Agent Stack Security: advisories and exploits for AI-agent packages

High and critical GitHub-reviewed security advisories, and CISA/ENISA "exploited in the wild" listings, for the packages AI agents are built from (LangChain, LlamaIndex, MCP SDKs, OpenAI and Anthropic SDKs, LiteLLM, vLLM, Transformers, Gradio, Langflow and more). Typed, signed events an agent can act on: check a lockfile, pin a version, alert a human. Facts only. Read-only.

Feed: https://agent-security.getvda.ai/feed.atom (Atom, signed with RSS-A).
Or follow every getvda.ai feed in one place, via the RSS-A hub: https://hub.rssa.getvda.ai/g/a546a3426130/feed.atom
Agent Card: https://agent-security.getvda.ai/.well-known/agent-card.json

House rules

Data: GitHub Advisory Database (CC BY 4.0) via osv.dev; CISA Known Exploited Vulnerabilities catalog (CC0); ENISA EU Vulnerability Database. Not affiliated with any of them.

Privacy: we count distinct fetchers of this feed per day from a one-way hash of IP address and user agent that changes every day. No IP address or user agent is stored, and nothing links one day to the next.

Latest