AgentsCVE-2026-27966 Langflow CSV Agent RCE CVSS 9.8TheHackerWire·high signalXBlueskyLinkedInCopy linkLangflow CSV Agent hardcodes allow_dangerous_code=True exposing python_repl_ast. CVSS 9.8 critical. Patched v1.8.0. Same eval epidemic vulnerability class.SourceSource pageTheHackerWire↳ Follow the threadPolicy dependency / Stack layerFour advisories land on Databricks' Omnigent meta-harness, one critical, all reported by an autonomous security agentGitHub Security AdvisoriesPolicy dependency / Stack layerCROSS-CATEGORY: Four Unrelated Vendors Shipped Agent Authorization Control Planes Inside 48 HoursJetStream (corroborated by Genesys Xperience 2026 coverage, aiagentstore.ai and Hacker News Show HN)Policy dependency / Stack layerCopilot CLI 1.0.83-4 granted sandboxed file tools access to token-bearing configs like ~/.npmrcGitHubPolicy dependency / Threat patternshadcn shipped cn, a drop-in replacement for tailwind-merge and clsx claiming 30x faster class mergingGitHubStack layer / Threat patternIFM releases K2 Horizon, six Apache-2.0 models from 0.9B to 375B-A23B with the entire training lifecycle opened, not just weightsInstitute of Foundation ModelsStack layer / Threat patternAn MCP Security Auditor Went Up on Apify at $0.25 Per Server, Scanning Five CWE Classes Without Executing CodeApify, via Hacker News Show HNStack layer / Threat patternCVE-2026-71963: Hermes Agent RCE stayed open through six unanswered vendor contactsNVDPolicy dependency / Stack layerTyped Provenance Guardrails Block All 19 Unsafe Releases From a Persistent Agent's Autobiographical MemoryarXiv 2609.02127