<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>PlainCVE</title><description>Real vulnerabilities explained in plain language, with sources you can check: who is affected, how the attack works, and how to fix and detect it.</description><link>https://plaincve.date/</link><language>en</language><item><title>CVE-2026-12537 Gemini CLI headless CI workspace trust flaw: a .gemini/.env file in an outside PR can run commands on the host before the sandbox starts</title><link>https://plaincve.date/en/vulns/cve-2026-12537-gemini-cli-headless-workspace-trust/</link><guid isPermaLink="true">https://plaincve.date/en/vulns/cve-2026-12537-gemini-cli-headless-workspace-trust/</guid><description>In CI, Gemini CLI trusted any workspace automatically, so a malicious .gemini/.env in a pull request could run commands on the build host.</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>gemini-cli</category><category>github-actions</category><category>ci-cd</category><category>workspace-trust</category><category>ai-agent</category><category>command-injection</category><category>CVE-2026-12537</category></item><item><title>CVE-2026-33017 Langflow public flow endpoint RCE: anyone can run Python on the server without logging in</title><link>https://plaincve.date/en/vulns/cve-2026-33017-langflow-public-flow-rce/</link><guid isPermaLink="true">https://plaincve.date/en/vulns/cve-2026-33017-langflow-public-flow-rce/</guid><description>Langflow&apos;s public flow endpoint ran Python code sent by anyone, with no login, letting attackers take over the server. Exploited in the wild.</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>langflow</category><category>rce</category><category>code-injection</category><category>missing-authentication</category><category>python</category><category>ai-pipeline</category><category>CVE-2026-33017</category></item><item><title>CVE-2026-45758 guardrails-ai 0.10.1 shipped malicious code: a PyPI supply-chain compromise of an AI safety library</title><link>https://plaincve.date/en/vulns/cve-2026-45758-guardrails-ai-pypi-compromise/</link><guid isPermaLink="true">https://plaincve.date/en/vulns/cve-2026-45758-guardrails-ai-pypi-compromise/</guid><description>A malicious guardrails-ai 0.10.1 was pushed to PyPI with a stolen token; on Linux, importing it fetched and ran a remote payload.</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>pypi</category><category>python</category><category>malicious-package</category><category>ci-cd</category><category>credential-theft</category><category>shai-hulud</category><category>llm-guardrails</category><category>CVE-2026-45758</category></item><item><title>CVE-2026-48501 GitHub CLI token leak: gh attestation and gh release verify could send your token to TUF and artifact hosts</title><link>https://plaincve.date/en/vulns/cve-2026-48501-github-cli-token-leak/</link><guid isPermaLink="true">https://plaincve.date/en/vulns/cve-2026-48501-github-cli-token-leak/</guid><description>GitHub CLI before 2.93.0 could attach your GitHub login token to requests to TUF and artifact hosts during three verification commands.</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>github-cli</category><category>credential-leak</category><category>token</category><category>sigstore</category><category>tuf</category><category>attestation</category><category>go</category><category>CVE-2026-48501</category></item><item><title>CVE-2026-50016 pnpm dependency alias path traversal: an indirect dependency can swap project folders for symlinks at install time, even with --ignore-scripts</title><link>https://plaincve.date/en/vulns/cve-2026-50016-pnpm-alias-path-traversal/</link><guid isPermaLink="true">https://plaincve.date/en/vulns/cve-2026-50016-pnpm-alias-path-traversal/</guid><description>pnpm didn&apos;t block &apos;..&apos; in dependency aliases, so a malicious package deep in the tree can swap project paths for symlinks, even with --ignore-scripts.</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>pnpm</category><category>npm</category><category>javascript</category><category>path-traversal</category><category>symlink</category><category>ignore-scripts</category><category>transitive-dependency</category><category>CVE-2026-50016</category></item><item><title>CVE-2026-5241 Hugging Face Transformers LightGlue loading: a model&apos;s config can override trust_remote_code=False and run the model&apos;s own code</title><link>https://plaincve.date/en/vulns/cve-2026-5241-transformers-lightglue-remote-code-override/</link><guid isPermaLink="true">https://plaincve.date/en/vulns/cve-2026-5241-transformers-lightglue-remote-code-override/</guid><description>In Transformers before 5.5.0, a LightGlue model&apos;s own config could override trust_remote_code=False and run the model&apos;s bundled Python code.</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>huggingface</category><category>transformers</category><category>trust-remote-code</category><category>model-supply-chain</category><category>python</category><category>code-execution</category><category>CVE-2026-5241</category></item><item><title>CVE-2026-82021 Hermes Agent&apos;s bundled MCP catalog pinned a branch instead of a commit: if the upstream repo were hijacked, installing would run someone else&apos;s code</title><link>https://plaincve.date/en/vulns/cve-2026-82021-hermes-agent-mcp-unpinned-branch/</link><guid isPermaLink="true">https://plaincve.date/en/vulns/cve-2026-82021-hermes-agent-mcp-unpinned-branch/</guid><description>Hermes Agent&apos;s MCP catalog installed its n8n bridge from a movable branch; if that upstream repo were hijacked, installs would run its code.</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>mcp</category><category>ai-agent</category><category>version-pinning</category><category>git</category><category>n8n</category><category>integrity-check</category><category>CVE-2026-82021</category></item><item><title>CVE-2026-90553 vLLM LlavaOnevision2 ignores trust_remote_code: code bundled in a malicious model runs even when you turned it off</title><link>https://plaincve.date/en/vulns/cve-2026-90553-vllm-llavaonevision2-remote-code-ignored/</link><guid isPermaLink="true">https://plaincve.date/en/vulns/cve-2026-90553-vllm-llavaonevision2-remote-code-ignored/</guid><description>vLLM before 0.28.0 ignores trust_remote_code=False for LlavaOnevision2 models, so code bundled in a malicious model can still run.</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>vllm</category><category>trust-remote-code</category><category>model-supply-chain</category><category>python</category><category>kwargs</category><category>multimodal</category><category>CVE-2026-90553</category></item><item><title>CVE-2026-26030 Microsoft Semantic Kernel (Python) runs InMemoryVectorStore filter conditions as code</title><link>https://plaincve.date/en/vulns/cve-2026-26030-semantic-kernel-filter-rce/</link><guid isPermaLink="true">https://plaincve.date/en/vulns/cve-2026-26030-semantic-kernel-filter-rce/</guid><description>Semantic Kernel turns the filter an AI model writes for a search plugin into Python code and runs it; prompt injection can make that run any code on the server.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate><category>prompt-injection</category><category>llm</category><category>agent</category><category>python</category><category>eval</category><category>rce</category><category>CVE-2026-26030</category></item><item><title>CVE-2026-33634 Trivy supply chain attack: a security scanner laced with credential-stealing code, spreading all the way to LiteLLM and Checkmarx</title><link>https://plaincve.date/en/vulns/cve-2026-33634-trivy-supply-chain/</link><guid isPermaLink="true">https://plaincve.date/en/vulns/cve-2026-33634-trivy-supply-chain/</guid><description>Attackers hijacked Trivy&apos;s releases to ship a credential stealer; secrets taken from CI pipelines that ran it were then used to poison LiteLLM and others.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate><category>github-actions</category><category>ci-cd</category><category>credential-theft</category><category>pypi</category><category>docker-hub</category><category>trivy</category><category>litellm</category><category>CVE-2026-33634</category></item><item><title>CVE-2026-45321 TanStack npm supply-chain compromise (Mini Shai-Hulud): hijacked release pipeline pushed credential-stealing malware into 42 @tanstack packages</title><link>https://plaincve.date/en/vulns/cve-2026-45321-tanstack-npm-supply-chain-compromise/</link><guid isPermaLink="true">https://plaincve.date/en/vulns/cve-2026-45321-tanstack-npm-supply-chain-compromise/</guid><description>Attackers hijacked TanStack&apos;s GitHub release pipeline and pushed credential-stealing malware in 84 versions of 42 @tanstack/* npm packages.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate><category>npm</category><category>github-actions</category><category>pull-request-target</category><category>cache-poisoning</category><category>oidc</category><category>worm</category><category>mini-shai-hulud</category><category>credential-theft</category><category>kev</category><category>CVE-2026-45321</category></item><item><title>CVE-2026-59822 LiteLLM Proxy MCP gateway authentication bypass: any made-up token can call MCP tools</title><link>https://plaincve.date/en/vulns/cve-2026-59822-litellm-mcp-auth-bypass/</link><guid isPermaLink="true">https://plaincve.date/en/vulns/cve-2026-59822-litellm-mcp-auth-bypass/</guid><description>LiteLLM Proxy&apos;s MCP endpoints let failed logins through as anonymous, so anyone can list and call its MCP tools with no account. Exploited in the wild.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate><category>mcp</category><category>llm-gateway</category><category>authentication</category><category>python</category><category>fail-open</category><category>CVE-2026-59822</category></item><item><title>CVE-2026-94127 F5 BIG-IP APM OAuth Authorization Server heap overflow: remote code execution without logging in, exploited as a zero-day</title><link>https://plaincve.date/en/vulns/cve-2026-94127-f5-big-ip-apm-oauth-heap-overflow/</link><guid isPermaLink="true">https://plaincve.date/en/vulns/cve-2026-94127-f5-big-ip-apm-oauth-heap-overflow/</guid><description>An F5 BIG-IP APM memory bug lets attackers who have not logged in run code on systems acting as OAuth Authorization Servers. Exploited as a zero-day.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate><category>f5</category><category>big-ip</category><category>apm</category><category>oauth</category><category>heap-overflow</category><category>rce</category><category>zero-day</category><category>kev</category><category>edge-device</category><category>CVE-2026-94127</category></item><item><title>axios npm package poisoned: maintainer account stolen, 1.14.1 and 0.30.4 shipped a remote access trojan</title><link>https://plaincve.date/en/vulns/ghsa-2026-axios-npm-compromise/</link><guid isPermaLink="true">https://plaincve.date/en/vulns/ghsa-2026-axios-npm-compromise/</guid><description>Attackers hijacked an axios maintainer&apos;s npm account and published two versions with a malicious dependency; a plain npm install drops a remote access trojan.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate><category>npm</category><category>javascript</category><category>account-takeover</category><category>postinstall</category><category>rat</category><category>north-korea</category></item></channel></rss>