What changed in AI security, Apr 13 to Apr 19, 2026
Apr 13 to Apr 19, 2026 (ISO week 2026-W16). Weeks run Monday to Sunday in UTC.
177 records published, -22 on the previous week: 39 vulnerabilities (-22), 0 incidents (no change), 23 research items (+12), 114 news items (-12), 1 policy item (no change).
Critical and high advisories
Vulnerability records rated critical or high, newest first. Showing 25 of 32.- Critical
GHSA-v38x-c887-992f: Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability
GitHub Advisory Database - High
GHSA-66r7-m7xm-v49h: OpenClaw: QQBot media tags could read arbitrary local files through reply text
GitHub Advisory Database - High
CVE-2026-40352: FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to…
CVE-2026-40352NVD/CVE Database - Critical
CVE-2026-40351: FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses…
CVE-2026-40351NVD/CVE Database - High
GHSA-vfp4-8x56-j7c5: OpenClaw: Exec environment denylist missed high-risk interpreter startup variables
GitHub Advisory Database - High
GHSA-5fw2-mwhh-9947: Flowise: Unauthenticated TTS endpoint accepts arbitrary credential IDs — enables API credit abuse via stored credentials
GitHub Advisory Database - High
GHSA-w47f-j8rh-wx87: Flowise: Public chatflow endpoints return unsanitized flowData including plaintext API keys, passwords, and credential IDs
GitHub Advisory Database - Critical
GHSA-47wq-cj9q-wpmp: Paperclip: Cross-tenant agent API token minting via missing assertCompanyAccess on /api/agents/:id/keys
GitHub Advisory Database - Critical
GHSA-vr7g-88fq-vhq3: Paperclip: OS Command Injection via Execution Workspace cleanupCommand
GitHub Advisory Database - High
GHSA-gqqj-85qm-8qhf: Paperclip: codex_local inherited ChatGPT/OpenAI-connected Gmail and was able to send real email
GitHub Advisory Database - High
GHSA-w8hx-hqjv-vjcq: Paperclip: Malicious skills able to exfiltrate and destroy all user data
GitHub Advisory Database - High
GHSA-f6hc-c5jr-878p: Flowise: resetPassword Authentication Bypass Vulnerability
GitHub Advisory Database - High
GHSA-28g4-38q8-3cwc: Flowise: Cypher Injection in GraphCypherQAChain
GitHub Advisory Database - High
GHSA-x5w6-38gp-mrqh: Flowise: Password Reset Link Sent Over Unsecured HTTP
GitHub Advisory Database - High
GHSA-6f7g-v4pp-r667: Flowise: Unauthenticated OAuth 2.0 Access Token Disclosure via Public Chatflow in Flowise
GitHub Advisory Database - High
GHSA-6r77-hqx7-7vw8: Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains
GitHub Advisory Database - High
GHSA-2x8m-83vc-6wv4: Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure)
GitHub Advisory Database - High
GHSA-xhmj-rg95-44hv: Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox
GitHub Advisory Database - High
GHSA-rh7v-6w34-w2rr: Flowise: File Upload Validation Bypass in createAttachment
GitHub Advisory Database - High
GHSA-cvrr-qhgw-2mm6: Flowise: Parameter Override Bypass Remote Command Execution
GitHub Advisory Database - High
GHSA-4jpm-cgx2-8h37: Flowise: Sensitive Data Leak in public-chatbotConfig
GitHub Advisory Database - High
GHSA-48m6-ch88-55mj: Flowise: Improper Mass Assignment in Account Registration Enables Unauthorized Organization Association
GitHub Advisory Database - Critical
GHSA-9wc7-mj3f-74xv: Flowise: Code Injection in CSVAgent leads to Authenticated RCE
GitHub Advisory Database - High
GHSA-f228-chmx-v6j6: Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using `Pandas`.
GitHub Advisory Database - Critical
CVE-2026-30617: LangChain-ChatChat 0.3.1 contains a remote code execution vulnerability in its MCP STDIO server configuration and…
CVE-2026-30617NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| Model Context Protocol | 9 | 3.3 | +5.8 |
| Prompt injection and jailbreaks | 7 | 2.0 | +5.0 |
| Adversarial machine learning | 4 | 2.3 | +1.8 |
| Deepfakes and impersonation | 4 | 2.5 | +1.5 |
| Coding assistants | 4 | 3.0 | +1.0 |
Research
Peer-reviewed first, then newest. Showing 8 of 23.LLLMs: A Data-Driven Survey of Evolving Research on Limitations of Large Language Models
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)Systematic Literature Review on Differential Privacy in Machine Learning
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)Privacy in Collaborative Deep Learning Systems: A Taxonomy and Archetypes
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)BioGuard: Malicious sample free defense method for biometric classifiers against model extraction attacks
Peer-reviewedElsevier Security JournalsHeterogeneous Privacy-Preserving Federated Learning for Edge Intelligence
Peer-reviewedIEEE Xplore (Security & AI Journals)Defending Against Patch-Based and Texture-Based Adversarial Attacks With Spectral Decomposition
Peer-reviewedIEEE Xplore (Security & AI Journals)Authentication With Passports for Deep RF Sensing Model Protection
Peer-reviewedIEEE Xplore (Security & AI Journals)Query-Efficient Hard-Label Attacks Against Black-Box Image Forgery Localization Model via Reinforcement Learning
Peer-reviewedIEEE Xplore (Security & AI Journals)
Policy and regulation
Newest first.Generated from the AI Sec Watch database at . Every item links to its record.