AgentsLangflow CVE-2026-27966 CVSS 10.0 CSV Agent RCECybersecurity News·high signalXBlueskyLinkedInCopy linkThird CVSS 10.0 agent platform RCE in 6 weeks. Langflow shipped with allow_dangerous_code=True permanently enabled.SourceSource pageCybersecurity News↳ Follow the threadStack layer / Threat patternCVE-2026-31020: DocsGPT renders user-supplied custom prompts through unsandboxed Jinja, giving unauthenticated RCENVDStack layer / Threat patternCodex users are getting 'Cyber Abuse' warnings from OpenAI for security-reviewing their own code, with appeals rejected then reversedr/OpenAI (79 upvotes, 58 comments)Stack layer / Threat patternQwen Code fixes a DingTalk channel that logged clientSecret and stream ticket on connectGitHubThreat pattern / ContrastHanding a coding agent false-positive templates doubles its success at writing CodeQL refinements, from 28% to 56-62%arXiv 2609.04535Policy dependency / Stack layerMoadim Ships an MIT-Licensed Scheduler That Runs Coding Agents on a Cron Instead of a PromptMoadim, via Hacker News Show HNThreat pattern / ContrastTerence Eden: one in five newly registered gTLD domains is a scam, and .LOCKER blocklists at 72.9%Terence Eden (shkspr.mobi), via Simon WillisonPolicy dependency / Stack layerwebmcp-stack Generates Agent Tool Surfaces From an OpenAPI Spec So the Safety Decisions Survive Regenerationwebmcp-stack, via Hacker News Show HN (single source)Policy dependency / Stack layerGraphify 0.9.55 ships eight code-graph correctness fixes, including phantom edges fabricated from symbols that own no nodeGitHub