When AI Coding Agents Pull the Wrong Dependency: How a Trojaned PyPI Release Against LiteLLM Triggered Autonomous EDR and Stopped a Chain Reaction
Related Vulnerabilities
- CVE-2026-4977: The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for W MEDIUM
- CVE-2026-40153: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the execute_command function in she HIGH
- CVE-2026-6026: A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability aff CRITICAL
- CVE-2026-40217: LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting HIGH
- CVE-2026-39304: Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, HIGH
Related Coverage
Threat Actors