When AI Coding Agents Pull the Wrong Dependency: How a Trojaned PyPI Release Against LiteLLM Triggered Autonomous EDR and Stopped a Chain Reaction
Related Vulnerabilities
- CVE-2026-6011: A weakness has been identified in OpenClaw up to 2026.1.26. Affected by this issue is some unknown f MEDIUM
- CVE-2026-4977: The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for W MEDIUM
- CVE-2026-6069: NASM’s disasm() function contains a stack based buffer overflow when formatting disassembly output, HIGH
- CVE-2026-40150: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praison HIGH
- CVE-2026-5479: In wolfSSL's EVP layer, the ChaCha20-Poly1305 AEAD decryption path in wolfSSL_EVP_CipherFinal (and r HIGH
Related Coverage
Threat Actors