When AI Coding Agents Pull the Wrong Dependency: How a Trojaned PyPI Release Against LiteLLM Triggered Autonomous EDR and Stopped a Chain Reaction
Related Vulnerabilities
- CVE-2026-40150: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praison HIGH
- CVE-2026-29043: HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file MEDIUM
- CVE-2026-5994: A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This issue affects the CRITICAL
- CVE-2026-30232: Chartbrew is an open-source web application that can connect directly to databases and APIs and use N/A
- CVE-2026-34942: Wasmtime: Panic when transcoding misaligned utf-16 strings MEDIUM
Related Coverage
Threat Actors