When AI Coding Agents Pull the Wrong Dependency: How a Trojaned PyPI Release Against LiteLLM Triggered Autonomous EDR and Stopped a Chain Reaction
Related Vulnerabilities
- CVE-2026-40150: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praison HIGH
- CVE-2026-40151: PraisonAI is a multi-agent teams system. Prior to 4.5.128, the AgentOS deployment platform exposes a MEDIUM
- CVE-2026-40153: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the execute_command function in she HIGH
- CVE-2026-3446: When calling base64.b64decode() or related functions the decoding process would stop after encounter N/A
- CVE-2026-6026: A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability aff CRITICAL
Related Coverage
Threat Actors