What changed in AI security, Mar 23 to Mar 29, 2026
Mar 23 to Mar 29, 2026 (ISO week 2026-W13). Weeks run Monday to Sunday in UTC.
160 records published, +3 on the previous week: 48 vulnerabilities (+15), 0 incidents (no change), 14 research items (-11), 97 news items (no change), 1 policy item (-1).
Critical and high advisories
Vulnerability records rated critical or high, newest first. Showing 25 of 32.- High
CVE-2026-5002: PromtEngineer localGPT injection in LLM Prompt Handler via remote attack
CVE-2026-5002NVD/CVE Database - High
GHSA-frv4-x25r-588m: Giskard Agents have Server-side template injection via ChatWorkflow.chat() using non-sandboxed Jinja2 Environment
CVE-2026-34172GitHub Advisory Database - Critical
CVE-2026-33873: Langflow arbitrary Python execution through Agentic Assistant validation
CVE-2026-33873NVD/CVE Database - High
CVE-2026-33654: nanobot indirect prompt injection through email channel processing
CVE-2026-33654NVD/CVE Database - High
CVE-2026-31945: LibreChat server-side request forgery in agent actions and MCP
CVE-2026-31945NVD/CVE Database - High
CVE-2026-31943: LibreChat SSRF protection bypass via IPv4-mapped IPv6 addresses
CVE-2026-31943NVD/CVE Database - High
GHSA-qh6h-p6c9-ff54: LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions
CVE-2026-34070GitHub Advisory Database - High
GHSA-8c4j-f57c-35cf: Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
CVE-2026-34046GitHub Advisory Database - High
GHSA-3p2m-h2v6-g9mx: @mobilenext/mobile-mcp alllows arbitrary file write via Path Traversal in mobile screen capture tools
CVE-2026-33989GitHub Advisory Database - High
GHSA-vphc-468g-8rfp: Azure Data Explorer MCP Server: KQL Injection in multiple tools allows MCP client to execute arbitrary Kusto queries
CVE-2026-33980GitHub Advisory Database - High
GHSA-jjp7-g2jw-wh3j: Open WebUI's process_files_batch() endpoint missing ownership check, allows unauthorized file overwrite
CVE-2026-28788GitHub Advisory Database - High
CVE-2026-30304: AI Code terminal command execution bypassed via prompt injection
CVE-2026-30304NVD/CVE Database - High
CVE-2026-29871: awesome-llm-apps path traversal in stream-audio endpoint of FastAPI backend
CVE-2026-29871NVD/CVE Database - High
CVE-2026-33718: OpenHands command injection in git diff endpoint path parameter
CVE-2026-33718NVD/CVE Database - High
CVE-2026-27893: vLLM remote code execution through hardcoded trust_remote_code in model loading
CVE-2026-27893NVD/CVE Database - High
GHSA-7xr2-q9vf-x4r5: OpenClaw: Symlink Traversal via IDENTITY.md appendFile in agents.create/update (Incomplete Fix for CVE-2026-32013)
GitHub Advisory Database - High
CVE-2026-33622: PinchTab arbitrary JavaScript execution through POST /wait fn mode
CVE-2026-33622NVD/CVE Database - High
GHSA-cxmw-p77q-wchg: OpenClaw: Arbitrary code execution via unvalidated WebView JavascriptInterface
GitHub Advisory Database - High
GHSA-xrf2-5r3p-5wgj: libcrux: Panic in Signature Hint Decoding During Verification
GitHub Advisory Database - High
GHSA-jfjg-vc52-wqvf: BentoML has Dockerfile Command Injection via system_packages in bentofile.yaml
CVE-2026-33744GitHub Advisory Database - High
GHSA-fxcw-h3qj-8m8p: n8n Has External Secrets Authorization Bypass in Credential Saving
CVE-2026-33722GitHub Advisory Database - High
GHSA-m63j-689w-3j35: n8n is Vulnerable to Credential Theft via Name-Based Resolution and Permission Checker Bypass in Community Edition
CVE-2026-33663GitHub Advisory Database - High
GHSA-647h-p824-99w7: @grackle-ai/mcp has a workspace authorization bypass in its knowledge_search MCP tool
GitHub Advisory Database - High
GHSA-xvh5-5qg4-x9qp: n8n has In-Process Memory Disclosure in its Task Runner
CVE-2026-27496GitHub Advisory Database - Critical
GHSA-5mg7-485q-xm76: Two LiteLLM versions published containing credential harvesting malware
GitHub Advisory Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| @n8n/agents | npm | Model Context Protocol SDK, Vercel AI SDK | 0.1.0 | |
| unclecode-litellm | PyPI | OpenAI SDK | 1.81.13 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| Inference infrastructure | 4 | 0.3 | +3.8 |
| Adversarial machine learning | 5 | 1.8 | +3.3 |
| AI agents | 20 | 19.0 | +1.0 |
Research
Peer-reviewed first, then newest. Showing 8 of 14.One Trigger, Multiple Victims: Clean-Label Neighborhood Backdoor Attacks on Graph Neural Networks
Peer-reviewedIEEE Xplore (Security & AI Journals)GDetox: Purifying Backdoor Encoder in Graph Self-Supervised Learning via Knowledge Distillation
Peer-reviewedIEEE Xplore (Security & AI Journals)Component-Specific Prompt Tuning for Deepfake Detection
Peer-reviewedIEEE Xplore (Security & AI Journals)PadNet: Defending Neural Networks Against Adversarial Examples
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)Propose and Rectify: A Forensics-Driven MLLM Framework for Image Manipulation Localization
Peer-reviewedIEEE Xplore (Security & AI Journals)Assessing and Improving DNN Robustness Against Adversarial Examples From the Perspective of Fully Connected Layers
Peer-reviewedIEEE Xplore (Security & AI Journals)Filter, Obstruct, and Dilute: Defending Against Backdoor Attacks on Semi-Supervised Learning
Peer-reviewedIEEE Xplore (Security & AI Journals)Multiobjective Simulated Annealing-Based Stopwords Substitution for Rubbish Text Attack
Peer-reviewedIEEE Xplore (Security & AI Journals)
Policy and regulation
Newest first.Generated from the AI Sec Watch database at . Every item links to its record.