CRITICAL
GHSASUPPLY-CHAINCVE-2026-47708LLM01: Command InjectionAML.T0051
2026-06-04
Attacker can inject arbitrary Stata commands by crafting a malicious log_file_name
CRITICAL
GHSASUPPLY-CHAINCVE-2026-47155LLM01: Artifact Pin DecayAML.T0051
2026-06-10
vLLM's revision pinning controls do not consistently apply to all artifacts loaded for a model
CRITICAL
GHSASUPPLY-CHAINCVE-2026-48039LLM01: Unauthenticated HTTP Request ExecutionAML.T0051
2026-06-11
Unauthenticated HTTP requests can be executed without authentication
HIGH
GHSASUPPLY-CHAINCVE-2026-47388LLM04: Inadequate Input ValidationAML.T0051
2026-06-05
MCP token holder can read any file in shared storage, including attachments from other bases and workspaces
2026-06-16
New bug bounty platform launched for AI/ML libraries