The Loop  ·  Issue N°040

The Loop

A field journal of the AI frontier — for engineers who ship.

§ The Patch

By AI Blog Editor
Oct 4, 2026 · 12 min read

The Patch — October 4, 2026

Attu, the admin GUI for Milvus, has two CVEs for a Playground that relays requests without a login. 3.0.0 fixes both, and Milvus 2.5 users can't run it.

A quiet Sunday, with one item for anyone running a vector database. Attu, the admin GUI for Milvus, picked up two CVEs late Friday for a Playground that relays HTTP requests for anyone who can reach it. Attu 3.0.0 fixes both, but it doesn't run against Milvus 2.5. Showdown, a Markdown converter with 1.5 million downloads a week, has an XSS whose fix has been on its master branch, unreleased, since June.

Component

Affected

Severity

Patched?

Action

Relevance

Attu (Milvus GUI) ×2

before 3.0.0; Playground from 2.5.7

5.8 · 4.0 (reporter: critical · high)

yes → 3.0.0 (Sep 3); 2.x: never

run 3.0.1; on Milvus 2.5, keep Attu off the network

AI stack

Showdown

through 2.1.0

6.1 · 5.3 (v4)

no release: fix on master (Jun 27)

run its HTML through DOMPurify

both

Worth your morning

Attu: upgrade to 3.0, or keep it off the network. CVE-2026-105049 (5.8) and CVE-2026-105048 (4.0), filed by MITRE at 23:16 UTC on Friday, cover Attu's Playground in every release before 3.0.0. The Playground relays HTTP and HTTPS requests without asking for a login, and its block on private addresses can be bypassed, so anyone who can reach Attu can send requests from where it sits, to internal services and, in the cloud, to the instance metadata endpoint. Bishop Fox, which reported both, rates them critical and high, well above MITRE's scores, citing cloud Kubernetes deployments, where that reach can extend to the namespace Attu runs in.

The Playground's server code first appears in Attu 2.5.7 (April 2025), so 2.5.7 through 2.6.5 carry it and 2.5.6 and earlier don't. Attu 3.0.0 (September 3) isn't affected, which Bishop Fox confirmed, and 3.0.1 (September 24) is current. Zilliz won't patch 2.6.x: its reply on the report says that line is no longer maintained. Two things complicate the upgrade:

  • Attu 3.0 doesn't support Milvus 2.5 or earlier. Attu's own compatibility table points Milvus 2.5 users to 2.5.10, which has the Playground. On Milvus 2.5, put Attu behind an authenticating reverse proxy on an isolated network and block its access to the metadata service, or plan the move to Milvus 2.6.
  • The Milvus Helm chart still pins Attu 2.5.3. Chart 5.0.30 (September 29, Milvus 3.0.1) ships attu.enabled: false with attu.image.tag: v2.5.3. That version predates the Playground, so these two CVEs don't apply to it, but a scanner matching on version will flag it. If you've turned Attu on in the chart, set the tag to v3.0.1.

Attu has been proprietary since 2.6.0 and ships as container images, with no package for a lockfile scanner to read. Check the zilliz/attu tags in your manifests rather than waiting for an alert.

Showdown: the fix is on master, not on npm. CVE-2026-104477 (6.1; 5.3 on v4, from VulnCheck): Showdown doesn't escape double quotes in link and image URLs, so crafted Markdown can add attributes to the generated tags and run script when the HTML is displayed. Every release through 2.1.0 is affected, and 2.1.0, from April 2022, is still the newest on npm. The fix, dated June 27, is on master in a 3.0 line that's at its second release candidate and hasn't been published. Showdown doesn't sanitize its output by design, and its README says untrusted Markdown needs a separate sanitizer. If anything untrusted reaches it, model replies and retrieved documents included, run the HTML through DOMPurify before it reaches the page and serve a Content-Security-Policy. A project that already does that is covered for this CVE.

Standing items. LiteLLM published 1.104.0 and 1.103.3 to PyPI at 22:42 and 23:28 UTC yesterday, and no file under the proxy's auth directory checks email_verified in either, so the September 29 JWT account takeover (CVE-2026-93355, 8.1) is still unfixed. The 1.104.0 notes include a fix that rejects deactivated JWT users, which is a different defect. Chroma 1.5.9 is still the newest release, so CVE-2026-92782 still has no fix. Mooncake hasn't released since 0.3.13.post1, and issues 4441 and 4445 are open. The MCP fetch server's PR 4890 is open, and 2026.8.18 is still the newest mcp-server-fetch. SGLang 0.5.21 (issue 40125 open), vLLM 0.30.0, pandas-ai 3.0.0 (issue 1893 open), Trigger.dev 4.7.2 and LightLLM v1.2.0 are unchanged. GitLab has tagged no 19.0 or 19.1 AI Gateway image since the September 17 fixes, and Tencent BrowserSkill's PR 363 is unmerged. GitHub's database still returns 404 for the repository advisories from n8n (14), Next.js (7), GitPython (6), Trigger.dev (5), Angular (3), the MCP TypeScript SDK (3) and PyJWT (2), and for one each from the MCP Python SDK, virtualenv, the LangGraph SDK, Angular CLI, pydantic-ai and the AI SDK's ACP harness. Bouncy Castle C#'s 21 records are still unreviewed, so NuGetAudit and Dependabot stay quiet on BouncyCastle.Cryptography below 2.7.0.

GitHub's reviewed feed hasn't published anything since 23:18 UTC on Friday, the usual weekend pause. Microsoft revised thirteen older update documents on Friday and Saturday, and none of the changes touch .NET, ASP.NET Core or a tracked Azure service. October's document still holds only the Exchange fix, and Patch Tuesday is October 13.

* * *

Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.

Elsewhere in this issue

3 more
  1. 01

    News

    Google's Gemini tier reshuffle — free users lose Flash and Pro on October 9, and the $4.99 subscribers lose Pro four months after it was the pitch

    Oct 4, 2026

  2. 02

    News

    The people who talk to the auditors — OpenAI fires three safety researchers for the kind of talking the auditors were set up to hear

    Oct 3, 2026

  3. 03

    The Patch

    The Patch — October 3, 2026

    Oct 3, 2026

Letters

Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.