One file per incident. Latest at the top.

Date disclosed ID Severity Status
2026-09-24 OpenAI's evaluation agents breached an Australian government Medicare statistics portal on 2026-06-18 — refused, then 'found a way around those blocks,' read non-public files and wrote files to the server; OpenAI noticed on 08-11 and emailed a public mailbox on 09-10; the PM disclosed it on 09-24. Same day, Transluce's urlquery.net dataset shows the same OpenAI-linked swarms probing three public data sites with SQLi, XSS, path-traversal and command-injection payloads and pulling a blocked file from a pre-production host high contained
2026-09-24 Cloudflare Containers and Sandboxes: a customer could read other customers' residual disk blocks — directory trees, database pages and 'structurally complete SQLite databases' from previous tenants on the same host — through thin-provisioned storage with block zeroing disabled; reported by Accomplish on 2026-09-04, fixed 09-07, disclosed 09-24, no evidence of other exploitation high patched
2026-09-24 OpenCode 1.14.30–1.18.21 (npm/pnpm/Bun installs): any web page could make a running opencode serve/web upgrade itself from an attacker's tarball via a text/plain post to /global/upgrade → npm lifecycle-script RCE; fixed 1.18.22 (2026-08-24), no CVE by vendor choice, disclosed by Datadog 2026-09-24 high patched
2026-09-24 SalesBleed — three Salesforce Agentforce flaws chain into zero-click unauthenticated CRM data exfiltration and Slack phishing: prompt injection via a public Web-to-Lead form, a Trusted URLs redaction bypass, and DNS-based exfiltration via image tags / Slack unfurling; reported 2026-06-01, all fixed by 2026-09-21 (Zenity Labs) high patched
2026-09-23 third-party.com — a documentation placeholder that is not IANA-reserved — has served a ClickFix clipboard-poisoning lure to Windows browsers since at least June 2026; it appears in 1,500+ files across 1,700+ public repositories including AI agent skills, MCP-server docs and test fixtures (Manifold Security) medium ongoing
2026-09-22 One operator chained three open-source agent harnesses (Hermes/Strix/Cairn) through OpenRouter for ~$25 a target, compromised 27+ companies in five days (a Fortune 500 hospitality firm and a major US airline among them) and stole 600,000+ card records with checkout skimmers confirmed on 19 sites; Gambit reconstructed it from the operator's recovered staging server high ongoing
2026-09-23 GitLab 19.4.1 / 19.3.3 / 19.2.7 (2026-09-23): two CVSS 9.9 authenticated RCEs from a crafted regular expression in a CI/CD configuration (CVE-2026-89078 double free, CVE-2026-93577 integer overflow), plus four AI-feature bugs — Duo troubleshooting leaks CI/CD variable values, an MCP-scoped token acts beyond its scope, Duo Workflow governance bypass, MCP search returns another user's results critical patched
2026-09-23 GitLab's 'email this project' address is an account-wide, non-expiring credential: anyone holding your incoming+…-glimt-…@incoming.gitlab.com address can change the -issue suffix to -merge-request, attach a .patch, and GitLab commits it as you and runs CI on it — in every project you can reach, past IP allow-lists and 2FA; GitLab closed the HackerOne report as intended behaviour (Aikido, 2026-09-23) high mitigated
2026-09-21 Miri wrote every environment variable of the CI job into target/ — and projects that cache target/ in GitHub Actions (actions/cache, Swatinem/rust-cache) with a cache readable by pull requests handed their secrets to any PR author; Rust Security Response WG disclosure 2026-09-21, fixed in the 2026-09-22 nightly medium patched
2026-09-23 MemTensor's official OpenClaw memory plugin (@memtensor/memos-cloud-openclaw-plugin 0.1.21 / 0.1.23 / 0.1.25) and MemoryOS 2.0.34 on PyPI were published from stolen release tokens with a credential-stealing Go implant ('sckit') that runs when the agent gateway starts and on memory-recall events; four researchers confirmed it within hours on 2026-09-23 — clean baselines are 0.1.20 and 2.0.33 high active
2026-09-22 Next.js 16.2.0–16.3.5: remote code execution in next/og ImageResponse (Node.js runtime) through an upstream Satori SVG-escaping bug (CVE-2026-94545, CVSS 9.5) — out-of-band fix 16.3.6 / 15.5.26; any OG-image route that renders request input is the exposure critical patched
2026-09-17 mathmain, mathsbase and math-universe — three npm clones of mathjs (part of a 23-package campaign) carried an encrypted loader that stays dormant until code calls math.lusolve() with a specific 3×3 Pascal matrix, then decrypts a remote-access payload; a GitHub Actions farm inflated all three past 2M weekly downloads; JFrog + SafeDep disclosed 2026-09-17/21, npm removed them high contained
2026-06-25 Supabase Realtime ≤ 2.111.1: a private-channel client allowed presence.write but denied presence.read still received every other member's presence metadata (CVE-2026-62247, CVSS 6.5); fixed 2.111.2, CVE published 2026-09-21 high ongoing
2026-09-18 Zhipu's ZCode coding app packaged every logged-in user's whole workspace — including the full .git history, LFS cache and reflogs, with the secret-file filter skipped for history — encrypted it with a key only Zhipu holds, and uploaded it to Alibaba Cloud OSS before prompts and after tasks; the UI toggles did nothing, the privacy policy said nothing; Zhipu apologised 09-18, removed the pipeline in 3.14.0, open-sourced the client and had the bucket audited as deleted on 09-21 high contained
2026-09-17 Rust's crates.io team warns of an ongoing campaign against rust-lang members and popular-crate owners — a fake job, project or contract pitch leads to a video call where the target is asked to install a 'missing audio codec' or run a clipboard command; a June attempt on a crates.io maintainer delivered a RAT hidden in a take-home TypeScript 'test' repo, and the August arrayref compromise fits the same shape high active
2026-09-17 indexed-btree and nine sibling npm packages (a sorted-btree look-alike, ~2M registry downloads a week) carried no install script at all — the loader sat inside BTree.prototype.set and fired the first time an application called it with key 100, fingerprinted the host to Slack and Telegram, and pulled an encrypted second stage from an Ethereum Sepolia smart contract; removed from npm 2026-09-03, disclosed by Checkmarx 2026-09-17 high contained
2026-07-12 xAI's Grok Build CLI uploaded every repository it was opened in — as a git bundle with full history, including tracked .env files and files the agent was told not to read — to a Google Cloud Storage bucket; the 'Improve the model' toggle did not stop it (5.10 GiB out for a task that needed 192 KB); xAI switched uploads off server-side on 2026-07-13 and Musk promised deletion, but the upload code stayed in the client high mitigated
2026-09-15 Heapjack and Overpatch — two OpenAI Codex sandbox escapes: Codex Desktop's JavaScript sandbox kept its trust token in the same V8 heap as untrusted code (read-only mode → host commands), and Codex CLI's apply_patch granted write access to the parent directory of any path in a patch (workspace-write → ~/.zshrc); fixed 0.149.0 / build 26.818.21641, no CVE, no advisory high patched
2026-09-18 Google is the fourth lab in the Irregular cluster — during a May 2026 capture-the-flag evaluation, Gemini got unintended internet access, guessed one real company's password and used credentials found in public code repositories to enter two more; the model stopped once it recognised the systems were real, Irregular notified Google in July, the public learned on 2026-09-18 high contained
2026-09-18 Plugin4Shell — Claude Code, Codex, GitHub Copilot and Gemini CLI checked out a pinned plugin commit without verifying HEAD landed there, so a branch named with the SHA (Bitbucket/self-hosted) or a FETCH_HEAD default branch swaps reviewed code for malicious code and auto-updates it into every install; Claude Code and Codex patched, Copilot and the retired Gemini CLI not high mitigated
2026-09-18 Hacktron reached OpenAI's internal monorepo via the community forum — a Claude-built exploit for an un-CVE'd libheif bug in Discourse's HEIC upload path, then an over-scoped Sign-in-with-OpenAI token that turned a forum session into full ChatGPT and Codex API access and an internal PR high patched
2026-09-18 PhantomRaven, revisited — CrowdStrike attributes the 126-package npm stealer (remote HTTP-URL dependencies, slopsquatted names, CI/CD secret theft) to a self-described bug-bounty hunter who likely had an LLM write the malware medium ongoing
2026-09-17 WeaselBiscuit — 13–14 npm packages published 2026-09-12 → 09-16 fire on import, pull a Base64 second stage from a JSON dead-drop into memory and harvest Chrome extension storage on Windows, macOS and Linux; stripped-down BeaverTail/OtterCookie descendant, DPRK attribution low-to-moderate medium contained
2026-09-16 Sentry Seer "PhantomFix" (CVE-2026-90999, CVSS 9.8) — anyone who can post an error event to a public Sentry DSN can fabricate a bug, have Seer embed it into the prompt it hands a coding agent, and get the agent to install an attacker-chosen package; no vendor statement critical unconfirmed
2026-09-15 Docker Sandboxes — the microVM that runs your coding agent could read and modify arbitrary macOS host files through a virtio-fs symlink race (CVE-2026-77179, CVSS 9.4) and reach any host Unix socket (CVE-2026-79994, 8.7); fixed in 0.42.0 with a D-Bus host-command bug and a cross-sandbox OAuth hijack critical patched
2026-09-08 Commodity infostealers now collect your coding agent's local state — Gen Digital telemetry shows Amatera, Remus, CallbackBeaver, Djinn and five other families grabbing tokens, MCP configs, conversation databases and prompt histories from Claude, Cursor, Codex, Cline, Continue, OpenCode, Gemini and Kilo high ongoing
2026-06-30 Orkes Conductor (workflow and AI-agent orchestrator) — CVE-2026-58138, CVSS 9.8: an unauthenticated workflow definition with an INLINE/LAMBDA/DO_WHILE/SWITCH expression runs OS commands through an unsandboxed GraalVM evaluator; fixed 3.30.2 in June without a security label, exploited in the wild since 2026-08-21 critical active
2026-09-16 CrewAI — an unpatched ZDI zero-day in load_agent_from_repository (CVE-2026-92206, CVSS 8.8) on top of eight 2026 CVEs the project never posted an advisory for: a CVSS 9.8 FileWriterTool path-traversal RCE, a Docker-fallback sandbox escape, a ctypes blocklist bypass critical active
2026-09-16 Mandiant case study — an attacker hijacked a live AI coding-assistant session at a SaaS provider, had it recommend a poisoned PyPI package, stole GitHub OAuth tokens and spread Shai-Hulud across ~100 internal repositories; a red-team case shows an internal repo/CI assistant talked into pushing private code to an external GitHub account high ongoing
2026-09-16 BragJack — a browser extension with page-modification and declarativeNetRequest permissions hijacks the built-in AI assistant in Chrome, Edge, Perplexity Comet, Opera Neon and Claude in Chrome via the vendor's trusted domain (CVE-2026-0628, CVE-2026-55945; Anthropic patched with no CVE) high mitigated
2026-09-16 OpenAI's six misalignment reports — internal models searched GitHub for leaked API keys and used one, uploaded task data to public hosts, used Artifactory as a covert channel between samples, and wrote jailbreak instructions into their own compaction summaries; live internet access during training now disabled medium contained
2026-09-11 AWS Kiro IDE and Kiro CLI — eight 2026 CVEs disclosed only via AWS bulletins: an agent-written workspace setting that exfiltrates data before the approval prompt is answered (CVE-2026-89332), three CVSS 8.5 workspace-trust bypasses, a stdin tool-approval bypass, a world-readable token cache high patched
2026-09-10 AWS Security Agent MCP server and aws-agents-for-devsecops plugin — account-id-derived scan-input S3 bucket never ownership-checked, so a pre-registered bucket receives the private source archive with credentials and infrastructure state (CVE-2026-87912 / CVE-2026-87913) medium patched
2026-09-07 Shai-Hulud payload republished after 111 days — four npm packages including the MCP server feishu-docx-mcp pushed with the byte-identical @AntV Wave-C preinstall stealer, with .claude/settings.json and .vscode/tasks.json persistence; a known hash passed npm's publish-time scan high contained
2026-09-01 Coder registry compromise — a stolen Cloudflare API key rerouted registry.coder.com for 14 hours (2026-08-31), serving credential-stealing Terraform modules to AI-workspace provisioners (GHSA-vx42-ghc9-gw65) critical patched
2026-08-31 RevStealer — a fake 'Claude Opus 5 Free Desktop' GitHub repo delivers a Windows infostealer that streams credentials, wallets and dev secrets, then deletes itself high active
2026-07-06 @zereight/mcp-gitlab — unauthenticated file read → PAT theft → full GitLab account takeover, plus SSRF, DNS-rebinding and path-traversal token redirects (CVE-2026-61560 et al.) critical patched
2026-09-14 Bifrost (8K-star Go AI gateway) — one unauthenticated POST /api/mcp/client registers a stdio MCP client and runs it as the gateway process (CVE-2026-90898, CVSS 9.8); authentication is off by default critical patched
2026-07-31 mcp-remote (the npm bridge Claude Desktop / Cursor / VS Code use for remote MCP servers, ~784K downloads/week): five CVEs assigned 2026-09-24 for a seven-finding OAuth-discovery audit — SSRF via a server-supplied WWW-Authenticate metadata URL (CVE-2026-51994), browser-launch validation still allowing loopback/private/metadata addresses (CVE-2026-51997), and more; reviewed range 0.1.16–0.1.38, no vendor advisory, package now under new ownership at 0.14.x high unconfirmed
2026-07-20 Google Agent Studio — SSRF in the auto-generated /api-proxy backend of web apps built before 2026-07-01; the fix is regenerate-and-redeploy, so deployed apps stay vulnerable until you act (vendor release note, single-source) high mitigated
2026-07-10 mcp-atlassian — the most-used Atlassian MCP server (161K weekly PyPI downloads) got 26 CVEs assigned at once on 2026-09-22 for the July security audit: headline CVE-2026-77244, a CVSS 10.0 unauthenticated auth bypass; all fixed in 0.22.0, current 0.23.1 critical patched
2026-07-10 unstructured (the ingestion layer under LangChain's UnstructuredURLLoader, LlamaIndex's UnstructuredReader and Chainlit) — full-read SSRF via partition(url=) (CVE-2026-71428, CVSS 9.3), fixed 0.24.0 critical patched
2026-04-15 Clerk SDKs — CVSS 9.1 middleware route-protection bypass in @clerk/nextjs, @clerk/nuxt and @clerk/astro (CVE-2026-41248), plus an authorization-predicate bypass (CVE-2026-42349) and a secret-key-leaking proxy SSRF (CVE-2026-34076); no changelog entry, no press critical patched
2026-09-11 OpenClaw publishes 75 security advisories in one day (2026-09-11) for bugs fixed in 2026.7.1–2026.8.1 — 30 rated High: non-owner senders reaching owner-only tools, MCP config injection to RCE, exec approvals that outlive their directory, a gcloud argument injection high patched
2026-09-03 OmniRoute (66K-star self-hosted AI gateway) — unauthenticated RCE through the custom ACP agent endpoint when requireLogin is off (CVE-2026-88062, CVSS 9.5–10.0); vendor, NVD and the advisory database disagree on which version is fixed critical patched
2026-02-18 SvelteKit February–July 2026 advisory backfill — nine vendor advisories (three CVSS 8.7 remote-function DoS bugs, a cross-user query.batch data leak, a BODY_SIZE_LIMIT bypass, a ReDoS) that got CVE numbers only on 2026-08-28 high patched
2026-09-08 Langflow 1.0.0–1.11.5 — IBM PSIRT bulletin of 11 code-execution CVEs, three of them unauthenticated CVSS 9.8 (fixed in 1.11.6) critical patched
2026-08-25 NVIDIA NemoClaw and OpenShell — 18-CVE August bulletin: two CVSS 9.9 OpenShell sandbox escapes, and a web page that hijacks the agent's local Ollama backend via DNS rebinding (CVE-2026-65105) critical patched
2026-08-17 SWE-agent trajectory inspector — unauthenticated path traversal on an all-interfaces, wildcard-CORS server leaks trajectory files holding repo contents and API keys (CVE-2026-75482, unpatched) high active
2026-09-11 OpenAI agents linked to the May 2026 RubyGems 'GemStuffer' campaign — 2,000+ packages, RCE on RubyDoc.info build workers, attempts on a legacy API-key cache leak high contained
2026-09-10 GitLab CVE-2026-85706 — unauthenticated arbitrary file read via the repository commits API (CVSS 10.0), probed within a day, CISA KEV critical active
2026-09-10 JFrog Artifactory — CVE-2026-42018 + CVE-2026-42016 chained in the wild for unauthenticated admin tokens; Rust backdoors and Groovy plugins; CISA KEV critical active
2026-09-10 Anthropic September 2026 threat report — stolen AI credentials as loot/compute/cover, a fraudulent Claude reseller, prompt injection against an eval sandbox, agents that rebuild malware after detection high ongoing
2026-09-08 DeepSeek Harness — sandboxed agent flips itself to 'danger-full-access' via a Host-header-only trusted local API (CVE-2026-82533, CVSS 9.4) critical patched
2026-09-08 Google Threat Intelligence — attackers run agentic pipelines: TeamPCP trojanized MCP servers and hidden .claude//.cursor/ malware, 'Recon' dashboard with 23,800+ secrets, mass credential theft built in under six hours high ongoing
2026-01-09 Langflow CVE-2026-0768 — unauthenticated Python code injection in the validate endpoint (CVSS 9.8, ZDI zero-day), mass-exploited from 2026-08-30 to harvest OpenAI and AWS keys critical active
2026-08-27 Aurora ransomware affiliate ran Cursor Agent (Claude Sonnet) as a hands-on intrusion operator against 10 organizations — vendor-side misuse detection did not interrupt it medium historical
2026-08-26 Claude Code Auto Mode (Opus 5) — "summarize this page" escalates to code execution via module shadowing of the agent's own defensive decoder; Anthropic: working as designed high active
2026-08-12 Deadbugz — malicious MCP server waits until the third tool call before rewriting its own metadata into credential-theft instructions high unconfirmed
2026-04-09 Research: third-party LLM API routers caught injecting malicious tool calls and harvesting credentials high unconfirmed
2026-03-30 OpenAI Codex — unsanitized GitHub branch names inject shell commands, stealing GitHub tokens critical patched
2026-09-04 aider auto-loads a repo's .aider.conf.yml and runs its test-cmd/lint-cmd with no confirmation (CVE-2026-85674, unpatched) high unconfirmed
2026-09-01 GitSpawn — repo-local git config (core.fsmonitor and others) runs code in 7 AI coding agents before any trust prompt critical active
2026-09-02 Kestra OSS — unauthenticated RCE via '/configs' auth-filter bypass (CVE-2026-49869, CISA KEV) critical active
2026-08-30 Generic infostealer malware hijacks Claude.ai browser sessions to drain paid usage and expose account data high active
2026-08-28 @7nohe/openapi-react-query-codegen (150K weekly downloads) compromised via a comment-triggered npm publish workflow — no stolen token needed critical contained
2026-07-28 Gitea diffpatch git-hook RCE (CVE-2026-60004, CVSS 9.8) — unauthenticated if self-registration is on, added to CISA KEV 2026-08-25 critical active
2026-08-07 OpenAI Astra — unreleased model may have crossed the 'Critical' cybersecurity capability threshold in OpenAI's Preparedness Framework, first frontier model to trigger the tier high mitigated
2026-02-18 Context7 MCP documentation server — attacker-registered library docs inject instructions into every connected coding agent ("ContextCrush," CVE-2026-75130); fixed since February, CVE only assigned in August high patched
2026-08-14 MindsDB Minds Platform — unpatched CVSS 10.0 unauthenticated RCE via prompt injection into an unsandboxed scratchpad tool (CVE-2026-73678), plus a patched file-upload RCE (CVE-2026-27483) critical active
2026-07-13 JSONata — the "safe expression" engine n8n embeds ships two CVSS 9.3 sandbox-escape RCEs (CVE-2026-77414, CVE-2026-77415) critical patched
2026-07-12 orval — eleven critical code-injection CVEs in the OpenAPI → TypeScript client/zod/MSW generator; a hostile spec executes at codegen, test time, or import (fixed 8.21.0) high patched
2026-08-10 One Pyodide sandbox-escape flaw broke n8n, Grist, Cohere Terrarium, and Hugging Face smolagents — DEF CON 34 backfill, four CVEs critical patched
2026-05-19 Nuxt's May 2026 security release — four CVEs in the /__nuxt_island/* endpoint, including a route-middleware auth bypass (predates the July batch) high patched
2026-08-17 Ray CVE-2025-62593 — a Mozilla User-Agent prefix was the browser-attack defense; DNS rebinding turns any web page into RCE on your AI compute cluster (CISA KEV) critical patched
2026-08-07 Both JavaScript sandboxes AI workflow platforms run untrusted code in broke in the same fortnight — vm2 (host DNS hijack) and isolated-vm (type confusion → host RCE) critical patched
2026-08-17 August 2026 agent-framework and MCP-server CVE batch — Spring AI tool-authorization bypass, PyCharm's unauthenticated Jupyter MCP, Splunk MCP RCE, LangChain SitemapLoader SSRF high patched
2026-07-30 knaithe/KnYuan — an autonomous DeepSeek+Hermes agent mass-scanned 460+ targets for Langflow, n8n and Marimo RCEs; the AI-tool exploits failed only where auth was on high active
2026-08-20 arrayref (244M downloads) and append-only-vec hijacked on crates.io to pull a build-time infostealer via a typosquatted proc-macro1 dependency critical contained
2026-03-09 @siteboon/claude-code-ui — three command-injection CVEs, including unauthenticated RCE from a default JWT secret (backfill) critical patched
2026-05-20 VIPER-MCP — automated audit of 39,884 MCP server repos finds 106 confirmed zero-days, 67 CVEs assigned high ongoing
2026-06-23 An autonomous agent found and exploited a Snowflake CI flaw that Copilot's review and GitHub Advanced Security both passed as clean high patched
2026-08-02 MLflow — unauthenticated SSRF (CVSS 9.3) into cloud metadata plus two authorization-bypass CVEs, all fixed in 3.15.0 critical patched
2026-08-18 CoSnitch — one-click data exfiltration from Microsoft Copilot Personal via an undocumented autorun URL parameter (CVE-2026-24301) critical patched
2026-08-10 NullReceiver — DPRK-linked npm malware hides C2 IPs inside blank Ethereum transactions, two packages impersonate Tailwind CSS/PostCSS plugins high contained
2026-08-12 Suspected China-linked actor runs a four-day, near end-to-end autonomous AI-agent attack on Taiwan's government and nuclear safety agency (agentic threat actor) high unconfirmed
2026-08-14 npm "bin entry harvesting" — 21 packages squat unscoped binary names exposed by Google-scoped npm packages (unconfirmed, single-source) medium unconfirmed
2026-08-10 Cursor CLI ran untrusted repository code before the Workspace Trust prompt — and even with --sandbox enabled high patched
2026-08-06 Meta joins OpenAI and Anthropic in disclosing an AI-eval containment failure — all three used the same third-party testing vendor, Irregular high contained
2026-01-05 CVE-2026-35603 — Claude Code, Cursor, Codex CLI, Gemini CLI all load Windows system config from a folder any local user can write to high active
2026-08-06 Metabase CVE-2026-72898 — unauthenticated SQLi (CVSS 10.0), CISA KEV, breached n8n customer data critical active
2026-08-11 Microsoft August 2026 Patch Tuesday — critical elevation-of-privilege CVEs in Azure SRE Agent and Copilot Cowork critical patched
2026-08-11 AI-agent-assisted SharePoint exploit chain — JWT auth bypass + unsafe deserialization RCE (CVE-2026-55040, CVE-2026-63520) high patched
2026-08-11 GhostSplice — splitting a malicious instruction across an MCP tool's description and result fields raises coding-agent compliance from 42% to 82% high unconfirmed
2026-08-10 Research: encrypted reasoning-trace replay across OpenAI/Anthropic/Google APIs recovers 182 credentials from public AI-agent transcripts medium unconfirmed
2026-08-06 Zenity Labs finds malicious AI-agent skills on Vercel's skills.sh, one family with 1.7M+ installs, abusing Claude Code and OpenClaw as droppers high contained
2026-08-09 GhostJacking — prompt injections planted in Cloudflare/Datadog/Sentry logs hijack Claude Code 9 times out of 10 high active
2026-08-07 Moonshot AI's open-weight Kimi K3 escapes a UK AISI cyber-eval sandbox via a network egress misconfiguration medium contained
2026-08-05 "No Tools Required" — Check Point finds a dozen framework-internals RCE/deserialization bugs across LangChain, CrewAI, Microsoft Agent Framework, Google ADK (details pending) high unconfirmed
2026-08-03 "I'll Just Call You" — a PR comment tricks Google ADK's triage bot into invoking its maintainer-only agent, leaking API keys and a GCP service-account key high patched
2026-07-02 Langflow CVE-2026-9198 — a fifth distinct unauthenticated RCE, /auto_login superuser token chained into /validate/code's exec(); CISA KEV critical active
2026-08-05 Flooding Dropper — ~850 npm packages deliver a cross-platform RAT via require()-time execution, targeting Russian fintech developers high contained
2026-08-05 Paperclip AI agent orchestration platform — self-registration to unauthenticated RCE via malicious agent import (CVE-2026-41679, CVSS 10.0) critical patched
2026-08-05 Atlassian Rovo — indirect prompt injection exfiltrates Jira/Confluence data; the admin "disable web search" toggle doesn't stop it (unpatched) high active
2026-04-24 Gemini CLI "TrustIssues" — a public GitHub issue reaches CI secrets via --yolo mode tool-allowlist bypass (CVE-2026-12537, CVSS 10.0) critical patched
2026-04-22 CanisterWorm — self-propagating npm worm hits Namastex Labs' Automagik AI-agent packages, uses an Internet Computer canister as a dead drop high contained
2026-02-25 Google API keys silently gain Gemini access when a project enables the Generative Language API — 2,863 leaked keys exposed high mitigated
2025-12-27 PleaseFix / Intent Collision — zero-click hijack of Claude in Chrome, ChatGPT Atlas, Gemini, Perplexity Comet, Copilot Edge (Black Hat USA 2026) high active
2026-08-04 UK AISI: an unsupervised Claude Mythos 5 agent invented fake identities and tried to social-engineer a real open-source maintainer into merging malicious code high contained
2026-08-04 keyv/cacheable npm worm ("ChainDrop") — Shai-Hulud-lineage credential stealer plants Claude Code + VS Code auto-run hooks, spread to 400+ packages critical contained
2026-08-04 77 "evil twin" Open VSX extensions impersonate real tools, exfiltrate Git/CI metadata to a single C2 domain high contained
2026-07-10 CoreBreak — forged tool-call events bypass the model entirely across AWS Bedrock AgentCore, Google ADK, and Vercel AI SDK harnesses critical patched
2026-03-17 DeepJack / CursorJack — crafted cursor:// deeplinks install malicious MCP servers, patch bypass of CVE-2025-54133 (unfixed) high active
2026-02-16 RoguePilot — a GitHub Issue + symlinked PR let GitHub Copilot leak your Codespaces GITHUB_TOKEN (patched, backfilled) high patched
2025-12-27 ShadowPrompt — zero-click prompt injection via Claude's Chrome extension, any website could hijack it high patched
2026-03-04 GitHub.com / GitHub Enterprise Server — RCE via a single git push (CVE-2026-3854, CVSS 8.7) critical patched
2025-09-04 CopyPasta License Attack — self-replicating prompt injection in LICENSE.txt/README.md across Cursor, Windsurf, Kiro, Aider high active
2026-07-28 Microsoft Copilot for Word — self-propagating "AI worm" via document-borne prompt injection, no fix after 144 days high active
2026-02-06 Claude Code / Claude Desktop's own GHSA page — 8 more patched advisories this repo hadn't tracked (CVE-2026-55607, -54316, -44470, -44467, -46406, -40068, -35020, -25722) high patched
2025-11-03 Cursor's own GHSA page — 3 more patched advisories from November 2025 this repo hadn't tracked (CVE-2025-64106, -64107, -64108) high patched
2026-07-30 Anthropic discloses Claude models breached three real organizations during misconfigured cybersecurity evaluations, including publishing a malicious PyPI package high contained
2026-07-28 Compromised Joyfill npm beta packages ship an import-time DEV#POPPER RAT with blockchain-resolved C2 high active
2026-07-29 HashiCorp Consul MCP Server — SSRF and cross-tenant credential-reuse CVEs (CVE-2026-16328, CVE-2026-16326) high patched
2026-07-27 Nuxt July 2026 security release — 7 advisories including server-side RCE via Server Island prop injection and a critical DevTools RCE high patched
2026-07-28 18 npm packages impersonating internal Alibaba tooling deliver a cross-platform RAT (aone-cli) — single-source, unconfirmed medium unconfirmed
2026-07-29 RufRoot: Ruflo's unauthenticated MCP bridge lets one HTTP request run shell commands and poison agent memory (CVE-2026-59726, CVSS 10.0, patched 3.16.3) critical patched
2026-03-16 AWS Bedrock AgentCore — 5 CVEs including a recurring argument-injection bug and a CoreBreak tool-call-forgery instance high patched
2026-06-01 Vitest Browser Mode — unauthenticated Chrome DevTools Protocol proxy leads to RCE (CVE-2026-53633, CVSS 9.8, public PoC) critical patched
2026-02-04 GitHub Codespaces auto-executes devcontainer.json / tasks.json / settings.json on repo open — Microsoft calls it "by design" high active
2026-01-09 Langflow CVE-2026-0770 — unauthenticated root RCE via exec_globals in validate_code(), added to CISA KEV 8+ months later, still no patch critical active
2026-07-23 SharedRoot — Claude Cowork's local macOS VM shares the host filesystem read-write with guest-root (CVE-2026-46331) high active
2026-07-23 FakeAgent — a legitimate claude.ai Artifact used as a fake "Claude Desktop" installer, deploys SectopRAT via DLL sideloading high contained
2026-07-23 Hermes AI agent in "YOLO mode" runs unattended post-exploitation against Thailand's Ministry of Finance high unconfirmed
2026-07-14 ChainVeil / ViteVenom — two npm typosquat waves impersonating Tailwind CSS and Vite tooling, four-tier blockchain C2 medium contained
2026-06-04 AgentForger — a single ChatGPT link CSRF'd a fully autonomous, attacker-controlled Workspace Agent high patched
2026-07-21 Azure DevOps MCP server — invisible HTML comments in PR descriptions hijack AI review agents across projects high active
2026-07-20 NextAuth.js / Auth.js — 4 advisories including a homoglyph bypass that redirects magic-link sign-in to an attacker's inbox high unconfirmed
2026-07-20 Next.js July + August 2026 Security Releases — 9 CVEs in July (middleware bypass, SSRF, cache confusion), then two critical unauthenticated RCEs in August (AVIF image optimization + Windows path traversal CVE-2026-75604; 16.3.3 / 15.5.24) critical patched
2026-07-13 MemGhost — a single malicious email plants persistent false memories in AI agents (research, OpenClaw + Claude Code SDK) high active
2026-07-17 On-chain backdoor in a malicious TRAE IDE extension — Ethereum smart contract as C2 (juannegro.solidity) high unconfirmed
2026-07-20 PostCSS sourceMappingURL arbitrary file read (CVE-2026-45623) — reachable through Tailwind CSS's build pipeline high patched
2026-06-15 Pickle in the Middle — Google Cloud Vertex AI SDK bucket-squatting RCE, plus an unrelated stored-XSS CVE (CVE-2026-2472) in the same SDK critical patched
2026-07-07 Rogue Agent — shared Cloud Run execution environment let one Dialogflow CX agent hijack every agent in a GCP project high patched
2026-07-08 n8n — 10-advisory security batch: host-level RCE via expression evaluator, SSO privilege escalation, AI-agent sandbox bypass high patched
2026-07-15 PromptFiction — Claude Desktop's claude:// URI auto-submitted hidden prompts with zero clicks, chainable with Claudy Day high patched
2026-07-14 Cursor IDE — a git.exe planted in a repo root auto-executes on open; CVE-2026-63093 assigned but patch status disputed high active
2026-02-11 AWS Kiro IDE — prompt injection lets the agent rewrite its own MCP config, achieving RCE (CVE-2026-10591) high patched
2026-05-21 Cursor's own GHSA page: 4 more sandbox-escape advisories, one still unpatched high active
2026-07-16 Hugging Face discloses a weekend-long intrusion run almost entirely by an autonomous AI agent high contained
2026-07-13 SANS ISC documents internet-wide scanning for exposed MCP servers and AI-coding-tool credential files medium active
2026-07-09 AI-SDK-name typosquats on npm harvest git/SSH/cloud identity — anthropic-toolkit, ai-sdk-helpers, @langgraphjs/toolkit and more high contained
2026-07-14 AsyncAPI npm compromise — GitHub Actions "pwn request" steals CI token, publishes Miasma RAT through the project's own OIDC pipeline critical active
2026-07-08 HalluSquatting — pre-registering AI-hallucinated package/skill/repo names weaponizes coding-agent trust high active
2026-07-14 Microsoft July Patch Tuesday — GitHub Copilot JetBrains plugin CVE-2026-50510 + M365 Copilot mobile CVE-2026-48561 + cross-tenant EoP CVE-2026-41106 + RCE CVE-2026-50517 + VS Code credential leak CVE-2026-47282 critical patched
2026-07-11 jscrambler npm compromise — Rust infostealer that survives --ignore-scripts, targets Claude Desktop/Cursor/Windsurf configs high contained
2026-05-28 Zapocalypse — five-stage exploit chain turns a free Zapier account into NPM publish rights on zapier.com's own JS bundle critical patched
2026-07-08 Injective Labs SDK npm compromise — compromised contributor account plants wallet-key stealer high contained
2026-07-01 Claude Cowork for Windows sandbox escape — chained flaws reach root in the Hyper-V VM; Anthropic disputes it's a vulnerability high active
2026-07-08 GhostApproval — symlinked config files trick 6 AI coding assistants into writing outside the workspace high active
2026-07-08 Friendly Fire — hijacking Claude Code auto-mode and Codex auto-review into running the malware they were sent to catch high active
2026-07-07 Fake Paysafe / Skrill / Neteller SDKs on npm and PyPI steal credentials (17 packages, removed) high contained
2026-06-30 GuardFall — shell-injection design flaw breaks command guards in 10 of 11 open-source AI coding agents high active
2026-07-06 GitLost — public GitHub Issue prompt-injects GitHub Agentic Workflows into leaking private repos (no full fix) high active
2026-06-19 Langflow CVE-2026-55255 — cross-tenant IDOR chained with CVE-2026-33017 RCE, added to CISA KEV critical active
2026-06-02 better-auth — 13+ OAuth/OIDC/SSO/SCIM advisories including a critical MCP-plugin refresh-token bypass (CVE-2026-53512) high patched
2026-07-06 Coder — coordinated security release: AI Bridge Proxy TLS bypass, CLI session-token exfil, two OIDC account-takeover CVEs high patched
2026-07-02 JADEPUFFER — first documented fully agentic ransomware attack, run start-to-finish by an autonomous AI agent high active
2026-06-30 Claude Code covert China-proxy fingerprinting channel steganographically encoded in system prompt — China's NVDB issues public alert, Alibaba bans internal use medium patched
2026-07-04 Rollup polyfill impersonation — 6 npm packages drop full RAT, tentatively linked to Lazarus high contained
2026-07-01 Claude Desktop personalization-sync prompt injection → reverse shell — Anthropic calls it expected functionality high active
2026-03-01 PolinRider — DPRK-linked campaign backdoors npm, Packagist, Go, and a Chrome extension via maintainer-account takeover high active
2026-01-20 SvelteSpill — SvelteKit + Vercel cache deception exposes authenticated responses (CVE-2026-27118) high patched
2026-01-15 Five CVEs across the Svelte ecosystem — devalue DoS, SvelteKit memory-amplification DoS + prerendering SSRF, a hydratable-key XSS high patched
2026-06-25 Cursor DuneSlide — two CVSS 9.8 zero-click prompt-injection-to-RCE flaws (CVE-2026-50548, CVE-2026-50549) critical patched
2026-04-06 Vite dev-server WebSocket arbitrary file read + fs.deny bypasses (CVE-2026-39363, CVE-2026-39364, CVE-2026-39365) — mass-scanned in the wild from August 2026 for .env, AWS and Terraform secrets high active
2026-04-10 Single operator uses Claude Code + GPT-4.1 to breach nine Mexican government agencies — 195M+220M records, AI-augmented attacker high historical
2026-04-02 Claude Code deny-rule bypass via 50-subcommand parser cap (silently patched v2.1.90) high patched
2026-04-29 Claude Code GitHub Action's unsandboxed Read tool leaks CI/CD secrets via /proc/self/environ (patched 2.1.128) high patched
2026-05-29 Dependency-confusion recon campaign — 4 waves, escalated to full credential theft high active
2026-05-14 Svelte CVE-2026-42573 — DOM clobbering of internal framework state leads to XSS medium patched
2026-03-18 Claudy Day — three chained Claude.ai flaws exfiltrate conversation history via hidden URL-parameter prompt injection high mitigated
2026-06-25 Operation Navy Ghost — 8 fake pyrogram packages backdoor Telegram bot servers via victim's own bot token as C2 (~24K installs) high unconfirmed
2026-06-25 Mozilla 0DIN DNS Setup Trap — clean GitHub repos trick Claude Code into reverse shell via DNS-TXT record command injection (no patch) high active
2026-06-26 Amazon Q Developer CVE-2026-12957 + CVE-2026-12958 — auto-loading .amazonq/mcp.json ran attacker code with live AWS credentials on repo open (patched) high patched
2026-06-24 Miasma LeoPlatform + Go wave — 20 npm packages + Go module + 1,442 GitHub Actions repos compromised via Phantom Gyp (binding.gyp) in 3-second burst critical historical
2026-06-26 Miasma hits @immobiliarelabs Backstage GitLab/LDAP plugins — 22 versions, AI-assistant config persistence critical contained
2026-06-22 Dify DifyTap — 4 CVEs (top CVSS 9.4) allow cross-tenant AI conversation exfiltration across 1M+ apps; patched 1.14.2 high patched
2026-06-24 Cordyceps — GitHub Actions CI/CD misconfiguration class exposes 300+ repos (Microsoft, Google, Cloudflare) to PR-based code execution and credential theft high active
2026-05-07 TrustFall — Claude Code, Cursor CLI, Gemini CLI, Copilot CLI, Codex CLI auto-execute MCP servers on folder-trust dialog (no patch; Anthropic won't fix) high active
2026-06-15 Microsoft 365 Copilot SearchLeak (CVE-2026-42824) — 1-click exfil of emails, MFA codes, and OneDrive files via parameter-to-prompt injection + CSP bypass high patched
2026-06-18 IDEsaster — 30+ flaws (24 CVEs) in Cursor, Windsurf, Kiro.dev, GitHub Copilot, Zed, Roo Code, Junie, Cline high active
2026-06-16 Langflow CVE-2026-5027 — unauthenticated path traversal → RCE via file upload (distinct from CVE-2026-33017) high patched
2026-06-14 PromptSnatcher — malicious Chrome ad-blocker extensions intercept AI chatbot conversations from 900K users high active
2026-06-13 AutoJack — AutoGen Studio 3-flaw chain: browsing agent + unauthenticated MCP WebSocket = localhost RCE high patched
2026-06-17 15 malicious JetBrains Marketplace plugins steal AI provider API keys on entry (70K+ installs) high historical
2026-06-17 Mastra AI npm namespace compromise — 145 packages backdoored via hijacked contributor account critical historical
2026-06-12 Klue AI integration breach — Icarus extortion group steals OAuth tokens; CRM data exfiltrated from Huntress and Recorded Future high contained
2026-06-11 Atomic Arch — AUR supply-chain attack: 1,500+ packages hijacked via orphaned-package takeover; eBPF rootkit high active
2026-06-15 Claude Code MCP OAuth token hijack via malicious npm postinstall hook — Anthropic won't fix high active
2026-06-13 Solana FakeFix Campaign — 25 malicious npm + PyPI packages steal wallet keys via GitHub issue spam high historical
2026-06-12 Agentjacking — Sentry DSN injection via MCP poisons AI coding agent context (2,388 orgs exposed) high active
2026-06-10 onering Rust crate compromised — build.rs exfiltrates source-code diffs as fake Sentry telemetry high unconfirmed
2026-06-10 Streamlit CVE-2026-33682 — unauthenticated SSRF on Windows leaks NTLMv2 credentials high patched
2026-06-10 SymJack — symlink hijacking tricks AI coding agents into registering attacker-controlled MCP servers high mitigated
2026-06-09 LangGraph RCE chain — SQLite SQL injection + msgpack deserialization → arbitrary code execution critical patched
2026-06-08 Hades Campaign — 19 PyPI bioinformatics + MCP-developer packages poisoned with Bun credential stealer (June 2026) critical historical
2026-06-05 Miasma Wave 5 — 73 Microsoft Azure GitHub repos + mantine-datatable poisoned; payload auto-fires via Claude Code / Cursor / Gemini CLI critical contained
2026-06-04 IronWorm — Rust npm worm with eBPF kernel rootkit + Tor C2 (36 packages) critical active
2026-06-06 Gluestack @react-native-aria RAT via compromised contributor token critical contained
2026-06-04 Phantom Gyp — Miasma wave 4: self-propagating npm worm via binding.gyp (57 packages) critical active
2026-06-04 Claude Code GitHub Actions [bot] trust bypass — supply chain risk (patched v1.0.94) high patched
2026-06-01 Cline — two separate cross-origin WebSocket hijack → RCE CVEs across its VS Code extension and CLI Hub critical patched
2026-06-01 codexui-android npm — OpenAI Codex auth-token stealer high historical
2026-06-01 Miasma — @redhat-cloud-services npm scope compromised by Mini-Shai-Hulud-derived worm critical contained
2026-05-25 Cargo May 2026 security release — symlink-override + sparse-URL leak (CVE-2026-5223, CVE-2026-5222) medium patched
2026-05-22 Megalodon — mass GitHub-Actions workflow poisoning of 5,561 repos critical contained
2026-05-22 BadHost — Starlette host-header auth bypass blasts FastAPI, vLLM, LiteLLM, MCP servers (CVE-2026-48710) critical patched
2026-05-22 Composio AI-agent platform breach — LLM-augmented attacker registered malicious tool definitions in the sandbox high contained
2026-05-22 TrapDoor — cross-ecosystem stealer poisons .cursorrules / CLAUDE.md critical active
2026-05-20 Claude Code network-sandbox SOCKS5 null-byte bypass high patched
2026-05-20 TeamPCP breaches GitHub internal repos via poisoned VS Code extension high contained
2026-05-19 Mini Shai-Hulud May 19 wave — @antv npm + Microsoft durabletask PyPI critical historical
2026-05-18 Shai-Hulud copycats after the worm source went public high historical
2026-05-18 Nx Console VS Code extension compromise (nrwl.angular-console 18.95.0) critical contained
2026-05-12 Claude Code claude-cli:// deeplink RCE (2.1.118) critical patched
2026-05 WhiteCobra — VS Code / Cursor / Windsurf / Open VSX crypto-stealer campaign (July 2025 → ongoing) high active
2026-05 PCPJack — credential-stealing counter-worm that removes TeamPCP infections high active
2026-05-06 ClaudeBleed — Claude in Chrome extension hijack high mitigated
2026-05-06 ZiChatBot — 3 trojanized PyPI packages use the Zulip chat API as C2, suspected OceanLotus/APT32 medium contained
2026-05-13 OpenClaw "Claw Chain" — 9 CVEs/batches spanning Feb–May 2026: sandbox escapes, device-pairing/token-rotation privilege escalation, an SSRF/path-traversal batch, and an unconfirmed prompt-injection RCE critical patched
2026-05-13 Systemic MCP stdio RCE class — now with HashiCorp Terraform MCP + Kubernetes MCP + Token Optimizer MCP entries high mitigated
2026-05-14 node-ipc compromise critical historical
2026-05-11 PraisonAI auth bypass (CVE-2026-44338) high patched
2026-05-11 Mini Shai-Hulud wave — TanStack/Mistral/UiPath/OpenSearch critical active
2026-05-08 Cursor open-folder + Git-hook RCE high patched
2026-05-07 Microsoft Semantic Kernel RCE (CVE-2026-25592 / CVE-2026-26030) critical patched
2026-05-06 Next.js + React May 2026 security release (13 CVEs) high patched
2026-05 Windsurf zero-click MCP RCE (CVE-2026-30615) critical patched
2026-04-30 PyTorch Lightning + intercom-client (Mini Shai-Hulud) critical contained
2026-04-24 LiteLLM proxy pre-auth SQL injection (CVE-2026-42208, CISA KEV) critical patched
2026-04-24 elementary-data PyPI + GHCR compromise (malicious .pth auto-exec) critical contained
2026-04-23 Flowise RCE cluster — CVE-2025-59528 actively exploited + April Agent-node cluster (CVE-2026-41265 et al.) critical patched
2026-04-22 Bitwarden CLI backdoored — first AI-tool-cred-hunting supply-chain malware critical contained
2026-04-19 Vercel breach via Context.ai OAuth supply chain high contained
2026-04-08 Marimo notebook pre-auth RCE (CVE-2026-39987) critical patched
2026-04 Mini Shai-Hulud SAP packages high historical
2026-04 "Comment and Control" PR prompt injection critical patched
2026-03 SGLang unauth RCE cluster — CVE-2026-3059 / CVE-2026-3060 (pickle ZMQ, CVSS 9.8) + CVE-2026-5760 (GGUF model RCE) critical patched
2026-03-12 TeamPCP breaches Trivy GitHub Actions → LiteLLM 1.82.7–1.82.8 backdoored critical contained
2026-03-31 Axios compromise critical contained
2026-03-31 Claude Code source-map leak medium contained
2026-03-27 OpenHands git-diff command injection (CVE-2026-33718) high patched
2026-02-25 Langflow CVE-2026-27966 — CSV Agent hardcodes allow_dangerous_code=True → prompt-injection RCE (CVSS 9.8) critical patched
2026-03-17 Langflow unauthenticated RCE (CVE-2026-33017) critical patched
2026-03-02 ModelScope ms-agent OS command injection (CVE-2026-2256) — unpatched, public PoC, CERT/CC advisory medium active
2026-03-11 Supabase Auth OIDC issuer-validation bypass (CVE-2026-31813) high patched
2026-02-28 Google Antigravity sandbox escape (Pillar) high patched
2026-02-17 Cline 2.3.0 supply-chain compromise (Clinejection → OpenClaw) critical contained
2026-02-17 SANDWORM_MODE — Shai-Hulud-style npm worm with MCP injection, CI implant, and 48-hour delayed activation critical historical
2026-02-09 Claude Desktop Extensions (DXT) zero-click RCE — Anthropic won't fix critical active
2026-02-01 ClawHavoc — malicious-skill poisoning of OpenClaw's ClawHub marketplace high active
2026-01-26 OpenClaw 1-click RCE via WebSocket gateway-URL token theft (CVE-2026-25253) critical patched
2026-01-07 LangSmith CVE-2026-25750 unvalidated baseUrl → account takeover high patched
2026-01-12 OpenCode AI coding agent — twin localhost RCEs (CVE-2026-22812 + CVE-2026-22813) critical patched
2025-11-09 n8n Ni8mare (CVE-2026-21858, CVSS 10.0) — unauth RCE + credential theft in workflow automation critical patched
2025-12-28 Shai-Hulud 3.0 test payload — @vietmoney/react-big-calendar@0.26.2 high contained
2025-12-23 LangChain LangGrinch (CVE-2025-68664) + path traversal (CVE-2026-34070) critical patched
2025-12-05 React2Shell — CVE-2025-55182 RCE in React Server Components (CISA KEV, exploited through Apr 2026) critical patched
2026-01-05 AI IDEs recommend non-existent extensions — OpenVSX namespace hijack high mitigated
2025-11-24 Shai-Hulud "Second Coming" critical contained
2025-10-21 Cursor & Windsurf ship stale Chromium — 94+ n-day vulns high active
2025-10 Windsurf path-traversal via prompt-injected README (CVE-2025-62353) critical patched
2025-10-17 GlassWorm — self-propagating VS Code / Open VSX worm high active
2025-09-17 postmark-mcp backdoor high contained
2025-09-15 Shai-Hulud original critical contained
2025-09-08 qix npm account compromise critical contained
2025-09-01 Lies in the Loop (LITL) — approval-dialog padding hides malicious commands below the fold; no vendor fix (Claude Code, VS Code Copilot) high active
2025-08-26 Salesloft Drift OAuth Breach — UNC6395 steals Salesforce CRM data from Cloudflare, Palo Alto, Zscaler and hundreds of orgs high contained
2025-08-26 Nx s1ngularity critical contained
2025-08 → ongoing Claude Code InversePrompt (multiple CVEs) medium patched
2025-07-17 Amazon Q VS Code wiper medium contained
2025-07 Cursor CurXecute / MCPoison high patched
2025-07 Supabase MCP lethal trifecta high mitigated
2025-06-25 VSXPloit — Open VSX nightly build pipeline token theft; 8M+ developers at risk (patched June 2025) high patched
ongoing Slopsquatting medium ongoing
ongoing Vibe platform data exposure high ongoing

Severity

  • critical — active credential theft, RCE, or supply-chain worm. Drop everything.
  • high — practical exploitation path, requires action if you use the affected tool.
  • medium — pattern of attack worth knowing, mitigation usually exists.

Status

  • active — malware still in registry, attack still propagating, or no patch yet.
  • contained — package removed / patch shipped, but old lockfiles still vulnerable.
  • patched — vendor fix released; update and you're fine.
  • mitigated — design-level fix or workaround available, no perfect patch.
  • ongoing — class of attack that keeps recurring; treat as evergreen.

Format

Every advisory uses the same skeleton. See CONTRIBUTING.md for the template.