What changed in AI security, Mar 30 to Apr 5, 2026
Mar 30 to Apr 5, 2026 (ISO week 2026-W14). Weeks run Monday to Sunday in UTC.
176 records published, +16 on the previous week: 59 vulnerabilities (+11), 0 incidents (no change), 13 research items (-1), 103 news items (+6), 1 policy item (no change).
Critical and high advisories
Vulnerability records rated critical or high, newest first. Showing 25 of 41.- High
GHSA-5qhv-x9j4-c3vm: @mobilenext/mobile-mcp: Arbitrary Android Intent Execution via mobile_open_url
CVE-2026-35394GitHub Advisory Database - High
GHSA-v959-cwq9-7hr6: BentoML: SSTI via Unsandboxed Jinja2 in Dockerfile Generation
CVE-2026-35044GitHub Advisory Database - High
GHSA-fgv4-6jr3-jgfw: BentoML: Command Injection in cloud deployment setup script
CVE-2026-35043GitHub Advisory Database - Critical
GHSA-jjhc-v7c2-5hh6: LiteLLM: Authentication bypass via OIDC userinfo cache key collision
CVE-2026-35030GitHub Advisory Database - High
GHSA-53mr-6c8q-9789: LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint
CVE-2026-35029GitHub Advisory Database - High
GHSA-3jr7-6hqp-x679: Mesop: Unbounded Thread Creation in WebSocket Handler Leads to Denial of Service
CVE-2026-34824GitHub Advisory Database - Critical
CVE-2026-0545: mlflow job endpoints lack authentication when basic-auth is enabled
CVE-2026-0545NVD/CVE Database - High
GHSA-v3qc-wrwx-j3pw: OpenClaw: Agentic Consent Bypass — LLM Agent Can Silently Disable Exec Approval via `config.patch`
GitHub Advisory Database - High
CVE-2026-34524: SillyTavern path traversal in chat endpoints via avatar_url
CVE-2026-34524NVD/CVE Database - High
CVE-2026-34522: SillyTavern path traversal in /api/chats/import through character_name
CVE-2026-34522NVD/CVE Database - High
GHSA-q56x-g2fj-4rj6: ONNX: TOCTOU arbitrary file read/write in save_external_dat
GitHub Advisory Database - High
GHSA-44c2-3rw4-5gvh: PraisonAI Has SSRF in FileTools.download_file() via Unvalidated URL
CVE-2026-34954GitHub Advisory Database - High
GHSA-r4f2-3m54-pp7q: PraisonAI Has Sandbox Escape via shell=True and Bypassable Blocklist in SubprocessSandbox
CVE-2026-34955GitHub Advisory Database - High
GHSA-x6m9-gxvr-7jpv: PraisonAI: SSRF via Unvalidated api_base in passthrough() Fallback
CVE-2026-34936GitHub Advisory Database - High
GHSA-w37c-qqfp-c67f: PraisonAI: Shell Injection in run_python() via Unescaped $() Substitution
CVE-2026-34937GitHub Advisory Database - Critical
GHSA-6vh2-h83c-9294: PraisonAI: Python Sandbox Escape via str Subclass startswith() Override in execute_code
CVE-2026-34938GitHub Advisory Database - High
GHSA-xw59-hvm2-8pj6: DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost
CVE-2026-34742GitHub Advisory Database - High
CVE-2026-34445: ONNX ExternalDataInfo unsafe attribute setting from model metadata
CVE-2026-34445NVD/CVE Database - High
CVE-2026-27489: Open Neural Network Exchange path traversal via symlink to read arbitrary files
CVE-2026-27489NVD/CVE Database - High
GHSA-ghq9-vc6f-8qjf: TorchGeo Remote Code Execution Vulnerability
CVE-2024-49048GitHub Advisory Database - High
GHSA-jccr-rrw2-vc8h: OpenClaw safeBins jq `$ENV` filter bypass allows environment variable disclosure
GitHub Advisory Database - Critical
GHSA-vv7q-7jx5-f767: FastMCP OpenAPI Provider has an SSRF & Path Traversal Vulnerability
CVE-2026-32871GitHub Advisory Database - High
GHSA-rww4-4w9c-7733: FastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnerabilities
CVE-2026-27124GitHub Advisory Database - High
CVE-2026-34452: Claude SDK for Python memory tool sandbox escape via symlink race
CVE-2026-34452NVD/CVE Database - High
CVE-2026-34451: Claude SDK for TypeScript path traversal in local filesystem memory tool
CVE-2026-34451NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| @langchain/protocol | npm | LangChain | 0.0.1 | |
| @ai-sdk/otel | npm | Vercel AI SDK | 0.0.1-beta.0 | |
| @n8n/mcp-browser | npm | Model Context Protocol SDK | 0.1.0-rc1 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| Model Context Protocol | 9 | 4.5 | +4.5 |
| Inference infrastructure | 5 | 1.3 | +3.8 |
| Prompt injection and jailbreaks | 5 | 2.3 | +2.8 |
Research
Peer-reviewed first, then newest. Showing 8 of 13.A Survey on Recent Advances in Conversational Data Generation
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)AISM: Adversarial image steganography model for defending unauthorized recognition
Peer-reviewedElsevier Security JournalsEvaluating Large Language Models on Named Entity Recognition
Peer-reviewedIEEE Xplore (Security & AI Journals)Erratum: Adversarial Machine Learning in IoT Security: A Comprehensive Survey
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)Seeking Flat Minima Over Diverse Surrogates for Improved Adversarial Transferability: A Theoretical Framework and Algorithmic Instantiation
Peer-reviewedIEEE Xplore (Security & AI Journals)Prompting Frameworks for Large Language Models: A Survey
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)Chat-Scene++: Exploiting Context-Rich Object Identification for 3D LLM
Peer-reviewedIEEE Xplore (Security & AI Journals)Actual Self-disclosure to Anthropomorphic AI Chatbots: A Contextual Privacy Calculus Approach
Peer-reviewedAIS eLibrary (Journal of AIS, CAIS, etc.)
Policy and regulation
Newest first.Generated from the AI Sec Watch database at . Every item links to its record.