Fetching from the wire…
Security2026-09-05 · source-backed
GitHub published four medium-severity vLLM advisories on September 4 against the inference server most self-hosted agent stacks run on. GHSA-pr7f-p5mw-fc87 shows the CVE-2025-62164 remediation can be bypassed using concurrent prompt parts. GHSA-48jh-3gj7-fg8v is a ReDoS through structured_outputs.regex in the lm-format-enforcer backend with no compile timeout. GHSA-hwrm-c4cx-rf4j leaks internal paths and the username through unauthenticated validation errors. Structured outputs are how tool calling gets constrained, so the ReDoS is the one that touches every agent deployment (GitHub Advisories).
Each link below shares sources, entities, or timing with this story.
GHSA-w8wf-3qvj-6xqf and GHSA-2q7j-2vhx-56g8, both high, published September 3, against @openclaw/feishu. Permission tools and general Feishu tools could ignore per-account disablement, so a lower-trust caller performed actions that should have required a stronger check. First...
GitHub published four advisories against omnigent-ai/omnigent v0.1.0, the meta-harness that runs Claude Code, Codex and Pi under policy and sandboxing. GHSA-jrrm-9hc7-2v3h at CVSS 9.0 lets any user with session edit rights overwrite a shared template agent via PUT /sessions/{i...
Splitting the open-issues count via the GitHub search API gives a 1:2.8 ratio where most trending agent repos this week run PR-heavy. Still shipping daily, v1.18.27 on September 2, pushed within the hour. For anyone evaluating it as a base, the backlog shape says user-reported...
NVD posted nine advisories on August 25, clustering into one shape: a local server assuming a browser can't reach it. PraisonAI validated MCP origins with request_origin.startswith(allowed) against a localhost allowlist, so an attacker-registered localhost.attacker.com passes...
CVE-2026-81835 hits fetch_instructions via a malicious MCP server in versions through 3.51.1. The exploit is public. GitHub's advisory GHSA-q2jq-8pm2-fj8h rates it low, NVD scores it 5.5 MEDIUM. (NVD) If your upgrade gating reads GHSA severity only, this one slips through.
Released August 26 with backports to v1.38.13 and v1.37.15 the next day, the vector database now runs its streamable MCP server stateless (GitHub). The same batch adds a DigitalOcean generative module, export and import endpoints for database user API-key hashes, pins a minimu...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.