ASR AI Security Radar
Back to homepage

Recent AI Security Incidents

This archive includes all published incident pages. Page 8 of 16.

Each page is intended to help a security team answer three questions quickly: why the issue is AI-relevant, what part of the workflow may be exposed, and what actions should happen first.

Selection criteria and correction policy are documented in Methodology & Editorial Policy.

AI security incident: Feathers has an open redirect in OAuth callback enables account takeover (GHSA-ppf9-4...

Incident date: February 19, 2026 | Published: February 25, 2026

Description The redirect query parameter is appended to the base origin without validation, allowing attackers to steal access tokens via URL authority injection.

Read details

AI security incident: Formwork Improperly Managed Privileges in User creation (GHSA-34p4-7w83-35g2)

Incident date: February 19, 2026 | Published: February 25, 2026

Summary The application fails to properly enforce role-based authorization during account creation. Although the system validates that the specified role exists, it does not verify whether the current user has sufficient privileges to...

Read details

AI security incident: Leaf-kit html escaping does not work on characters that are part of extended grapheme...

Incident date: February 19, 2026 | Published: February 25, 2026

Summary htmlEscaped in leaf-kit will only escape html special characters if the extended grapheme clusters match, which allows bypassing escaping by using an extended grapheme cluster containing both the special html character and some...

Read details

AI security incident: Cilium may not enforce host firewall policies when Native Routing, WireGuard and Node...

Incident date: February 19, 2026 | Published: February 25, 2026

Impact [Host Policies](https://docs.cilium.io/en/stable/security/policy/language/#host-policies) will incorrectly permit traffic from Pods on other nodes when all of the following configurations are enabled: * [Native Routing](https://docs.

Read details

AI security incident: CVE-2026-26057 (NVD)

Incident date: February 19, 2026 | Published: February 20, 2026

Skill Scanner is a security scanner for AI Agent Skills that detects prompt injection, data exfiltration, and malicious code patterns.

Read details

AI security incident: Keycloak: Missing Check on Disabled Client for Docker Registry Protocol (GHSA-fjf4-6f...

Incident date: February 19, 2026 | Published: February 25, 2026

A flaw was identified in the Docker v2 authentication endpoint of Keycloak, where tokens continue to be issued even after a Docker registry client has been administratively disabled.

Read details

AI security incident: Kata Container to Guest micro VM privilege escalation (GHSA-wwj6-vghv-5p64)

Incident date: February 19, 2026 | Published: February 25, 2026

Summary An issue in Kata with Cloud Hypervisor allows a user of the container to modify the file system used by the Guest micro VM ultimately achieving arbitrary code execution as root in said VM.

Read details

AI security incident: Unauthorized npm publish of cline@2.3.0 with modified postinstall script (GHSA-9ppg-j...

Incident date: February 19, 2026 | Published: February 25, 2026

Description On February 17, 2026 at 3:26 AM PT, an unauthorized party used a compromised npm publish token to publish an update to Cline CLI on the NPM registry: cline@2.3.0. The published package contains a modified package.

Read details

AI security incident: Kargo has an Authorization Bypass Vulnerability in Batch Resource Creation API Endpoi...

Incident date: February 19, 2026 | Published: February 25, 2026

Summary The batch resource creation endpoints of both Kargo's legacy gRPC API and newer REST API accept multi-document YAML payloads.

Read details

AI security incident: Kargo has Missing Authorization Vulnerabilities in Approval & Promotion REST API Endp...

Incident date: February 19, 2026 | Published: February 25, 2026

Summary Kargo's authorization model includes a promote verb -- a non-standard Kubernetes ["dolphin verb"](https://www.aquasec.com/blog/kubernetes-verbs/) -- that gates the ability to advance Freight through a promotion pipeline.

Read details