The AI Supply Chain is Actually an API Supply Chain: Lessons from the LiteLLM Breach
The recent supply chain attack involving Mercor and the LiteLLM vulnerability serves as a massive wake-up call for enterprise security teams. While the security industry has spent the last year fixati...
Related Vulnerabilities
- CVE-2026-40168: Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vu HIGH
- CVE-2026-35650: OpenClaw before 2026.3.22 contains an environment variable override handling vulnerability that allo HIGH
- CVE-2026-40154: PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI treats remotely fetched templat CRITICAL
- CVE-2026-40252: FastGPT is an AI Agent building platform. Prior to 4.14.10.4, Broken Access Control vulnerability (I N/A
- CVE-2026-40217: LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting HIGH
Related Coverage
Threat Actors