By AI Blog Editor
Oct 5, 2026 · 20 min read
The Patch — October 5, 2026
AutoGPT disclosed a 10.0 for self-hosted platforms that kept the default JWT secret. 0.8.0 fixes it, and RAGFlow's agent authorization fix isn't in any release yet.
Monday's lead is AutoGPT: two advisories this morning for self-hosted AutoGPT Platform deployments that kept the default secrets, one of them a 10.0. RAGFlow's maintainers disclosed an agent authorization flaw whose fix isn't in any release you can upgrade to. Mammoth, the Word-to-HTML converter that several document loaders use, has a CVE for a denial of service fixed in September, and its Python port has the same fix with no CVE.
Component | Affected | Severity | Patched? | Action | Relevance |
|---|---|---|---|---|---|
AutoGPT Platform ×2 | 10.0 · 8.2 | yes → 0.8.0 (Sep 19) | run 0.8.2; rotate the encryption key and stored credentials if you kept the defaults | AI stack | |
RAGFlow | 7.1 | no release: fix merged Sep 18, after 0.27.2 | set | AI stack | |
Mammoth (.docx → HTML) | 7.5 · 8.7 (v4) | yes → 1.12.3 (Sep 12); Python: 1.12.2 | upgrade; refresh lockfiles | both | |
MindSearch · R2R · Verba | 10.0 · 7.3 · 5.3 | never: vendors didn't respond; Verba archived | retire, or keep off shared networks | AI stack |
Worth your morning
AutoGPT: the defaults were the secrets. AutoGPT published two advisories at 04:57 UTC today for the self-hosted AutoGPT Platform. GHSA-24q6-6h89-f9p7 (10.0): a deployment that kept the default .env verifies logins with a JWT key published in the repository, so anyone can mint valid tokens for any user or as an admin. That gives them agents, execution history, stored credentials and workspace files, plus admin routes and agent runs billed to other users. GHSA-57mf-wqwq-6g6x (8.2): the default ENCRYPTION_KEY that protects stored OAuth tokens and LLM API keys is just as public, so anyone who gets a copy of the database can decrypt them. The first affects 0.6.26 through 0.7.4, the second 0.6.23 through 0.7.4.
The fixes merged on September 16 and 17 and shipped in 0.8.0 on September 19, sixteen days before the advisories. 0.8.0 removes the default JWT key, rejects HS-signed tokens, ships ENCRYPTION_KEY blank, refuses to start on the old default, and adds a key-rotation command. 0.8.2 (September 30) is current. If you ran an affected version on the defaults and anyone else could reach it, upgrade, rotate the encryption key, and revoke and reconnect the OAuth connections and API keys it stored. Neither advisory has a CVE or a record in GitHub's global database, and the platform deploys from the repository rather than a package, so no scanner will raise them. Check which tag your checkout is on.
RAGFlow: fixed in the code, not in a release you can run. GHSA-c6q8-23rp-32cv (7.1), published by the maintainers at 04:38 UTC today: RAGFlow's OpenAI-compatible agent completion endpoint doesn't check whether the caller may use the agent. Any logged-in user who knows a private agent's ID can run it and read its output, across users and tenants. Versions 0.25.2 through 0.27.2 are affected, and the advisory names no fixed version. The fix, PR 19817, merged on September 18, eight days after 0.27.2, and there is no 0.27.3. v1.0.0-rc1 (September 29) includes the commit, but it's a preview of a rewrite in Go, its data migration from 0.27.2 can't be rolled back, and its notes list the Team/Me permission model as not yet supported.
Until a fixed release ships, "any logged-in user" means anyone who can register, and RAGFlow's Docker .env ships with REGISTER_ENABLED=1. Set it to 0 on any instance other people can reach, and don't put data or tools behind a private agent that you wouldn't show every account holder. GitHub's global database doesn't carry this advisory either.
Mammoth: fixed in September, and the Python port has no CVE. CVE-2026-105219 (7.5; 8.7 on v4), filed by VulnCheck yesterday: a .docx with a crafted embedded style map can stall Mammoth's style-map parser, a denial of service for anything that converts uploaded Word files. Mammoth.js 1.3.0 through 1.12.2 are affected. 1.12.3 (September 12) fixes it and 1.13.0 is current, at 11.6 million downloads a week. LangChain.js's community package and @llamaindex/readers declare mammoth at ^1.11.0 and Flowise's components at ^1.5.1, so all three accept the fixed version and a lockfile refresh is enough.
The Python port, mammoth on PyPI, got the same fix the same morning in 1.12.2, with the same changelog entry. The CVE names only the JavaScript package, so no scanner flags Python versions before 1.12.2. Microsoft's MarkItDown, a document-to-Markdown converter built for LLM pipelines, pins mammoth~=1.11.0 for its docx extra, including in 0.1.8 (September 21), so markitdown[docx] can't install the fix. Where you can't upgrade, turn off embedded style maps (includeEmbeddedStyleMap: false in JavaScript, include_embedded_style_map=False in Python) and run conversions in a separate thread with a timeout, as both changelogs advise.
Three dormant AI apps, three CVEs that won't be fixed. VulDB filed three CVEs yesterday from one reporter, and each record says the vendor was contacted and didn't respond. InternLM's MindSearch (CVE-2026-105135, 10.0; 9.3 on v4) has code injection in its planner agent. Its only release is v0.1.0 from November 2024, and the repository has been idle since July 2025. SciPhi's R2R (CVE-2026-105148, 7.3; 5.5 on v4) has a server-side request forgery in its retrieval completion API in every release through 3.6.6, the newest on PyPI (August 2025). Its repository was last pushed in November 2025. Weaviate's Verba (CVE-2026-105145, 5.3) has an information disclosure in its streaming endpoint through 2.1.3. Weaviate has archived Verba, and its README says the project won't get security patches. If you still run any of them, take it off networks other people can reach, or replace it.
Standing items. The MCP fetch server's private-address guard (CVE-2026-104120) has merged but hasn't shipped. The maintainers closed PR 4890 at 06:14 UTC today as superseded by PR 5033, which merged at 04:48 UTC into the v2/main branch, 331 commits ahead of main. With it, the server refuses private, loopback, link-local and cloud-metadata addresses by default, checks every redirect, and takes --allow-private-ips to turn the guard off. Its README says the guard doesn't cover DNS rebinding. mcp-server-fetch 2026.8.18 is still the newest on PyPI, so keep the egress controls in place until a release carries it.
LiteLLM has no stable release after 1.104.0, so the JWT account takeover (CVE-2026-93355) is still unfixed. Chroma 1.5.9 is still the newest release, Mooncake hasn't released since 0.3.13.post1, and Showdown's newest on npm is still 2.1.0. SGLang 0.5.21, vLLM 0.30.0, pandas-ai 3.0.0, Trigger.dev 4.7.2 and LightLLM v1.2.0 are unchanged, and the SGLang, pandas-ai and LightLLM issues are still open. GitLab has tagged no 19.0 or 19.1 AI Gateway image since September 17, Tencent BrowserSkill's PR 363 is unmerged, and the Milvus Helm chart still pins Attu 2.5.3. GitHub's database still returns 404 for the repository advisories from n8n (14), Next.js (7), GitPython (6), Trigger.dev (5), Angular (3), the MCP TypeScript SDK (3) and PyJWT (2), and for one each from the MCP Python SDK, virtualenv, the LangGraph SDK, Angular CLI, pydantic-ai and the AI SDK's ACP harness. Bouncy Castle C#'s 21 records are still unreviewed.
Nothing new for the .NET or Angular stack. GitHub's reviewed feed hasn't published anything since 23:18 UTC on Friday. Microsoft hasn't revised a document since early Sunday, and none of the weekend's revisions touch .NET, ASP.NET Core or a tracked Azure service. Patch Tuesday is October 13.
* * *
Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.
Elsewhere in this issue
3 more- 01
News
Google's Gemini tier reshuffle — free users lose Flash and Pro on October 9, and the $4.99 subscribers lose Pro four months after it was the pitch
Oct 4, 2026
- 02
The Patch
The Patch — October 4, 2026
Oct 4, 2026
- 03
News
The people who talk to the auditors — OpenAI fires three safety researchers for the kind of talking the auditors were set up to hear
Oct 3, 2026
Letters
Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.