When AI Coding Agents Pull the Wrong Dependency: How a Trojaned PyPI Release Against LiteLLM Triggered Autonomous EDR and Stopped a Chain Reaction
Related Vulnerabilities
- CVE-2026-4664: The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authentication bypass in MEDIUM
- CVE-2026-4977: The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for W MEDIUM
- CVE-2026-35195: Wasmtime has out-of-bounds write or crash when transcoding component model strings MEDIUM
- CVE-2026-40160: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, web_crawl's httpx fallback path pas HIGH
- CVE-2026-5466: wolfSSL's ECCSI signature verifier `wc_VerifyEccsiHash` decodes the `r` and `s` scalars from the sig HIGH
Related Coverage
Threat Actors