Advisories
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
37 items
CVE-2026-12481 affects keras-team/keras version 3.14.0. The _raise_for_lambda_deserialization() function fails to enforce the safe-mode guard when safe_mode is None, the default outside a SafeModeScope context, because it conflates None with False. This lets attacker-controlled marshal bytecode be deserialized through keras.layers.deserialize(config), keras.models.clone_model(model) and direct Lambda.from_config(config) calls, enabling arbitrary OS-level code execution in the server or user process.
CVE-2026-45499 is a server-side request forgery (CWE-918) in Azure OpenAI. The flaw lets an authorized attacker elevate privileges over a network. Microsoft Corporation is the source, and NVD published the entry on 07/02/2026 with no NVD assessment yet.
CVE-2026-41106 is a URL redirection to untrusted site ('open redirect') flaw, CWE-601, in M365 Copilot. The source says an unauthorized attacker can exploit it over a network to elevate privileges. NVD has not yet provided an assessment, and the NVD published and last modified dates are both 07/02/2026.
All HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, even when MCP_API_KEY or OAuth is configured. An unauthenticated remote attacker can upload content into the memory store, retrieve stored document content, and permanently delete memories belonging to authenticated users. The /api/memories routes enforce authentication, which makes the boundary inconsistent. The source rates it CVSS 9.8 Critical.
CVE-2026-7874 affects IBM Langflow OSS versions 1.0.0 through 1.10.0. The flaw is a weak and reversible key derivation mechanism used for encryption at rest, which could allow disclosure of all stored credentials. The weakness is classified as CWE-338, use of a cryptographically weak pseudo-random number generator, and NVD has not yet provided an assessment.
CVE-2026-7873 affects IBM Langflow OSS versions 1.0.0 through 1.10.0. It allows an authenticated attacker to execute arbitrary OS commands and read sensitive files, including credentials, which enables complete system compromise and lateral movement. The weakness is classified as CWE-94, Improper Control of Generation of Code ('Code Injection'), and NVD has not yet provided its assessment.
CVE-2026-7871 affects IBM Langflow OSS versions 1.0.0 through 1.10.0. A user with Redis access can execute arbitrary code with full application privileges, which compromises all secrets, data, and system integrity. The weakness is classified as CWE-502, Deserialization of Untrusted Data, and NVD has not yet provided its own assessment.
CVE-2026-7803 affects IBM Langflow OSS versions 1.0.0 through 1.10.0. Improper validation of flow nodes that have missing or empty component type fields could allow arbitrary code execution. The weakness is classified as CWE-20, Improper Input Validation, and NVD had not yet provided an assessment when the entry was published on 06/30/2026.
CVE-2026-7663 affects IBM Langflow OSS versions 1.0.0 through 1.9.6. The flaw is improper authorization enforcement in the Streamable MCP transport endpoint, which allows unauthenticated attackers to access protected MCP project resources and execute MCP operations. The weakness is classified as CWE-285 (Improper Authorization), and NVD had not yet provided an assessment at the time of publication.
CVE-2026-10140 affects IBM Langflow OSS versions 1.0.0 through 1.10.0 in voice mode. Improper shared-state handling allows reuse of API clients across tenant boundaries, so an authenticated attacker can manipulate cache state. Requests from other users may then be processed with incorrect upstream API credentials, causing cross-tenant billing and accountability misattribution. The weakness is classified as CWE-639, Authorization Bypass Through User-Controlled Key.
CVE-2026-10134 affects IBM Langflow OSS 1.0.0 through 1.9.3. An attacker can read every secret available to the Langflow process and read and modify every flow, conversation, message, file upload and saved component in the Langflow database. The source also says an attacker can connect to internal services, abuse cloud metadata endpoints, move laterally to other tenants on the same instance, and establish persistence by modifying a public flow's `tool_code`, so that normal `/api/v1/build/...` calls re-execute attacker code.
CVE-2026-58116 affects LLaMA-Factory through 0.9.5. An attacker with WebUI access can execute arbitrary Python code by supplying a malicious model path in the Chat or Training interfaces. The application passes this input unvalidated into AutoTokenizer.from_pretrained() and AutoModel.from_pretrained() with a hardcoded trust_remote_code=True, so the transformers library fetches and runs code from a remote or local model repository with the privileges of the server process.
In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML pass calls AnalysisContext.shorten_code(node) on every import, which marks each import as already reported in the shared reported_shortened_code set. The MLAllowlist pass then receives already_reported=True for every import and skips its allowlist check, so standard library modules outside the UNSAFE_IMPORTS denylist can pass check_safety() as LIKELY_SAFE. Because fickling.load() passes that verdict to pickle.loads(), such a payload is deserialized and executed.
CVE-2025-71372 affects Picklescan before 0.0.33. The scanner fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, so crafted pickle files that execute arbitrary Python code when loaded pass its safety checks. The flaw enables supply-chain poisoning of shared model files. VulnCheck rates it CVSS 4.0 7.6 (HIGH), and NVD has not yet provided an assessment.
CVE-2025-71342 affects picklescan before 0.0.30, which fails to detect malicious pickle files that use idlelib.run.Executive.runcode in reduce methods. Attackers can embed undetected code that executes during pickle.load, enabling remote code execution in PyTorch models and supply chain attacks. VulnCheck rates it CVSS 4.0 7.6 HIGH, and NIST has not yet provided an assessment.
A vulnerability in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0 could allow a remote attacker to perform an indirect prompt injection attack and execute unintended API requests. The weakness is classified as CWE-20, Improper Input Validation, and NVD has not yet provided an assessment.
Weaviate versions before 1.38.0 fail to check whether a principal assigning an RBAC role actually holds the permissions that role grants. The assignRoleToUser and assignRoleToGroup handlers (POST /authz/users/{id}/assign and /authz/groups/{id}/assign) only verify the caller may assign roles, unlike role creation, which limits users to permissions they already hold. A user with only assign_and_revoke_users or assign_and_revoke_groups can assign the built-in admin role or any high-privilege custom role to itself or others, gaining full administrative control of the database.
Grackle's MCP server, `@grackle-ai/mcp` with `@grackle-ai/plugin-core` and `@grackle-ai/auth`, is affected through version 0.132.1 and earlier. Authorization for scoped agent callers is enforced inline per tool and omitted in several mutating tools, such as `task_update`, `task_delete`, `task_resume`, `session_kill` and `session_resume`, so a scoped agent can act on sibling, parent or cross-workspace tasks and sessions. Backend gRPC handlers perform no caller-based authorization, making the MCP tool layer the sole boundary.
The SQLChatAgent in langroid, versions up to and including 0.63.0, uses a regex blocklist (_DANGEROUS_SQL_PATTERNS in sql_chat_agent.py) that omits PostgreSQL's pg_read_file, pg_stat_file, pg_ls_logdir, pg_ls_waldir and related functions, plus SQL Server OPENDATASOURCE and SQLite ATTACH without the DATABASE keyword. Because these payloads are ordinary SELECT statements, they pass the statement-type allowlist and reach the live engine, letting an attacker who can shape the LLM's generated SQL read arbitrary files from the PostgreSQL host, even under the default configuration.
Langroid's ReadFileTool and WriteFileTool in langroid/agent/tools/file_tools.py only change the process working directory to curr_dir and never check that the resolved file_path stays inside it. A tool caller can pass traversal sequences such as ../secret.txt to read, or ../written_by_tool.txt to write, files outside the configured directory. The source's local PoC confirmed both read and write escapes against the current repository checkout.
Fix: Fixed in 1.38.0.