Advisories
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
44 items
Boxlite, a sandbox service that runs OCI containers inside lightweight virtual machines, does not validate symlink targets when extracting tar entries from OCI image layers. An attacker can publish a crafted image to registries such as DockerHub, and once a user loads it, the attacker can write arbitrary content to any host path, which can lead to remote code execution on the host. The flaw sits in extract_layer_tarball_streaming and apply_oci_layer in boxlite/src/images/archive/tar.rs, and ensure_parent_dirs deliberately preserves symlinks that escape the extraction root.
BoxLite, a sandbox service that runs untrusted code in lightweight VMs and OCI containers, enforces its read_only host mounts only by adding the MS_RDONLY flag after the VM starts. Because the container is not restricted in kernel capabilities, malicious code can remount the directory read-write and modify data that should be read-only, potentially reaching code execution on the host.
NVIDIA Triton Inference Server contains an authentication bypass flaw, tracked as CVE-2026-24207 and classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel). A successful exploit might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure. The NVD has not yet provided its own assessment.
9router exposes unauthenticated endpoints under /api/cli-tools/* and /api/mcp/*, which fall outside the authentication matcher in src/proxy.js. An attacker can POST a custom plugin with an arbitrary command and args to /api/cli-tools/cowork-settings, then GET /api/mcp/[plugin]/sse to trigger spawn() with that command, executing arbitrary OS commands as the user running 9router with no credentials required.
A malicious version, guardrails-ai 0.10.1, was published to PyPI on May 11, 2026 at approximately 6:00 PM Pacific by an attacker. Anyone who installed guardrails-ai==0.10.1 from PyPI that day is affected, and PyPI quarantined the repository after researchers identified the package within about 2 hours. The maintainers report no requests to Guardrails AI infrastructure from the malicious version and no evidence of user data exfiltration through their systems.
The mistralai PyPI package version 2.4.6 contains a malicious dropper that runs on import on Linux. The code was added to src/mistralai/client/__init__.py and was not produced by the project's normal release pipeline, which uses PyPI Trusted Publishing. Versions 2.4.5 and earlier are not known to be affected.
CVE-2026-45829 is a pre-authentication code injection flaw in version 1.0.0 or later of the ChromaDB Python project. An unauthenticated attacker can run arbitrary code on the server by sending a malicious model repository with trust_remote_code set to true to the /api/v2/tenants/{tenant}/databases/{db}/collections endpoint. HiddenLayer assigned a CVSS 4.0 score of 10.0 (Critical), and NIST had not yet provided an assessment.
CVE-2026-9255 is a missing input source validation issue in the tool authorization prompt of Kiro CLI, an AI coding assistant, affecting kiro-cli prior to 1.28.0. A local actor who crafts content piped to kiro-cli via stdin could execute arbitrary tools, including shell commands, without user approval.
Network-AI v5.4.4 defaults the MCP SSE server secret to an empty string (`process.env['NETWORK_AI_MCP_SECRET'] ?? ''` in `bin/mcp-server.ts`), so `_isAuthorized` in `lib/mcp-transport-sse.ts` returns true for every request with no Authorization header. The server also sends `Access-Control-Allow-Origin: *` on every response, letting a cross-origin browser script read results. An attacker who lures a user to a malicious web page can invoke all 22 exposed MCP tools, including `config_set`, `agent_spawn` and `blackboard_write`, against a default-configured localhost server.
LiteLLM versions prior to 1.83.10 let a user change their own user_role through the /user/update endpoint. The endpoint limits updates to the caller's own account but does not restrict which fields can be changed, so a user can set their role to proxy_admin and gain full administrative access, including all users, teams, keys, models, and prompt history. Users with the org_admin role can exploit this without chaining any additional flaw.
Fix: Fixed in 1.83.10.
LiteLLM versions prior to 1.83.14 let an authenticated internal_user create API keys with access to routes their role does not permit. The allowed_routes field is stored without checking that the specified routes fall within the user's own permissions. A key granted admin-only routes can reach them, bypassing role-based access controls and enabling full privilege escalation from internal_user to proxy_admin.
Fix: Fixed in 1.83.14 (LiteLLM versions prior to 1.83.14 are affected).
The mcp-server-kubernetes package exposes ALLOW_ONLY_READONLY_TOOLS, ALLOW_ONLY_NON_DESTRUCTIVE_TOOLS and ALLOWED_TOOLS as access controls, but they are enforced only at tools/list and not at tools/call. Any client that knows a tool name can invoke it directly, so kubectl_delete, exec_in_pod, kubectl_generic and node_management run regardless of the configured restriction, which the advisory says is equivalent to full cluster compromise when the service account has cluster-admin.
Fixed in v3.6.0. The fix applies the same filtering logic from ListToolsRequestSchema at the start of the CallToolRequestSchema handler, returning an error for any tool call outside the active allowed set.
Under certain circumstances, the ModelBuilder/Serve component of Amazon SageMaker Python SDK stores an HMAC signing key in cleartext as the SAGEMAKER_SERVE_SECRET_KEY container environment variable. The DescribeModel, DescribeEndpointConfig, and DescribeModelPackage APIs return this variable in plaintext. A remote authenticated actor with describe permissions and S3 write access to the model artifact path could extract the key, forge integrity signatures for crafted model artifacts, and achieve code execution in inference containers with the SageMaker execution role's IAM permissions. Affected versions are >= v2.199.0 through <= v2.257.1, and >= v3.0.0 through <= v3.7.1.
lmdeploy hardcodes trust_remote_code=True at several HuggingFace Transformers call sites in lmdeploy/archs.py and lmdeploy/utils.py, including AutoConfig.from_pretrained(), PretrainedConfig.get_config_dict() and GenerationConfig.from_pretrained(). Versions lmdeploy <= 0.12.3 are confirmed affected, verified on v0.12.3 and main. An attacker who controls the model_path of a serving process can point it to a malicious HuggingFace repository, and Transformers then executes its remote Python code with the serving process's privileges.
The `diffusers` package's `DiffusionPipeline.from_pretrained` flow contains a time-of-check/time-of-use flaw in its `trust_remote_code` guard. The guard reads `model_index.json` through `hf_hub_download` from one Hub commit, then `snapshot_download` fetches the files, and these two independent calls can resolve to different commits if the repository changes between them. Because the custom pipeline `.py` file is then imported from the newer snapshot, a custom-code load can run without `trust_remote_code=True`, allowing arbitrary code execution.
CVE-2026-24214 is a vulnerability in the DALI backend of NVIDIA Triton Inference Server, classified as CWE-190 (Integer Overflow or Wraparound). An attacker could trigger an integer overflow in that backend. A successful exploit might lead to code execution, data tampering, or denial of service.
NVIDIA Triton Inference Server contains an out-of-bounds read in its DALI backend, tracked as CVE-2026-24213 and classified under CWE-125. According to the source, a successful exploit might lead to code execution, data tampering, denial of service, or information disclosure. NVD has not yet provided an assessment, and the affected software versions are not listed in the source text.
NVIDIA Triton Inference Server contains an integer overflow vulnerability, classified as CWE-190 (Integer Overflow or Wraparound). An attacker could trigger it, and a successful exploit might lead to denial of service. NVD has not yet provided an assessment, and the record was published 05/20/2026.
NVIDIA Triton Inference Server contains a path traversal vulnerability, classified as CWE-22, that an attacker could trigger. The source states that a successful exploit might lead to denial of service. NVD has not yet provided an assessment, and the record was published on 05/20/2026.
NVIDIA Triton Inference Server contains an authentication bypass vulnerability, tracked as CVE-2026-24206 and classified under CWE-288 (Authentication Bypass Using an Alternate Path or Channel). The source states that a successful exploit might lead to privilege escalation, denial of service, or information disclosure. NVD had not yet provided an assessment at the time of publication.
Fix: Downgrade to guardrails-ai==0.10.0, which is unaffected, since no patched version above 0.10.1 is available yet. While the PyPI quarantine is active, install from GitHub with pip install git+https://github.com/guardrails-ai/guardrails.git@v0.10.0. If 0.10.1 was installed, treat the host as potentially compromised, rotate any credentials accessible from it (GitHub PATs, cloud provider keys, package registry tokens, API keys), and audit the GitHub account for unauthorized workflows or repositories. Snowglobe and Guardrails Hub API keys will be invalidated at 2:00 PM Pacific on May 13, 2026, so rotate them before then.
GitHub Advisory DatabaseFix: Pin mistralai to 2.4.5 or earlier. While the PyPI project is quarantined, install from this repository at a known-good tag, e.g. git+https://github.com/mistralai/client-python.git@v2.4.5. On affected Linux hosts, rotate every credential reachable from the importing process and
Fix: Upgrade to Amazon SageMaker Python SDK v2.257.2 or v3.8.0 and rebuild any models previously created with ModelBuilder, since models built with affected versions may still hold the HMAC key in their container environment variables. Patch any forked or derivative code. If upgrading is not immediately possible, manually remove the SAGEMAKER_SERVE_SECRET_KEY environment variable by recreating the model without it in the container environment configuration.
GitHub Advisory Database