What changed in AI security, Feb 2 to Feb 8, 2026
Feb 2 to Feb 8, 2026 (ISO week 2026-W06). Weeks run Monday to Sunday in UTC.
53 records published, +27 on the previous week: 21 vulnerabilities (+17), 0 incidents (no change), 9 research items (-4), 23 news items (+14), 0 policy items (no change).
Critical and high advisories
Vulnerability records rated critical or high, newest first.- High
CVE-2026-25628: Qdrant arbitrary file append via /logger endpoint
CVE-2026-25628NVD/CVE Database - Critical
CVE-2026-25592: Semantic Kernel .NET SDK arbitrary file write in SessionsPythonPlugin
CVE-2026-25592NVD/CVE Database - High
CVE-2026-25580: Pydantic AI server-side request forgery in URL download via message history
CVE-2026-25580NVD/CVE Database - High
CVE-2026-25640: Pydantic AI web UI path traversal via version query parameter
CVE-2026-25640NVD/CVE Database - Critical
CVE-2026-25725: Claude Code bubblewrap sandbox escape by creating settings.json
CVE-2026-25725NVD/CVE Database - High
CVE-2026-25724: Claude Code deny rules bypassed through symbolic links
CVE-2026-25724NVD/CVE Database - Critical
CVE-2026-25722: Claude Code write protection bypass via cd into protected directories
CVE-2026-25722NVD/CVE Database - Critical
CVE-2025-62616: AutoGPT server-side request forgery in SendDiscordFileBlock via unfiltered URL
CVE-2025-62616NVD/CVE Database - High
GHSA-345p-7cg4-v4c7: @modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
CVE-2026-25536GitHub Advisory Database - High
CVE-2026-24887: Claude Code confirmation prompt bypass via find command
CVE-2026-24887NVD/CVE Database - High
CVE-2026-24052: Claude Code WebFetch trusted domain check bypass via startsWith validation
CVE-2026-24052NVD/CVE Database - Critical
CVE-2026-22778: vLLM information leak of heap address via multimodal endpoint image errors
CVE-2026-22778NVD/CVE Database - Critical
GHSA-x34r-63hx-w57f: Langroid has WAF Bypass Leading to RCE in TableChatAgent
CVE-2026-25481GitHub Advisory Database - High
CVE-2026-0599: A vulnerability in huggingface/text-generation-inference version 3.3.6 allows unauthenticated remote attackers to…
CVE-2026-0599NVD/CVE Database - High
CVE-2025-10279: mlflow world-writable temp directory allows code execution
CVE-2025-10279NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.| Advisory | Exploitation | EPSS | Published |
|---|---|---|---|
| CVE-2026-0599: A vulnerability in huggingface/text-generation-inference version 3.3.6 allows unauthenticated remote attackers to… CVE-2026-0599NVD/CVE Database | Not listed | 29.9% | |
| CVE-2026-22778: vLLM information leak of heap address via multimodal endpoint image errors CVE-2026-22778NVD/CVE Database | Not listed | 11.2% |
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| @ai-sdk/alibaba | npm | Vercel AI SDK | 1.0.0 | |
| pyzotero | PyPI | Model Context Protocol SDK | 1.10.0 | |
| @ai-sdk/moonshotai | npm | Vercel AI SDK | 2.0.0 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| AI agents | 14 | 2.5 | +11.5 |
Research
Peer-reviewed first, then newest. Showing 8 of 9.PROTheft: A Projector-Based Model Extraction Attack in the Physical World
Peer-reviewedIEEE Xplore (Security & AI Journals)A2Net: Affiliation Alignment Networks for Whole-Body Pose Estimation With Vision--Language Models
Peer-reviewedIEEE Xplore (Security & AI Journals)An Evidential Deep Neural Network for Set-Valued Classification and Novelty Detection
Peer-reviewedIEEE Xplore (Security & AI Journals)Evaluating and Mitigating Relationship Hallucinations in Large Vision-Language Models
Peer-reviewedIEEE Xplore (Security & AI Journals)Allies Teach Better Than Enemies: Inverse Adversaries for Robust Knowledge Distillation
Peer-reviewedIEEE Xplore (Security & AI Journals)Toward Real-World Holistic Privacy-Preserving Person Re-Identification
Peer-reviewedIEEE Xplore (Security & AI Journals)Jailbreak and Guard Aligned Language Models With Only Few In-Context Demonstrations
Peer-reviewedIEEE Xplore (Security & AI Journals)Discovering unknown AI misalignments in real-world usage
IndustryOpenAI Alignment Research Blog
Policy and regulation
Newest first.No regulatory or policy records were published in this week.
Generated from the AI Sec Watch database at . Every item links to its record.