When AI Coding Agents Pull the Wrong Dependency: How a Trojaned PyPI Release Against LiteLLM Triggered Autonomous EDR and Stopped a Chain Reaction
Related Vulnerabilities
- CVE-2026-35670: OpenClaw before 2026.3.22 contains a webhook reply delivery vulnerability that allows attackers to r MEDIUM
- CVE-2026-40150: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praison HIGH
- CVE-2026-6011: A weakness has been identified in OpenClaw up to 2026.1.26. Affected by this issue is some unknown f MEDIUM
- CVE-2026-40217: LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting HIGH
- CVE-2026-5999: A vulnerability has been found in JeecgBoot up to 3.9.1. This impacts an unknown function of the com MEDIUM
Related Coverage
Threat Actors