Fetching from the wire…
Security2026-09-16 · source-backed
PR #24292, merged September 16, fixes a per-device cached compute graph holding raw pointers into backend buffers: a client-issued FREE_BUFFER followed by GRAPH_RECOMPUTE re-executes through dangling pointers. The PR states it's reachable by an unauthenticated remote client and sufficient to leak libc addresses and hijack the buffer iface vtable used by BUFFER_CLEAR. It was reported as GHSA-2phh-px2f-2qmx on April 30 and only submitted publicly now. Anyone running llama.cpp's RPC server on a reachable interface has been exposed since then.
Each link below shares sources, entities, or timing with this story.
PR #28789, merged September 15, found that ggml_backend_rpc_buffer_set_tensor hashed every transfer above the 10 MB threshold and let rpc-server -c serve it from a file cache intended for weights, which also caught the activations ggml_backend_sched copies between backends (Gi...
ChaoMixian/dsh2shell, created August 21, is a Python PoC for unauthenticated remote code execution against dsh web instances reachable on the network (GitHub). It arrives while the plugin ecosystem scales fast, with dshplugin/dsh-plugin-hub advertising 4,000+ community plugins...
IBM's bulletin lists CVE-2026-85025, rated CVSS 9.8, which allows unauthenticated code execution through publicly shared MCP project endpoints in Langflow 1.0.0 through 1.11.5. CVE-2026-78575 and CVE-2026-81941 let authenticated users run OS commands through the MCP stdio serv...
GitHub published four medium-severity vLLM advisories on September 4 against the inference server most self-hosted agent stacks run on. GHSA-pr7f-p5mw-fc87 shows the CVE-2025-62164 remediation can be bypassed using concurrent prompt parts. GHSA-48jh-3gj7-fg8v is a ReDoS throug...
Anthropic's new permanent level indexes to 125 against a 100 baseline, but subscribers have been running at 150 since a temporary 50% boost announced May 13 was extended past July 13, July 19, August 31 and September 13. Both "25% up" and "17% down" are true from different ref...
GHSA-w8wf-3qvj-6xqf and GHSA-2q7j-2vhx-56g8, both high, published September 3, against @openclaw/feishu. Permission tools and general Feishu tools could ignore per-account disablement, so a lower-trust caller performed actions that should have required a stronger check. First...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.