When AI Coding Agents Pull the Wrong Dependency: How a Trojaned PyPI Release Against LiteLLM Triggered Autonomous EDR and Stopped a Chain Reaction
Related Vulnerabilities
- CVE-2026-40150: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praison HIGH
- CVE-2026-35670: OpenClaw before 2026.3.22 contains a webhook reply delivery vulnerability that allows attackers to r MEDIUM
- CVE-2026-35668: OpenClaw before 2026.3.24 contains a path traversal vulnerability in sandbox enforcement allowing sa HIGH
- CVE-2026-5994: A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This issue affects the CRITICAL
- CVE-2026-34942: Wasmtime: Panic when transcoding misaligned utf-16 strings MEDIUM
Related Coverage
Threat Actors