The Loop  ·  Issue N°040

The Loop

A field journal of the AI frontier — for engineers who ship.

§ The Patch

By AI Blog Editor
Sep 15, 2026 · 20 min read

The Patch — September 15, 2026

Langflow takes a 9.6 whose fix shipped in June, and it arrives with something none of Langflow's own advisories has ever carried — a declared fixed version.

Langflow takes a 9.6 this morning and the fix is twelve weeks old. That is the shape of the whole table: seven AI-stack records landed overnight, and every one that has a fix at all was fixed in June, August or early September. The two that have no fix — DocsGPT and Refly — are sitting on their current releases.

Component

Affected

Severity

Patched?

Action

Relevance

langflow

1.0.0 – 1.10.0

9.6 (critical)

yes → 1.10.1, June 23

nothing to do at 1.12.1; check the container is non-root

AI stack

wandb

< 0.29.0

8.8 (v3.1) · 8.7 (v4)

yes → 0.29.0, Aug 26

upgrade; 0.30.0 is current

AI stack

a2a-java ×2

1.2.0

7.3 · 4.3 (v3.1)

yes → 1.3.0.Final, Aug 27

upgrade; 1.3.2.Final is current

AI stack

WeKnora

< 0.7.0

6.5 (v3.1) · 7.1 (v4)

yes → 0.7.0

upgrade; 0.8.0 is current

AI stack

docsgpt

≤ 0.20.0 (current)

5.4 · 5.3

no

hold off on new cloud-storage connectors

AI stack

refly

≤ 1.1.0 (current since Feb)

5.0 · 5.3

no

restrict egress from the API container

AI stack

vllm

≤ 0.27.1 (claimed)

4.3 · 2.1 (low)

no — fix PR open

availability only; 0.29.0 does not clear it

AI stack

Worth your morning

Langflow — a critical that names a fixed version, which is new. CVE-2026-12944 (9.6) covers Langflow OSS 1.0.0 through 1.10.0: an authenticated user reaches arbitrary Python execution on the server, and in the published container that process runs as root. IBM's bulletin names 1.10.1 as the remediation. 1.10.1 shipped June 23, the bulletin went up July 2, and the advisory reached the feed this morning — ten weeks behind the vendor. Current is 1.12.1, out September 8, so anyone tracking releases has been clear since the summer. Two things are worth keeping. This digest wrote on Saturday that not one of Langflow's eight published advisories declares a fixed version; this record does, and the version comes from IBM's bulletin rather than the project's own feed, which remains the only place it has ever been stated. And the root detail belongs to how the image is run, not to the defect — the blast radius is the whole container because nothing in it drops privileges. Worth confirming your compose file names a non-root user whatever version you are on.

wandb — the trust direction is the interesting part. CVE-2026-91771 (8.8 on v3.1, 8.7 on v4) is path traversal in File.download: the client takes the file name out of the server's response and writes it without validating it, so a backend returning a name with traversal segments can place a file outside the download directory. The exposure runs from the server to your machine, which inverts the usual reading — it matters if you point the client at a self-hosted or third-party endpoint, or pull artifacts from a project you do not control. Fixed in 0.29.0 on August 26; 0.30.0 has been current since September 9. On wandb.ai and a current client, this is already closed.

Nothing here will reach your scanner. All seven records are unreviewed GitHub advisories with no package mapping, so no pip or npm feed carries them and no SCA tool will raise them against a lockfile. The reviewed feed itself came back on Sunday afternoon after sixty-six hours of silence and has published six entries since — ZITADEL, ESPHome Device Builder and October CMS — none of which touches the tracked stack. That leaves the two unpatched items to handle by hand. CVE-2026-91201 (5.4 / 5.3) has DocsGPT posting OAuth connector session tokens to a wildcard target origin in its callback-status endpoint, through 0.20.0 — which shipped September 12 and is the current release; until a fix lands, don't authorize new cloud-storage connectors, and re-issue any you granted recently. CVE-2026-91199 (5.0 / 5.3) is SSRF on Refly's scrape endpoint through 1.1.0, reaching loopback, private and link-local addresses; 1.1.0 has been the latest release since February 2, so egress control is the whole remediation.

Two shorter ones. The a2a-java pair (CVE-2026-90819, 7.3 on v3.1 but 6.9 on v4, and CVE-2026-90820, 4.3 / 5.3) both close at 1.3.0.Final from August 27, with 1.3.2.Final current — note that the first is scored high under 3.1 and medium under 4.0, so the label your tooling shows depends on which version it reads. WeKnora (CVE-2026-91750, 6.5 / 7.1) is a redirect that escapes the SSRF check on its knowledge-import endpoint, fixed at 0.7.0 with 0.8.0 current since September 3 — the v4 score crosses into high where the v3.1 score does not.

And one to read carefully. CVE-2026-90878 against vLLM declares an affected range of <= 0.27.1 and, in the same record, that the fix PR awaits acceptance. The PR is open and unmerged, so the upper bound marks where the reporter stopped looking rather than where the defect stops — 0.29.0 does not clear it. Impact is availability on the chat-completions path and the score is 2.1 under v4, so this is a note rather than a morning's work, but it does not belong under the 0.29.0 floor and your scanner will file it there.

Nothing new from Ollama, llama.cpp, LangChain, LlamaIndex, Haystack, LiteLLM, Open WebUI, n8n or the vector databases at repository level. Microsoft revised nine release documents overnight and none of the revisions touched .NET, ASP.NET Core, Azure or Visual Studio — the September 8 Patch Tuesday line stands. Angular is unchanged at 22.1.6, PrimeNG at 21.1.10.

* * *

Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.

Elsewhere in this issue

3 more
  1. 01

    News

    Google's Gemini tier reshuffle — free users lose Flash and Pro on October 9, and the $4.99 subscribers lose Pro four months after it was the pitch

    Oct 4, 2026

  2. 02

    The Patch

    The Patch — October 4, 2026

    Oct 4, 2026

  3. 03

    News

    The people who talk to the auditors — OpenAI fires three safety researchers for the kind of talking the auditors were set up to hear

    Oct 3, 2026

Letters

Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.