What changed in AI security, Jun 15 to Jun 21, 2026
Jun 15 to Jun 21, 2026 (ISO week 2026-W25). Weeks run Monday to Sunday in UTC.
186 records published, +16 on the previous week: 68 vulnerabilities (+38), 0 incidents (no change), 15 research items (+3), 102 news items (-25), 1 policy item (no change).
Critical and high advisories
Vulnerability records rated critical or high, newest first. Showing 25 of 33.- High
CVE-2026-56340: vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because…
CVE-2026-56340NVD/CVE Database - High
GHSA-f4xh-w4cj-qxq8: LangSmith SDK TracingMiddleware: Arbitrary server-side file read
GitHub Advisory Database - High
GHSA-mrvx-jmjw-vggc: SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read`
GitHub Advisory Database - High
GHSA-xcqx-9jf5-w339: SearXNG MCP Server: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read`
GitHub Advisory Database - High
GHSA-2fmp-9rvw-hc96: Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning
GitHub Advisory Database - Critical
GHSA-ccv6-r384-xp75: Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
CVE-2026-55447GitHub Advisory Database - High
GHSA-qwqc-p3q8-wcg9: Langflow: Unauthenticated DoS through multipart form boundary file upload
CVE-2026-55446GitHub Advisory Database - Critical
GHSA-qrpv-q767-xqq2: Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
CVE-2026-55255GitHub Advisory Database - High
GHSA-vcv2-r9jh-99m5: Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSync
GitHub Advisory Database - High
GHSA-jv2h-4p9v-wf5w: ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys
GitHub Advisory Database - Critical
GHSA-qw6v-5fcf-5666: Network-AI: Improper Neutralization of Special Elements used in an OS Command
CVE-2026-54051GitHub Advisory Database - Critical
GHSA-r78r-rwrf-rjwp: Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests
CVE-2026-48814GitHub Advisory Database - High
GHSA-fq4x-789w-jg5h: AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridge-wake)
GitHub Advisory Database - High
GHSA-j8cv-x86q-rj85: Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
CVE-2026-54695GitHub Advisory Database - High
GHSA-4pcv-mg8v-vrgf: PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter
GitHub Advisory Database - Critical
GHSA-29w3-p9w9-wc47: PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation
GitHub Advisory Database - High
CVE-2026-12530 - Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()
AWS Security Bulletins - Critical
GHSA-x223-p2gf-v735: Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
CVE-2026-55450GitHub Advisory Database - High
GHSA-2mfg-cc43-9pcj: LangChain4j: SQL injection via metadata filters in langchain4j-mariadb and langchain4j-pgvector
CVE-2026-55405GitHub Advisory Database - Critical
GHSA-4xpc-pv4p-pm3w: LiteLLM: Authentication Bypass via Host Header Injection
CVE-2026-49468GitHub Advisory Database - High
GHSA-qrx8-25qr-5r7v: n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions
CVE-2026-54309GitHub Advisory Database - High
GHSA-42h7-m79w-wvg5: n8n: Stored XSS in Chat Trigger Node
CVE-2026-54302GitHub Advisory Database - High
GHSA-f989-c77f-r2cq: Crawl4AI: LLM credential exfiltration in Docker server via request base_url and env: token resolution
GitHub Advisory Database - High
GHSA-4qqr-vv2q-cmr5: Crawl4AI: SSRF filter bypass in Docker server via IPv6 transition forms (NAT64 / 6to4 / unspecified / v4-mapped)
CVE-2026-53754GitHub Advisory Database - Critical
GHSA-365w-hqf6-vxfg: Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution
GitHub Advisory Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.| Advisory | Exploitation | EPSS | Published |
|---|---|---|---|
| GHSA-qrpv-q767-xqq2: Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow CVE-2026-55255GitHub Advisory Database | Known exploited | 0.9% |
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| languagebind | PyPI | Hugging Face Hub / Transformers | 0.1.0 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| AI agents | 23 | 17.0 | +6.0 |
| Inference infrastructure | 9 | 3.0 | +6.0 |
| AI regulation and standards | 3 | 0.8 | +2.3 |
| Prompt injection and jailbreaks | 4 | 2.3 | +1.8 |
| Coding assistants | 4 | 2.5 | +1.5 |
Research
Peer-reviewed first, then newest. Showing 8 of 15.SALT: Semantic-guided adaptive latent space truncation sampling watermarking for diffusion models
Peer-reviewedElsevier Security JournalsProtecting Against Unauthorized Dataset Use in Fine-Tuning Text-to-Image Diffusion Models
Peer-reviewedIEEE Xplore (Security & AI Journals)NOAE: Noise-Optimized Adversarial Examples for Multivariate Time Series Anomaly Detection of the Industrial Internet of Things
Peer-reviewedIEEE Xplore (Security & AI Journals)MicroPatch: Directed Backdoor Erasing via Victim Parameter Decoupling
Peer-reviewedIEEE Xplore (Security & AI Journals)External Data Extraction Attacks Against Retrieval-Augmented Large Language Models
Peer-reviewedIEEE Xplore (Security & AI Journals)Post-Quantum Secure Semantic Communication With Discrete Latent Representations
Peer-reviewedIEEE Xplore (Security & AI Journals)TabHGIF: A Unified Hypergraph Influence Framework for Efficient Unlearning in Tabular Data
Peer-reviewedIEEE Xplore (Security & AI Journals)Double-Blind Cleanser: Blindly Unlearning Backdoors Without Clean Data
Peer-reviewedIEEE Xplore (Security & AI Journals)
Policy and regulation
Newest first.Generated from the AI Sec Watch database at . Every item links to its record.