Eight Langflow CVEs Arrived Self-Scored and Invisible to Scanners
IBM published eight vulnerabilities against its own AI workflow builder in under a second, two of them critical, with the fixes already shipped weeks earlier as bug fixes.
1d ago

IBM published eight vulnerabilities against its own AI workflow builder in under a second, two of them critical, with the fixes already shipped weeks earlier as bug fixes.
1d ago

A single research batch published against Qwen-Agent, Portkey, Quivr, VoltAgent and gpt-crawler. Seven of the nine name no fixed version at all.
1d ago

The UniBLEed disclosure went out at 16:13 UTC on 27 August with two CVEs published four hours later. One chain runs over an unauthenticated WebRTC-to-DDS bridge on TCP 9991; the other goes in over Bluetooth with no pairing at all.
2d ago

Six CVEs against Agno, LiteLLM, gpt-researcher, crewai-tools and PentestGPT were filed 0.74 seconds apart on 27 August. Every one of them has an empty CVSS block — so an unauthenticated RCE and a leaked telemetry key enter the database as equals.
2d ago

The MCP block runs CVE-2026-81091 to 81102 — Dropbox, ByteDance, Airtable, Telnyx, Timescale, Apify, Harvard, mcp-go, mcp-use, mcp-router, rails-mcp-server. Every fix had already been merged, in one case 161 days earlier.
2d ago

CVE-2026-18252 is untrusted-input inclusion: the agent read configuration from a place the user controls. Full details stay embargoed for around 30 days.
3d ago

Thirteen reporters, one contiguous block of identifiers, and three advisories describing the same bug at 8.6, at 7.3, and with no score at all.
4d ago

The maintainers stopped supporting the feature. They did not remove the code. Every scanner reading the older record's fixed-version field marks a live sink as clean.
5d ago

The parser and the shell disagree about what $HOME is, and the safety model is a list of scary strings. The bug report has been open 36 days with no maintainer reply.
5d ago

An incomplete fix for a 2025 SSRF, reachable because the standard library does not classify CGNAT space as internal.
6d ago

The RPC server takes a function pointer off the socket. The more serious of the two has no fix in the tree at all.
6d ago

CVE-2026-78062 covers a hard-coded authentication secret in TaxHacker. VulDB scored it 5.5 under CVSS 4.0 and 7.3 under CVSS 3.1, and the maintainer has not responded.
Aug 23, 2026

A CVE record is a bookkeeping event, not a disclosure. Scanners key off it anyway, which is how a four-month-old patch becomes Monday's critical alert.
Aug 22, 2026

CVE-2026-72848 carries the tag "unsupported when assigned", and GitHub's advisory lists the patched version as unknown. There is no fix to apply.
Aug 21, 2026

Both advisories went out on 19 August against versions below 0.10.0 — which reached PyPI on 11 June. Fourteen releases have shipped since.
Aug 20, 2026

CVE-2026-47729 sat in Squid's FTP parser since January 1997, leaking strangers' credentials from heap memory. Researchers found it three times in three months — one team with Claude Mythos reading the code.
Jul 7, 2026
