ASR AI Security Radar
Back to homepage

Recent AI Security Incidents

This archive includes all published incident pages. Page 3 of 18.

Each page is intended to help a security team answer three questions quickly: why the issue is AI-relevant, what part of the workflow may be exposed, and what actions should happen first.

Selection criteria and correction policy are documented in Methodology & Editorial Policy.

AI security incident: LangChain Core has Path Traversal vulnerabilites in legacy load prompt functions (GHS...

Incident date: March 27, 2026 | Published: March 27, 2026

LangChain Core has Path Traversal vulnerabilites in legacy load prompt functions Summary Multiple functions in langchain core.prompts.

Read details

AI security incident: Langflow has Authenticated Code Execution in Agentic Assistant Validation (GHSA-v8hw-...

Incident date: March 26, 2026 | Published: March 26, 2026

Langflow has Authenticated Code Execution in Agentic Assistant Validation Description Summary The Agentic Assistant feature in Langflow executes LLM-generated Python code during its validation phase.

Read details

AI security incident: Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings File (GH...

Incident date: March 19, 2026 | Published: March 19, 2026

Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings File Claude Code resolved the permission mode from settings files, including the repo-controlled .claude/settings.

Read details

AI security incident: VU#665416: SGLang (sglang) is vulnerable to code execution attacks via unsafe pickle...

Incident date: March 12, 2026 | Published: March 12, 2026

Overview Two unsafe pickle deserialization vulnerabilities have been discovered in the SGLang open-source project, one within the tool's multimodal generation module and another within the Encoder Parallel Disaggregation system.

Read details

AI security incident: @siteboon/claude-code-ui Vulnerable to Unauthenticated RCE via WebSocket Shell Inject...

Incident date: March 11, 2026 | Published: March 11, 2026

@siteboon/claude-code-ui Vulnerable to Unauthenticated RCE via WebSocket Shell Injection Security Advisory: Insecure Default JWT Secret + WebSocket Auth Bypass Enables Unauthenticated RCE via Shell Injection Download: cve claudecodeui...

Read details

AI security incident: @siteboon/claude-code-ui is Vulnerable to Command Injection via Multiple Parameters (...

Incident date: March 11, 2026 | Published: March 11, 2026

@siteboon/claude-code-ui is Vulnerable to Command Injection via Multiple Parameters Summary Multiple Git-related API endpoints use execAsync() with string interpolation of user-controlled parameters (file, branch, message, commit),...

Read details

AI security incident: @siteboon/claude-code-ui is Vulnerable to Shell Command Injection in Git Routes (GHSA...

Incident date: March 10, 2026 | Published: March 11, 2026

@siteboon/claude-code-ui is Vulnerable to Shell Command Injection in Git Routes Shell Command Injection in User Git Config Endpoint Field Value ------- ------- Severity High CVSS 3.1 8.

Read details

AI security incident: WeKnora Vulnerable to Remote Code Execution via SQL Injection Bypass in AI Database Q...

Incident date: March 6, 2026 | Published: March 7, 2026

WeKnora Vulnerable to Remote Code Execution via SQL Injection Bypass in AI Database Query Tool Summary A critical Remote Code Execution (RCE) vulnerability exists in the application's database query functionality.

Read details

AI security incident: Zarf's symlink targets in archives are not validated against destination directory (G...

Incident date: March 6, 2026 | Published: March 6, 2026

Zarf's symlink targets in archives are not validated against destination directory Summary A path traversal vulnerability in archive extraction allows a specifically crafted Zarf package to create symlinks pointing outside the destination...

Read details

AI security incident: Mercurius's queryDepth limit bypassed for WebSocket subscriptions (GHSA-m4h2-mjfm-mp55)

Incident date: March 6, 2026 | Published: March 6, 2026

Mercurius's queryDepth limit bypassed for WebSocket subscriptions Description Mercurius fails to enforce the configured queryDepth limit on GraphQL subscription queries received over WebSocket connections.

Read details