uploaded, its metadata (information about the package) is not properly cleaned before being used to create uninstall scripts, allowing an attacker to run arbitrary commands (any code they want) with high privileges (root on macOS/Linux, SYSTEM on Windows) when the uninstall is triggered.

Benchmarking Deepfake Attacks on Deep Face Recognition Systems

inforesearchPeer-Reviewed
security

PVLM: Parsing-Aware Vision-Language Model With Dynamic Contrastive Learning for Zero-Shot Deepfake Attribution

inforesearchPeer-Reviewed
research

GHSA-2rc4-7jc6-qffh: Fleet has a Windows MDM management endpoint authentication bypass

highvulnerability
security
May 14, 2026
CVE-2026-23998

Fleet, a device management system, had a security flaw in its Windows MDM (mobile device management, a system for controlling and configuring devices) endpoint where requests without proper client certificates (digital credentials proving a device's identity) were incorrectly accepted as trusted. An attacker who knew a valid device's identifier could impersonate that device and receive sensitive configuration data like Wi-Fi passwords or VPN settings intended for the real device.

Work with Codex from anywhere

infonews
industry
May 14, 2026

Codex, an AI coding assistant, is now available in the ChatGPT mobile app, allowing users to manage and guide AI-assisted coding work from their phones while Codex runs on their laptops or remote machines. The mobile app lets users review outputs, approve commands, answer questions, and provide direction to Codex in real time from anywhere, with a secure relay layer (an encrypted connection system) protecting machines from direct internet exposure while syncing updates between devices.

Establishing AI and data sovereignty in the age of autonomous systems

infonews
policyindustry

Data readiness for agentic AI in financial services

infonews
industry
May 14, 2026

Agentic AI (systems that can independently plan and take actions to complete tasks) offers significant potential for financial services, but its success depends primarily on the quality, security, and accessibility of its underlying data rather than the sophistication of the AI itself. Financial services companies must establish centralized, well-indexed, and secure data stores that can be searched and managed at scale, while ensuring all data processes are auditable and explainable to meet regulatory requirements and avoid errors like hallucinations (false or made-up information from the AI).

The Download: deepfake porn’s stolen bodies and AI sharing private numbers

infonews
safetyprivacy
Previous230 / 486Next

Fix: The issue has been fixed in n8n versions 1.123.43, 2.20.7, and 2.22.1. Users should upgrade to one of these versions or later. If upgrading is not immediately possible, administrators can temporarily: (1) limit workflow creation and editing permissions to fully trusted users only, or (2) disable the HTTP Request node by adding `n8n-nodes-base.httpRequest` to the `NODES_EXCLUDE` environment variable. The source notes these workarounds do not fully remediate the risk and should only be short-term measures.

GitHub Advisory Database
May 14, 2026

Autonomous AI agents (AI systems that can independently take actions like modifying data or triggering workflows) face unique security risks because their mistakes spread faster and are harder to undo than errors in regular software. The source recommends "defense in depth," which means using multiple overlapping security layers: the model layer (how the AI reasons), the safety system layer (runtime protections like content filtering and logging), the application layer (what actions the agent is allowed to take), and the positioning layer (how the system is presented to users), with the application layer being most critical because developers have full control over it.

Fix: The source recommends a specific design pattern: "Design agents like microservices" by limiting action scope and avoiding "everything agents" (single agents with broad permissions and many tools). The text states that "every additional tool expands the attack surface" and developers should carefully decide "which actions an agent is allowed to take, which tools and data it can access, how permissions are scoped and enforced, how failures are handled, and when humans must be involved."

Microsoft Security Blog
NVD/CVE Database
GitHub Advisory Database
GitHub Advisory Database
GitHub Advisory Database
GitHub Advisory Database

Fix: The source text provides recommendations but does not describe an implemented fix or version update. The recommendations listed are: 1) Implement rate limiting on this endpoint, 2) Use constant-time comparison to prevent timing attacks, 3) Consider using hashed comparison, 4) Return generic error messages, 5) Add logging for failed attempts. No specific patch version or deployed mitigation is mentioned in the source.

GitHub Advisory Database
GitHub Advisory Database
GitHub Advisory Database
GitHub Advisory Database

Fix: The source mentions two workarounds but no explicit fix or patch version: (1) avoid uploading software packages from untrusted or unverified sources, and (2) manually inspect and edit auto-generated uninstall scripts before deployment. An immediate upgrade is referenced as an option, but no specific patched version number is provided in this text.

GitHub Advisory Database
research
May 14, 2026

Researchers created a testing framework to evaluate how deepfakes (AI-generated fake videos or images of people) can fool face recognition systems (AI that identifies people by their faces). The study found that deepfake attacks succeed over 70% of the time, sometimes exceeding 90%, and discovered that attack success depends more on how well attackers can control the person's identity in the fake content rather than on how realistic the deepfake looks visually.

IEEE Xplore (Security & AI Journals)
security
May 14, 2026

This research paper introduces PVLM, a new method for identifying which AI system created a deepfake (fake video or image of a person's face) by analyzing how well different generators preserve facial features. The approach combines vision-language models (AI systems that understand both images and text) with face parsing (analyzing individual facial components) and dynamic contrastive learning (a training technique that groups similar items together while separating different ones) to better recognize deepfakes from unseen advanced generators like diffusion models (AI systems that create images by gradually removing noise).

IEEE Xplore (Security & AI Journals)

Fix: If an immediate upgrade is not possible, affected Fleet users should temporarily disable Windows MDM.

GitHub Advisory Database
OpenAI Blog
May 14, 2026

Companies are shifting away from relying on third-party AI providers because they worry about losing control of their proprietary data and competitive advantage when that data passes through external systems. This movement toward AI and data sovereignty, meaning companies want to build and control their own AI models rather than depend on centralized cloud providers, is now a major business priority, with 70% of executives surveyed believing they need sovereign data and AI platforms to succeed.

MIT Technology Review
MIT Technology Review
May 14, 2026

AI chatbots like Gemini are exposing people's private phone numbers by revealing personally identifiable information (personal details like names and contact info) that was present in their training data, making private contact information much easier for the public to find. Victims have little ability to stop these privacy breaches once their information is already in the AI system.

MIT Technology Review