What changed in AI security, Mar 2 to Mar 8, 2026
Mar 2 to Mar 8, 2026 (ISO week 2026-W10). Weeks run Monday to Sunday in UTC.
200 records published, +7 on the previous week: 40 vulnerabilities (+18), 0 incidents (no change), 22 research items (+13), 138 news items (-24), 0 policy items (no change).
Critical and high advisories
Vulnerability records rated critical or high, newest first. Showing 25 of 26.- High
CVE-2026-30834: PinchTab server-side request forgery in /download endpoint
CVE-2026-30834NVD/CVE Database - Critical
GHSA-8w32-6mrw-q5wv: WeKnora Vulnerable to Remote Code Execution via SQL Injection Bypass in AI Database Query Tool
CVE-2026-30860GitHub Advisory Database - High
GHSA-2f4c-vrjq-rcgv: WeKnora has Broken Access Control - Cross-Tenant Data Exposure
CVE-2026-30859GitHub Advisory Database - Critical
GHSA-ccj6-79j6-cq5q: WeKnora Vulnerable to Broken Access Control in Tenant Management
CVE-2026-30855GitHub Advisory Database - High
GHSA-5f53-522j-j454: Flowise Missing Authentication on NVIDIA NIM Endpoints
CVE-2026-30824GitHub Advisory Database - High
GHSA-cwc3-p92j-g7qm: Flowise has IDOR leading to Account Takeover and Enterprise Feature Bypass via SSO Configuration
CVE-2026-30823GitHub Advisory Database - High
GHSA-mq4r-h2gh-qv7x: Flowise Allows Mass Assignment in `/api/v1/leads` Endpoint
CVE-2026-30822GitHub Advisory Database - High
GHSA-j8g8-j7fc-43v6: Flowise has Arbitrary File Upload via MIME Spoofing
CVE-2026-30821GitHub Advisory Database - High
GHSA-wvhq-wp8g-c7vq: Flowise has Authorization Bypass via Spoofed x-request-from Header
CVE-2026-30820GitHub Advisory Database - High
GHSA-g8r9-g2v8-jv6f: GitHub Copilot CLI Dangerous Shell Expansion Patterns Enable Arbitrary Code Execution
CVE-2026-29783GitHub Advisory Database - High
CVE-2026-28795: OpenChatBI path traversal in save_report through file_format parameter
CVE-2026-28795NVD/CVE Database - High
CVE-2026-28677: OpenSift URL ingest pipeline server-side request forgery via remote URLs
CVE-2026-28677NVD/CVE Database - High
CVE-2026-28676: OpenSift path injection in storage helper file read, write and delete
CVE-2026-28676NVD/CVE Database - High
CVE-2026-0848: NLTK arbitrary code execution through StanfordSegmenter JAR loading
CVE-2026-0848NVD/CVE Database - High
CVE-2026-28353: Trivy Vulnerability Scanner VS Code extension distributed with malicious code
CVE-2026-28353NVD/CVE Database - High
CVE-2026-25750: LangSmith Studio URL parameter injection leaking bearer tokens via crafted link
CVE-2026-25750NVD/CVE Database - High
GHSA-5hwf-rc88-82xm: Fickling missing RCE-capable modules in UNSAFE_IMPORTS
GitHub Advisory Database - High
GHSA-vvjh-f6p9-5vcf: OpenClaw Canvas Authentication Bypass Vulnerability
GitHub Advisory Database - High
CVE-2026-0847: NLTK arbitrary file read through path traversal in CorpusReader classes
CVE-2026-0847NVD/CVE Database - High
GHSA-x2ff-j5c2-ggpr: OpenClaw: Slack interactive callbacks could skip configured sender checks in some shared-workspace flows
GitHub Advisory Database - High
GHSA-659f-22xc-98f2: OpenClaw hook transform path containment missed symlink-resolved escapes
GitHub Advisory Database - High
GHSA-m6w7-qv66-g3mf: BentoML Vulnerable to Arbitrary File Write via Symlink Path Traversal in Tar Extraction
CVE-2026-27905GitHub Advisory Database - High
GHSA-943q-mwmv-hhvh: OpenClaw: Gateway /tools/invoke tool escalation + ACP permission auto-approval
GitHub Advisory Database - High
GHSA-jq4x-98m3-ggq6: OpenClaw Canvas Path Traversal Information Disclosure Vulnerability
GitHub Advisory Database - High
GHSA-vmwq-8g8c-jm79: OpenChatBI has a Path Traversal Vulnerability in save_report Tool
GitHub Advisory Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| avidtools | PyPI | OpenAI SDK | 0.3 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| Model and package supply chain | 9 | 2.0 | +7.0 |
| Deepfakes and impersonation | 3 | 0.0 | +3.0 |
| AI agents | 14 | 12.3 | +1.8 |
| Adversarial machine learning | 3 | 1.5 | +1.5 |
| Model Context Protocol | 4 | 3.0 | +1.0 |
Research
Peer-reviewed first, then newest. Showing 8 of 22.The Evolution of AI Compliance Assistance from Reactive Support to Co-Agency
Peer-reviewedAIS eLibrary (Journal of AIS, CAIS, etc.)Stealthy Targeted Poisoning Attacks in Vertical Split Learning via Embedding Model Manipulation
Peer-reviewedIEEE Xplore (Security & AI Journals)ClusterGuard: Secure Clustered Aggregation for Federated Learning With Robustness
Peer-reviewedIEEE Xplore (Security & AI Journals)PrivateEdit: A Privacy-Preserving Pipeline for Face-Centric Generative Image Editing
Peer-reviewedIEEE Xplore (Security & AI Journals)DUAP: Disentanglement-Based Universal Adversarial Perturbations for Robust Multilingual Speech Privacy Protection
Peer-reviewedIEEE Xplore (Security & AI Journals)When Technology Becomes an Ideological Battleground: How Data Ideology Affects Affordance Actualization in People Analytics
Peer-reviewedAIS eLibrary (Journal of AIS, CAIS, etc.)A Fine-Tuning Data Recovery Attack on Generative Language Models via Backdooring
Peer-reviewedIEEE Xplore (Security & AI Journals)Extracting Training Dialogue Data From Large Language Model-Based Task Bots
Peer-reviewedIEEE Xplore (Security & AI Journals)
Policy and regulation
Newest first.No regulatory or policy records were published in this week.
Generated from the AI Sec Watch database at . Every item links to its record.