When AI Coding Agents Pull the Wrong Dependency: How a Trojaned PyPI Release Against LiteLLM Triggered Autonomous EDR and Stopped a Chain Reaction
Related Vulnerabilities
- CVE-2026-32893: Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, a Reflected Cross-Site Scripting ( MEDIUM
- CVE-2026-40100: FastGPT is an AI Agent building platform. Prior to 4.14.10.3, the /api/core/app/mcpTools/runTool end MEDIUM
- CVE-2026-34483: Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache MEDIUM
- CVE-2026-34941: Wasmtime: Heap OOB read in component model UTF-16 to latin1+utf16 string transcoding MEDIUM
- CVE-2026-6026: A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability aff CRITICAL
Related Coverage
Threat Actors