Agent Stack Security: advisories and exploits for AI-agent packages
High and critical GitHub-reviewed security advisories, and CISA/ENISA "exploited in the wild" listings, for the packages AI agents are built from (LangChain, LlamaIndex, MCP SDKs, OpenAI and Anthropic SDKs, LiteLLM, vLLM, Transformers, Gradio, Langflow and more). Typed, signed events an agent can act on: check a lockfile, pin a version, alert a human. Facts only. Read-only.
Feed: https://agent-security.getvda.ai/feed.atom (Atom, signed with RSS-A).
Or follow every getvda.ai feed in one place, via the RSS-A hub: https://hub.rssa.getvda.ai/g/a546a3426130/feed.atom
Agent Card: https://agent-security.getvda.ai/.well-known/agent-card.json
House rules
- Read-only: public APIs (osv.dev, CISA KEV, ENISA EUVD), keyless, about one call per source per hour.
- Facts only: ids, package, affected and fixed versions, severity, who lists it as exploited and since when. The GitHub one-line advisory title is quoted (CC BY 4.0); nothing else is copied.
- One entry per advisory and one per exploited CVE, whichever list reports it first. Nothing is edited after publishing.
- Severity is GitHub's; 'exploited' is CISA's or ENISA's listing, never our judgement.
- Not a compliance product. The EU Cyber Resilience Act's reporting duty for actively exploited vulnerabilities starts on 11 September 2026; this feed is a free early-warning signal, not a substitute for a manufacturer's own monitoring.
Data: GitHub Advisory Database (CC BY 4.0) via osv.dev; CISA Known Exploited Vulnerabilities catalog (CC0); ENISA EU Vulnerability Database. Not affiliated with any of them.
Privacy: we count distinct fetchers of this feed per day from a one-way hash of IP address and
user agent that changes every day. No IP address or user agent is stored, and nothing links one day to the next.
Latest
- [HIGH] pydantic-ai: Pydantic AI: Concurrency-limited models can keep their slot when a streamed request ends early
GitHub-reviewed advisory GHSA-6fqq-452j-qhrp (CVE-2026-107286), severity high, for pydantic-ai (PyPI). Affected: pydantic-ai >= 2.10.0, < 2.53.0.
- [HIGH] pydantic-ai: Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): a website visited by the developer can trigger agent runs and server-side tool execution on the local chat endpoint
GitHub-reviewed advisory GHSA-h4xc-3qfq-jf93 (CVE-2026-107295), severity high, for pydantic-ai (PyPI). Affected: pydantic-ai >= 1.34.0, < 1.107.4; >= 2.0.0b1, < 2.28.0.
- [CRITICAL] langflow: Langflow: OS command injection (RCE) via arbitrary command in MCP stdio server configuration
GitHub-reviewed advisory GHSA-w794-rj3p-xv45 (CVE-2026-105697), severity critical, for langflow (PyPI). Affected: langflow >= 1.1.2, < 1.10.3.
- [HIGH] langflow: Langflow has Authenticated Cross-Project File Disclosure via Unscoped MCP Resource Handlers
GitHub-reviewed advisory GHSA-4hmc-cfm3-w43c (CVE-2026-105699), severity high, for langflow (PyPI). Affected: langflow >= 1.6.8, < 1.9.1.
- [HIGH] langflow: Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Write
GitHub-reviewed advisory GHSA-4f6c-2vvp-gw82 (CVE-2026-105741), severity high, for langflow (PyPI). Affected: langflow >= 1.5.0, < 1.10.3.
- [CRITICAL] flowise: Flowise Prompt Injection to RCE and SSRF via CSV/Airtable Agent Python Validator Bypass
GitHub-reviewed advisory GHSA-w7x8-q2gp-5cgg (CVE-2026-73487), severity critical, for flowise (npm). Affected: flowise < 3.1.3.
- [CRITICAL] flowise: Flowise NodeVM sandbox escape via puppeteer allowlist - authenticated RCE and arbitrary file read via Chromium
GitHub-reviewed advisory GHSA-9gvv-qjj3-2p6g (CVE-2026-73483), severity critical, for flowise (npm). Affected: flowise < 3.1.3.
- [HIGH] @modelcontextprotocol/sdk: MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server
GitHub-reviewed advisory GHSA-6qxp-vccf-f47h (CVE-2026-104850), severity high, for @modelcontextprotocol/sdk (npm). Affected: @modelcontextprotocol/sdk >= 1.12.0, < 1.31.0.
- [CRITICAL] langflow: Langflow: PythonREPLComponent executes unsandboxed Python code, enabling authenticated RCE and privilege escalation
GitHub-reviewed advisory GHSA-8qpj-27x8-pwpq (CVE-2026-10561), severity critical, for langflow (PyPI). Affected: langflow < 1.10.1.
- [CRITICAL] langflow: Langflow: Weak Fernet Key via random.seed()
GitHub-reviewed advisory GHSA-jxw3-mjmx-3pqm (CVE-2026-9205), severity critical, for langflow (PyPI). Affected: langflow < 1.10.1.
- [CRITICAL] langflow: Langflow: Unauthenticated Flow Execution via Webhook Authentication Bypass
GitHub-reviewed advisory GHSA-cf6m-vc3m-7cgm (CVE-2026-8505), severity critical, for langflow (PyPI). Affected: langflow >= 1.7.0, < 1.9.1.
- [HIGH] langflow: Langflow: Title Authenticated Remote Code Execution in validate_code via Malicious Decorators Description
GitHub-reviewed advisory GHSA-w584-2h2r-2hvf (CVE-2026-51886), severity high, for langflow (PyPI). Affected: langflow >= 1.7.2, < 1.10.1.
- [HIGH] langflow: Langflow: Prompt injection in Langflow Smart Transform can lead to code execution
GitHub-reviewed advisory GHSA-9fpm-3445-2vx4 (CVE-2026-7700), severity high, for langflow (PyPI). Affected: langflow >= 1.3.0, < 1.10.3.