What changed in AI security, Jun 1 to Jun 7, 2026
Jun 1 to Jun 7, 2026 (ISO week 2026-W23). Weeks run Monday to Sunday in UTC.
165 records published, +37 on the previous week: 27 vulnerabilities (-5), 0 incidents (no change), 8 research items (-3), 127 news items (+43), 3 policy items (+2).
Critical and high advisories
Vulnerability records rated critical or high, newest first.- High
GHSA-pr2w-4gpj-cpq4: Twig: Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points
CVE-2026-47732GitHub Advisory Database - High
CVE-2026-0830 - Command Injection in Kiro GitLab Merge Request Helper
AWS Security Bulletins - High
Amazon Q Developer and Kiro – Prompt Injection Issues in Kiro and Q IDE plugins
AWS Security Bulletins - High
Security Findings in SageMaker Python SDK
AWS Security Bulletins - High
GHSA-7p8g-6c6g-h9w7: praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR
CVE-2026-47419GitHub Advisory Database - High
CVE-2026-11326: OpenAI Atlas before 1.2025.288.15 exposed privileged browser APIs to web content on *.openai.com origins. A cross-site…
CVE-2026-11326NVD/CVE Database - High
CVE-2026-45497: Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an…
CVE-2026-45497NVD/CVE Database - High
GHSA-fgcw-684q-jj6r: huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path
CVE-2026-5241GitHub Advisory Database - Critical
CVE-2026-32625: LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the…
CVE-2026-32625NVD/CVE Database - High
CVE-2026-31942: LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.7.6, an…
CVE-2026-31942NVD/CVE Database - Critical
CVE-2026-47117: OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path. The…
CVE-2026-47117NVD/CVE Database - High
CVE-2026-10591 - Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths
AWS Security Bulletins - High
CVE-2026-3198: MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails to enforce authorization checks for multiple Gateway API…
CVE-2026-3198NVD/CVE Database - High
CVE-2026-43624: F5-TTS through version 1.1.20 contains a path traversal vulnerability in the finetune Gradio handlers that allows…
CVE-2026-43624NVD/CVE Database - High
CVE-2026-38950: An issue in ESA AnomalyMatch before 1.3.1 allow attackers to execute arbitrary code via crafted model checkpoint files…
CVE-2026-38950NVD/CVE Database - High
CVE-2026-10214: A weakness has been identified in zhayujie chatgpt-on-wechat up to 2.0.8. This issue affects the function…
CVE-2026-10214NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| sagemaker-train | PyPI | Strands Agents | 1.13.0 | |
| skypilot-nightly | PyPI | Hugging Face Hub / Transformers | 1.0.0.dev20260602 | |
| @ag-ui/mcp-middleware | npm | Model Context Protocol SDK | 0.0.1 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| AI agents | 22 | 19.0 | +3.0 |
| Prompt injection and jailbreaks | 4 | 1.0 | +3.0 |
| Frontier model safety | 3 | 0.3 | +2.8 |
| Adversarial machine learning | 4 | 2.3 | +1.8 |
Research
Peer-reviewed first, then newest.SemAlign-PFL:Exploring stealthy and persistent backdoor attacks against personalized federated learning
Peer-reviewedElsevier Security JournalsDebapt: Ontology-driven multi-agent debate for APT adversary profile construction from cyber threat intelligence
Peer-reviewedElsevier Security JournalsDeepfake detection with dual-mode swin transformer: Multi-scale feature learning and local ambiguity mitigation
Peer-reviewedElsevier Security JournalsTrigger as Entity: Backdoor Attacks to Graph-Based Retrieval-Augmented Generation of Large Language Models
Peer-reviewedIEEE Xplore (Security & AI Journals)Quality-Guided Forgery Adapter for Generalizable AIGC Image Detection
Peer-reviewedIEEE Xplore (Security & AI Journals)BadBone: Backdoor Attacks Against Backbone Models in Visual Prompt Learning
Peer-reviewedIEEE Xplore (Security & AI Journals)mmGuard: A Countermeasure Against Physical Adversarial Attacks on mmWave Radar Sensing
Peer-reviewedIEEE Xplore (Security & AI Journals)Parameter-Agnostic Privacy-Preserving Machine Unlearning for Large Language Models
Peer-reviewedIEEE Xplore (Security & AI Journals)
Policy and regulation
Newest first.Generated from the AI Sec Watch database at . Every item links to its record.