Articles tagged AI Security
-
VulnerabilityAutoAgent Code Execution (CVE-2026-86124)
CVE-2026-86124 is a CVSS 9.8 unauthenticated RCE in HKUDS AutoAgent: the sandbox TCP server runs commands as root. VulnCheck KEV-listed Sept. 18, 2026.
-
Vulnerability9 CVEs: CodeWhale & deepseek-tui (CVE-2026-75913)
Nine CodeWhale AI coding-agent CVEs: arbitrary file write, an SSRF bypass, two auto-approved RCE paths, and five more approval-gate and sandbox failures.
-
Vulnerability5 CVEs Across 3 Vendors (CVE-2026-59971)
Five 2026 MCP-server CVEs: unauthenticated SQL execution (CVSS 10) in MySQL MCP Server, a code-execution flaw in functype-mcp-server, and three CKAN issues.
-
Vulnerabilitynuxt-ollama Information Disclosure (CVE-2026-59158)
A CWE-522 credential-exposure flaw in the nuxt-ollama npm package leaks a configured Ollama API key in plaintext to any unauthenticated visitor. Fixed in 1.3.1.
-
Vulnerability2 Ollama CVEs (CVE-2026-7482)
Two Ollama CVEs from 2026: a VulnCheck KEV-listed heap out-of-bounds read (CVSS 9.1) that can leak API keys and user data, plus a lower-severity crash bug.
-
Vulnerability10 CVEs: vLLM & vLLM Hardware Plugin for Intel Gaudi (CVE-2026-73560)
Ten 2026 vLLM CVEs assessed against NVD, GitHub Advisory, and CVE.org data: an SSRF and file-read flaw, a cross-user data leak, and an OpenAI API auth bypass.