HIGH
GHSASUPPLY-CHAINLLM05: Improper Output Handling
2026-08-25
A malicious site can drive unauthenticated requests to a local MCP server and execute accepted actions from a victim browser.
HIGH
GHSASUPPLY-CHAINCVE-2026-45019LLM05: Supply Chain Vulnerabilities
2026-08-25
Unauthenticated SSRF can reach internal services or metadata endpoints when Chainlit MCP is enabled.
HIGH
GHSASUPPLY-CHAINLLM05:2025 Improper Output Handling
2026-08-25
MCP-controlled paths allow arbitrary file writes that can lead to host code execution under the process permissions.
HIGH
NVDSUPPLY-CHAINCVE-2026-82275LLM05: Supply Chain Vulnerabilities
2026-08-28
Unauthenticated attackers can read arbitrary server files through Qwen-Agent document parsing.
HIGH
GHSASUPPLY-CHAINLLM05:2025 Improper Output Handling
2026-09-04
Attacker-supplied regex can hang vLLM structured-output compilation and stall engine workers, causing denial of service.
HIGH
GHSASUPPLY-CHAINLLM10:2025 Unbounded Consumption
2026-09-04
Authenticated clients can force vLLM derender endpoints to spend unbounded CPU and memory, causing denial of service.
HIGH
GHSASUPPLY-CHAINCVE-2025-62164LLM05: Supply Chain Vulnerabilities
2026-09-04
Concurrent prompt parts can bypass sparse tensor validation in vLLM, reopening a known remediation gap.
2026-09-04
Unauthenticated malformed requests can expose usernames, paths, Python version, and package details useful for follow-on attacks.