ASR AI Security Radar
Back to homepage

Recent AI Security Incidents

This archive includes all published incident pages. Page 14 of 18.

Each page is intended to help a security team answer three questions quickly: why the issue is AI-relevant, what part of the workflow may be exposed, and what actions should happen first.

Selection criteria and correction policy are documented in Methodology & Editorial Policy.

AI security incident: Indico has Server-Side Request Forgery (SSRF) in multiple places (GHSA-f47c-3c5w-v7p4)

Incident date: February 17, 2026 | Published: February 25, 2026

Impact Indico makes outgoing requests to user-provides URLs in various places. This is mostly intentional and part of Indico's functionality, but of course it is never intended to let you access "special" targets such as localhost or...

Read details

AI security incident: Unauthenticated File Upload in Gogs (GHSA-fc3h-92p8-h36f)

Incident date: February 17, 2026 | Published: February 25, 2026

Security Advisory:Unauthenticated File Upload in Gogs Vulnerability Type: Unauthenticated File Upload Date: Aug 5, 2025 Discoverer: OpenAI Security Research ## Summary Gogs exposes unauthenticated file upload endpoints by default.

Read details

AI security incident: Gogs has a Protected Branch Deletion Bypass in Web Interface (GHSA-2c6v-8r3v-gh6p)

Incident date: February 17, 2026 | Published: February 25, 2026

Summary An access control bypass vulnerability in Gogs web interface allows any repository collaborator with Write permissions to delete protected branches (including the default branch) by sending a direct POST request, completely...

Read details

AI security incident: Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs (...

Incident date: February 17, 2026 | Published: February 25, 2026

**Summary** A broken access control vulnerability in Gogs allows authenticated users with write access to any repository to modify labels belonging to other repositories. The UpdateLabel function in the Web UI ( internal/route/repo/issue.

Read details

AI security incident: Known affected by Account Takeover via Password Reset Token Leakage (GHSA-78wq-6gcv-w...

Incident date: February 13, 2026 | Published: February 14, 2026

Summary A Critical Broken Authentication vulnerability exists in Known 1.6.2. The application leaks the password reset token within a hidden HTML input field on the password reset page.

Read details

AI security incident: Cloudflare Agents has a Reflected Cross-Site Scripting (XSS) vulnerability in AI Play...

Incident date: February 13, 2026 | Published: February 14, 2026

Summary A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the AI Playground's OAuth callback handler.

Read details

AI security incident: Wildfly Elytron integration susceptible to brute force attacks via CLI (GHSA-qhp6-6p8...

Incident date: February 13, 2026 | Published: February 25, 2026

Impact A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks...

Read details

AI security incident: CVE-2026-26268 (NVD)

Incident date: February 13, 2026 | Published: February 14, 2026

Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicious agent (ie prompt injection) could write to improperly protected .

Read details

AI security incident: Cloudflare Agents is Vulnerable to Reflected Cross-Site Scripting in the AI Playgroun...

Incident date: February 13, 2026 | Published: February 25, 2026

Summary A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the AI Playground's OAuth callback handler.

Read details

AI security incident: CVE-2026-1731 (CISA KEV)

Incident date: February 13, 2026 | Published: February 25, 2026

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) - BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability.

Read details