The Loop  ·  Issue N°040

The Loop

A field journal of the AI frontier — for engineers who ship.

§ The Patch

By AI Blog Editor
Oct 3, 2026 · 33 min read

The Patch — October 3, 2026

GitLab's self-hosted AI Gateway has a 9.9 to patch, and MCP TypeScript SDK 1.32.0 closes two advisories no scanner raises yet.

GitLab disclosed a 9.9 in its AI Gateway yesterday: on a self-hosted gateway, a user with Duo Agent Platform access can run commands on the gateway host. Gateways that GitLab hosts are already fixed. The MCP TypeScript SDK shipped 1.32.0 for two advisories that GitHub's database doesn't carry yet, and .NET teams get 21 Bouncy Castle CVEs, all fixed in a July release that the two older package IDs will never receive.

Component

Affected

Severity

Patched?

Action

Relevance

GitLab AI Gateway (self-hosted)

18.1.6 to before 19.2.4 · 19.3 < 19.3.2 · 19.4 < 19.4.1

9.9 (critical)

yes → 19.2.4 / 19.3.2 / 19.4.1 (images tagged Sep 17)

upgrade the gateway; 19.0 and 19.1 get no fix

AI stack

@modelcontextprotocol/sdk ×2

1.24.0 – 1.31.0 · every 1.x ≤ 1.31.0

8.6 · 6.5

yes → 1.32.0 / client 2.3.0 (Oct 2)

upgrade; the 8.6 needs a taskStore

AI stack

BouncyCastle.Cryptography ×21

< 2.7.0

9.1 (v4) · 20 high

yes → 2.7.0 (Jul 30); Portable.BouncyCastle, BouncyCastle: never

reference 2.7.0 directly; move off the old package IDs

Venicecom stack

Trigger.dev (self-hosted) ×7

≤ 4.6.0 · ≤ 4.6.2 · ≤ 4.7.0

8.3 · 8.1 ×2 · 7.9 · 7.1 · 6.5 · 3.5

yes → 4.6.0 (Sep 14) to 4.7.x

upgrade the webapp to 4.7.2

AI stack

pandas-ai

3.0.0, the newest release

unscored

no

run it in its Docker sandbox, with no credentials

AI stack

Worth your morning

GitLab AI Gateway: a 9.9 that only self-hosters need to act on. GitLab published CVE-2026-90970 (9.9) at 15:17 UTC yesterday. On a self-hosted AI Gateway, an authenticated user with Duo Agent Platform access can escape the prompt-template sandbox through a crafted flow configuration and run commands on the gateway. GitLab.com, GitLab Dedicated and self-managed instances that use the GitLab-hosted gateway need no action. The fixed self-hosted images, 19.2.4, 19.3.2 and 19.4.1, were tagged on September 17, so the fix is two weeks old and only the disclosure is new. Every gateway from 18.1.6 onward is affected, and the 19.0 and 19.1 lines get no fix, so move those to 19.2.4 or later. CISA's assessment on the record lists no known exploitation. Until the new image is running, limit Duo Agent Platform access to people you'd trust with a shell on the gateway host.

MCP TypeScript SDK 1.32.0: two fixes your scanner can't see yet. The SDK gets 72 million downloads a week. 1.32.0 reached npm at 17:32 UTC yesterday and @modelcontextprotocol/client 2.3.0 at 17:46, and the advisories followed between 20:42 and 20:54. GHSA-22jm-h49p-29qw (8.6): on an HTTP server that passes a taskStore to McpServer or Server, experimental tasks weren't tied to the session that created them, so another client could reach them. It affects 1.24.0 to 1.31.0, the 2.x packages aren't affected, and if a search for taskstore in your code outside node_modules finds nothing, you aren't either. If you can't upgrade, remove the taskStore or create one InMemoryTaskStore per session. GHSA-6prh-2h8m-c8cw (6.5): the HTTP and SSE client transports and the OAuth helpers followed cross-origin redirects and re-sent custom headers and request bodies, so a redirect could carry an API key or a client_secret to another host. Every 1.x release through 1.31.0 and client 2.0.0 to 2.2.0 are affected; stdio clients aren't. After the upgrade, redirects are followed only within the same origin, and setting redirectPolicy: 'follow' brings back the old behaviour along with the exposure. If a redirect may have reached a host you don't control, rotate those keys and revoke the tokens. The Python SDK published the same redirect fix as GHSA-5h93-6whr-6q8j (5.9), already shipped in mcp 1.30.0 and 2.2.0 on September 7. None of the three is in GitHub's database yet, and neither is September 28's GHSA-6qxp, which picked up CVE-2026-104850 yesterday.

Bouncy Castle C#: 21 CVEs for a release that shipped in July. At 09:31 UTC yesterday, 21 CVE records landed against bc-csharp "before 2.7.0": one critical (CVE-2026-63569, 9.1 on v4, in Diffie-Hellman key agreement) and twenty high. Most are denial of service from crafted input (ASN.1, PKCS#12, OpenPGP, X.509 names, DTLS), several weaken certificate path validation (name constraints, attribute certificates), and a few affect CCM, IES and CMS decryption. One matters more than its 8.7 suggests: the ASN.1 parser fault ends in a StackOverflowException, which .NET can't catch, so the whole process exits. The fix is BouncyCastle.Cryptography 2.7.0, published to NuGet on July 30. Three things decide whether you have it:

  • NuGet picks the lowest version a dependency allows. MimeKit up to 4.17.0 (and so MailKit) and iText's itext.bouncy-castle-adapter up to 9.7.0 declare 2.6.2 or later, so without a direct reference a restore resolves 2.6.2. MimeKit 4.18.0 (September 13) and the iText adapter 9.8.0 (September 30) require 2.7.0. A direct PackageReference to 2.7.0 settles it either way.
  • The older package IDs are frozen. Portable.BouncyCastle (last release 1.9.0, October 2021, 521 million downloads) and BouncyCastle (1.8.9, January 2021) fall inside "before 2.7.0" and won't get a fix. Migrate to BouncyCastle.Cryptography, and budget a build-and-test pass for the API changes in the 2.x line.
  • Nothing flags it yet. The records are unreviewed and have no NuGet mapping, so NuGetAudit, dotnet list package --vulnerable and Dependabot stay quiet until GitHub reviews them. GitHub's reviewed NuGet feed hasn't published anything since September 25.

Trigger.dev: a missed September batch, and one from yesterday. A correction first: Trigger.dev published five advisories on September 14, four of them high, and this digest didn't report them because the repository wasn't on its sweep list. It is now. The four highs (GHSA-xrp6-5fpv-4fxf 8.3, GHSA-4gjx-f5hj-678x 8.1, GHSA-jc26-22qp-cgqj 7.9, GHSA-9rx3-j5hm-5f27 7.1) let one tenant's API key freeze another organization's runs indefinitely, let a restricted API key read its environment's root secret and every secret stored as an environment variable, expose runs across deployments through the supervisor workload API, and let a GitHub App installation link be taken over. 4.6.0 carries the fixes and went out an hour and a half before the advisories. A medium followed on September 16 (≤ 4.6.2), and GHSA-qwrm-2cq8-xfr8 (8.1) at 04:29 UTC yesterday: an API key holder could suspend a run that belongs to another tenant. Its range includes 4.7.0, the version it calls fixed, and the September records have the same overlap, so take 4.7.2, released yesterday. These are server-side defects. Self-hosters upgrade the webapp image; on Trigger.dev Cloud the server is the vendor's to patch. Separately, GitHub's reviewed feed indexed ten July Trigger.dev records last night (up to 9.2 on v4), all fixed by 4.5.9. They map to the npm trigger.dev package, which is the CLI, so npm audit will flag an old CLI in a project even though the defects are in the server.

pandas-ai and SuperAGI: two agent projects with no fix coming. CVE-2026-51898, filed yesterday without a score, is a code injection in pandas-ai's CodeExecutor.execute, and it names 3.0.0, the newest release (October 2025). The report has been open since May 27 with no maintainer reply, and nothing has been pushed to the repository (23,800 stars) since October 2025. pandas-ai runs model-written Python by design, so treat anything that reaches it, the data and the question included, as able to run code. Use the project's DockerSandbox from pandasai-docker, or a container with no credentials and no network access it doesn't need. Four records against SuperAGI (17,700 stars), filed yesterday, say an authenticated user from one organization can create, schedule, run or delete another organization's agents through 0.0.14. That's the last release (January 2024), and the repository hasn't been pushed since January 2025. Run a SuperAGI deployment for one organization only, or retire it.

virtualenv moves its floor again. GHSA-5vjq-rrrf-7h2q (7.8): under zsh with the PROMPT_SUBST option, sourcing activate for an environment whose name contains shell syntax runs that syntax each time the prompt is drawn. Fixed in 21.14.4 at 13:49 UTC yesterday, and 21.14.5 is current, so the floor moves up from yesterday's 21.14.2. Until you upgrade, set VIRTUAL_ENV_DISABLE_PROMPT=1 before sourcing activate, and check the name of any environment you didn't create.

Paperwork your scanner may raise. All of these were fixed before their records appeared:

  • @a2ui/web_core: August's openUrl record (6.1) was withdrawn as a duplicate and reissued as GHSA-72qq-p3r5-f7wq at 9.3, now with CVE-2026-10032. The range is unchanged (0.9.0 to before 0.10.2, fixed June 19), and 0.12.0 is current. Expect the alert to come back as critical.
  • LangGraph SDK (not covered here before): GHSA-fvww-7h3r-vfhp (7.6 on v4) got CVE-2026-104873 yesterday. Custom auth ignored the actions= argument on resource decorators such as @auth.on.threads, so authorization handlers didn't apply as written. Fixed in langgraph-sdk 0.4.4 on August 27, with no workaround. It isn't in GitHub's database yet.
  • Angular SSR on Windows (not covered here before): GHSA-7g7c-h8rr-7p6q (6.3 on v4) got CVE-2026-104871 yesterday. CommonEngine on Windows can serve prerendered pages from a sibling directory whose name starts with the public directory's name. Fixed in @angular/ssr 22.1.7, 21.2.23 and 20.3.36 on September 2, and v19 won't be patched. The advisory's workaround normalizes request URLs in server.ts before they reach CommonEngine.render.
  • @fastify/busboy: two 7.5s reached the reviewed feed at 23:16 UTC, fixed in 3.2.1 (August 12). GHSA-x8mw-p69m-v3mx covers every version from 1.0.0, and the 2.x line has no fix. undici 5.x and 6.0 to 6.7.0 depend on @fastify/busboy ^2.0.0, so a project on those can't clear the alert by bumping busboy. undici 6.7.1 and later don't use it.
  • Vibe-Trading (34,000 stars): three records, two at 10.0, reached the reviewed feed. All are fixed in vibe-trading-ai 0.1.7 (May 6), and 0.1.16 is current.
  • Headroom: GHSA-h46j-26q3-rggf (8.8, cross-site WebSocket hijacking in headroom-ai) is fixed in 0.35.0 (August 13).
  • rmcp: the third of the Rust MCP SDK's June advisories, GHSA-c9xm-49cp-xcr9 (6.3 on v4), reached GitHub's database yesterday. It's fixed in 2.0.0, and 3.5.0 is current.
  • Mooncake: CVE-2026-104433 (7.5), a crash on the handshake path, is fixed in 0.3.12. The 0.3.13.post1 upgrade from yesterday covers it.

Standing items. Mooncake hasn't released since 0.3.13.post1, and issues 4441 and 4445 are open with no maintainer reply, so yesterday's row stands. The MCP fetch server's SSRF guard, PR 4890, is still open, and 2026.8.18 is still the newest mcp-server-fetch on PyPI. SGLang 0.5.21 is still the newest release, with issue 40125 open. LiteLLM's newest stable is still 1.103.2. vLLM is at 0.30.0, Milvus at 2.6.25 and 3.0.2, LightLLM at v1.2.0 with issue 1576 open, NLTK at 3.10.3 and mcp-remote at 0.14.3. Tencent BrowserSkill's community fix, PR 363, is unmerged. Angular's LTS builds still pin piscina 5.2.0 (v20, v21) and 4.8.0 (v19), and v21 still pins webpack-dev-middleware 7.4.5. The repository advisories from n8n (14), GitPython (6), Next.js (7), Angular (3), PyJWT (2), pydantic-ai and the AI SDK's ACP harness still return 404 in GitHub's database. The ACP record hasn't arrived with its wrong package name yet.

On the Microsoft side, the October update document opened early, on October 2, with a single fix: CVE-2026-96940, an Exchange Server elevation of privilege (8.8), not exploited and not publicly disclosed. There's nothing for .NET, ASP.NET Core or Azure, and no tracked product in the September document has been revised since September 29. Patch Tuesday is October 13.

* * *

Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.

Elsewhere in this issue

3 more
  1. 01

    News

    Google freezes its open-source bug bounty — the AI slop finally reached a frontier lab's own vulnerability program

    Oct 5, 2026

  2. 02

    The Patch

    The Patch — October 5, 2026

    Oct 5, 2026

  3. 03

    News

    Google's Gemini tier reshuffle — free users lose Flash and Pro on October 9, and the $4.99 subscribers lose Pro four months after it was the pitch

    Oct 4, 2026

Letters

Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.