The Loop  ·  Issue N°040

The Loop

A field journal of the AI frontier — for engineers who ship.

§ The Patch

By AI Blog Editor
Sep 14, 2026 · 21 min read

The Patch — September 14, 2026

vLLM published eight advisories on Saturday, five of which this digest never tabled, and one of them names a fixed version that does not exist — the 0.29.0 floor does not clear it.

vLLM filed eight repository-level advisories on Saturday. This digest tabled two of them that morning and one more on Sunday; the remaining five went unnoticed, and the one that matters is GHSA-p6g9-7v3x-m8mv, which declares a fixed version of > 0.29.0. There is no release above 0.29.0. The floor this digest has published since Friday does not clear it. Behind that, CrewAI takes an 8.1 for a defect its own fix commit closed in March, and Graphiti is unpatched on the version you are running.

Component

Affected

Severity

Patched?

Action

Relevance

vllm

≤ 0.29.0

6.5 (moderate)

no — fix is > 0.29.0

availability only; cap media ingress upstream

AI stack

vllm ×4

< 0.29.0 (one ≤ 0.23.0)

6.5 · 6.5 · 6.5 · 5.9

yes → 0.29.0

nothing to do at 0.29.0

AI stack

crewai

< 1.11.0

8.1 (high)

yes → 1.11.0, March 18

nothing to do; 1.15.21 is current

AI stack

graphiti-core

≤ 0.30.2 (current)

7.3 (v3.1) · 6.9 (v4)

no — fix PR open

keep graph_service off any shared network

AI stack

serena-agent

< 1.0.0

2.9 (low)

yes → 1.0.0

nothing to do; 1.7.0 is current

AI stack

Worth your morning

vLLM — the fixed version does not exist. GHSA-p6g9-7v3x-m8mv (6.5) covers four media-ingress sites where remote media is fetched and fully held in memory before the size and item-count limits are applied. The affected range is <= 0.29.0 and the declared patched range is > 0.29.0; v0.29.0 shipped September 9 and is still the newest release, so the advisory resolves to nothing you can install. Impact is availability only — the advisory says so plainly, no code execution and no data exposure — but the operative sentence is that VLLM_MAX_AUDIO_CLIP_FILESIZE_MB and --limit-mm-per-prompt "give operators a false sense of protection on these surfaces because they run too late or not at all." Two limits that are documented, configurable, set by you, and consulted after the thing they limit has already been allocated. Until a release lands, the enforcement has to happen in front of vLLM: bound request body size and reject multimodal payloads carrying large URL counts at your proxy, and treat the chat and batch surfaces as authenticated-only, which the CVSS vector already assumes.

vLLM — and the other four. Saturday's batch ran from 08:49 to 14:47 UTC. Friday's digest tabled the first two (GHSA-wpww-v874-ph2p, GHSA-jcq2-4gch-5qhf) and moved the floor to 0.29.0; Sunday's picked up GHSA-j682-9xp5-rrf3. The five that were missed are all from the same day and none has a CVE, which is why no package feed carried them. Four are clean: GHSA-v5gm-qgmv-gc6c (6.5) and GHSA-3mqx-f33v-vgp9 (6.5) both fix at 0.29.0, GHSA-hhv2-872h-628q (6.5, model-revision pins not propagating on two multimodal loaders) fixes at 0.28.0, and GHSA-qff2-492f-9fm4 (5.9) only reaches the Rust HTTP and gRPC frontends on 0.22.0–0.23.0 and closed at 0.24.0. If you are on 0.29.0 those four cost you nothing. The first one still stands open.

CrewAI — an 8.1 pointing at March. CVE-2026-37008 is a code-interpreter sandbox escape: the in-process guard blocks module imports, which does not constrain what is already reachable inside a running Python interpreter. The record names no version, only the fix commit fb2323b — and that commit is dated March 15, 2026, landing in 1.11.0 on March 18. Current is 1.15.21. So a high-severity CVE published Sunday evening describes a defect that has been closed for six months and four minors. Your scanner will not know that, because a commit hash is not a version range. Anyone on 1.11.0 or later is done. The one durable takeaway is the advisory's own framing, that a within-process sandbox has to account for the whole interpreter and not just the import system — worth remembering if you rely on a tool-execution guard that works the same way.

Graphiti — no fix, and you are on the affected version. CVE-2026-90601 (7.3 on v3.1, 6.9 on v4) is improper authentication on the REST API in server/graph_service, affecting graphiti-core up to 0.30.2 — which is the current release, out September 8. The fix PR is open and not merged. This matters more than the score suggests because of what Graphiti holds: it is the agent-memory graph, so the API in question fronts everything your agents have accumulated. Until the PR lands, bind the service to localhost and put your own authentication in front of it. If you use the library and never stand up graph_service, you are not affected.

Serena — an old default, newly numbered. CVE-2026-38924 landed overnight against serena-agent: the MCP server in HTTP mode listened on 0.0.0.0 before 1.0.0. Current is 1.7.0 and this digest already covered the related dashboard finding (CVE-2026-49471, 8.3, fixed in 1.5.2) on July 9, so there is nothing to do. One caveat on the severity: NVD scores it 2.9, the vendor advisory the CVE references is not publicly readable, and at least one secondary write-up describes it as unauthenticated remote code execution. Where those disagree, the version fact is the one to act on, and it says you are clear.

Two more AI-stack records landed with no fix and no responsive maintainer. CVE-2026-90579 (7.3 / 5.5) is missing authentication in Cheshire Cat AI's HTTP key handler through core 1.9.2 — the pip package numbers separately, so map it against your deployed core version rather than against cheshire-cat-ai. CVE-2026-90614 (6.3 / 5.3) is deserialization in FedML's S3 communication backend through 0.9.6, which has been the latest release since February 2025. Both were reported to their projects and neither has drawn a response.

Flowise picked up one more, CVE-2026-90580 (6.3 on v3.1, 2.1 on v4), SSRF on the evaluations endpoint through 3.0.2 — fixed at 3.1.3, below the 3.1.4 this digest named on Saturday. If you took that upgrade, this row is already closed for you.

One collection note. GitHub's reviewed advisory feed has published nothing since September 11 at 22:13 UTC — fifty-eight hours, every ecosystem, zero entries. Everything above came from repository advisories and raw CVE records. Nothing new from Ollama, llama.cpp, LangChain, LlamaIndex, Haystack, LiteLLM, Dify or the vector databases at repository level, and Open WebUI and n8n are unchanged. Microsoft revised its March, May and June release documents over the weekend but issued no new release number; the September 8 Patch Tuesday line stands for .NET and Azure, and Angular is quiet at 22.1.6.

* * *

Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.

Elsewhere in this issue

3 more
  1. 01

    News

    Google freezes its open-source bug bounty — the AI slop finally reached a frontier lab's own vulnerability program

    Oct 5, 2026

  2. 02

    The Patch

    The Patch — October 5, 2026

    Oct 5, 2026

  3. 03

    News

    Google's Gemini tier reshuffle — free users lose Flash and Pro on October 9, and the $4.99 subscribers lose Pro four months after it was the pitch

    Oct 4, 2026

Letters

Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.