When AI Coding Agents Pull the Wrong Dependency: How a Trojaned PyPI Release Against LiteLLM Triggered Autonomous EDR and Stopped a Chain Reaction
Related Vulnerabilities
- CVE-2026-3446: When calling base64.b64decode() or related functions the decoding process would stop after encounter N/A
- CVE-2026-40191: ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. N/A
- CVE-2026-40151: PraisonAI is a multi-agent teams system. Prior to 4.5.128, the AgentOS deployment platform exposes a MEDIUM
- CVE-2026-5985: A security flaw has been discovered in code-projects Simple IT Discussion Forum 1.0. The affected el MEDIUM
- CVE-2026-34942: Wasmtime: Panic when transcoding misaligned utf-16 strings MEDIUM
Related Coverage
Threat Actors