The Loop  ·  Issue N°040

The Loop

A field journal of the AI frontier — for engineers who ship.

§ The Patch

By AI Blog Editor
Oct 7, 2026 · 31 min read

The Patch — October 7, 2026

IBM filed 24 CVEs against Langflow 1.0.0 through 1.12.2 overnight, two of them 9.8 and reachable without an account, all fixed in 1.12.3.

Wednesday's lead is Langflow: IBM filed 24 CVEs overnight against versions 1.0.0 through 1.12.2. Two are 9.8 and need no account, and all are fixed in 1.12.3, which shipped on September 22. vLLM published seven advisories fixed in 0.31.0. Payload has a 10.0 in its Form Builder plugin among twenty September advisories this digest never covered. Most of them still aren't in GitHub's database.

Component

Affected

Severity

Patched?

Action

Relevance

Langflow ×24

1.0.0 – 1.12.2

9.8 ×2 · 8.8 ×8 · 14 more from 4.3 to 8.5

yes → 1.12.3 (Sep 22)

upgrade to 1.12.5; scanners won't raise these

AI stack

vLLM ×7

< 0.31.0

8.1 · 7.5 ×2 · 6.5 ×3 · 3.7

yes → 0.31.0 (Oct 5)

upgrade; put a proxy in front of /tokenize and /invocations

AI stack

Payload ×23

< 3.90.0 · 4.0 canaries < .34

10.0 · 9.3 (v4) · 8.8 (v4) · 8.7 ×3 · 8.6 (v4) · 8.1 ×2 · 14 lower

yes → 3.90.0 (Sep 18)

upgrade to 3.90.2

AI stack

sharp

< 0.35.5

8.9 (v4)

yes → 0.35.5 (Sep 27)

refresh lockfiles; block SVG decoding until you can

AI stack

shell-quote

1.8.4 – 1.10.x

8.1 · 9.2 (v4)

yes → 1.11.0 (Sep 29)

refresh lockfiles; concurrently pins 1.9.0

both

Obot ×4

< 0.26.2

8.1 · 6.5 · 4.3 · 4.2

yes → 0.26.2 (Oct 2)

upgrade; delete API keys nobody created on purpose

AI stack

Worth your morning

Langflow: 24 CVEs, one bulletin, a fix from September. Between 00:31 and 03:30 UTC, GitHub's feed took 24 CVE records from IBM against "Langflow OSS 1.0.0 through 1.12.2". All of them cite one IBM security bulletin, dated October 2, whose remediation is to upgrade to 1.12.3. Fifteen are code execution, led by CVE-2026-104334 and CVE-2026-93674 (9.8 each), whose scores assume no account and no user action. The rest cover path traversal, cross-user data exposure, credential exposure and a ZIP-import denial of service. 1.12.3 (September 22) carries the matching hardening: code-scanner sandbox fixes, a cache scoped to the user running the flow, an expanded-size limit on flow imports, and local file access restricted by default. The bulletin lists 25 CVEs, and one of them, CVE-2026-97677 (8.1), hasn't reached GitHub yet.

If you upgraded after the September 29 edition recommended 1.12.3, you already have these fixes. Otherwise go to 1.12.5 (October 6), which also restricts built-in code execution to administrators. The records carry no package mapping, so pip-audit and Dependabot won't raise any of them. The standing Langflow floor moves from 1.12.0 to 1.12.3.

vLLM: seven advisories, all fixed in the release from two days ago. vLLM published six advisories between 06:58 and 07:10 UTC yesterday and a seventh at 20:45, all fixed in 0.31.0 (October 5). The highest, GHSA-h3rc-6mm3-gc2m (8.1), is remote code execution through a per-request processor option. It only applies to servers started with --trust-remote-code and serving a model whose processor loads its own code. Two 7.5s and three 6.5s let a single request exhaust memory, hang the engine while /health stays green, crash it, or alias cache entries across requests. Prefix caching is on by default. Several of these are reachable through /tokenize, /invocations or /inference/v1/generate, and vLLM's --api-key doesn't cover those, so put an authenticating proxy in front either way.

0.31.0 also changes a default: the API server now rejects per-request mm_processor_kwargs and media_io_kwargs unless it starts with --trust-request-mm-kwargs. Leave that flag off unless every client is trusted. None of the seven has a CVE or a record in GitHub's database. One, GHSA-gx7p-2j49-hfq4, gives its range as >= 0.7.3 with no upper bound. If it's indexed that way, scanners will flag 0.31.0 as well.

Payload: a 10.0 from September 18, still invisible to scanners. Payload's repository dates twenty advisories to September 18, the day 3.90.0 shipped. No edition of this digest covered them. Yesterday they got CVEs (CVE-2026-105847 through CVE-2026-105868), but only nine entered GitHub's database. The eleven that didn't include the two worst. GHSA-r488-j9vj-wx3q (10.0) is remote code execution through crafted submissions to @payloadcms/plugin-form-builder, which has 158,000 downloads a week. GHSA-97rh-rhh2-7vjv (8.1) is code execution through the public first-register operation, on local-auth installs that haven't created their first user. Others cover the duplicate operation copying hidden and access-restricted fields (9.3 on v4), an order-confirmation check in the ecommerce plugin (8.8 on v4), SVG and XML uploads running script, and a second SQL injection in the SQLite adapters (Postgres was fixed in 3.73.0).

Three more went up yesterday afternoon: Jobs access bypass (8.7 on v4, fixed 3.89.0), account takeover through the MCP plugin's password-recovery tool (7.6 on v4, 3.90.0) and a hidden-field leak in its login tool (7.1 on v4, 3.88.0). Until you upgrade, the advisories' workarounds are to deny untrusted users the Jobs collection and to remove the forgot-password and login tools from MCP API keys. Everything is fixed by 3.90.0, and 3.90.2 is current. The floor moves up from the 3.88.0 this digest gave on September 25. Those five September 22 advisories, including the 9.8 SQL injection, entered GitHub's database yesterday too. Scanners now flag anything below 3.90.0, but through the nine indexed September 18 records, not the 10.0 or the first-register flaw.

sharp: an image library with 133 million weekly downloads takes a librsvg fix. GHSA-wq5f-xc86-pv6w (8.9 on v4) covers a memory bug in the bundled librsvg, CVE-2026-96889. Decoding a crafted SVG can lead to code execution on glibc-based Linux when the node binary isn't built as a position-independent executable, and the advisory notes the official Node.js binaries aren't. sharp 0.35.5 (September 27) ships the fixed library, and the record reached GitHub's database yesterday. Next.js 16.4 and Transformers.js 4.3 both accept ^0.35.4, so a lockfile refresh reaches it. The older @xenova/transformers 2.17.2 (761,000 a week) pins ^0.32.0 and can't. Until you upgrade, the advisory's workaround is sharp.block({ operation: ["VipsForeignLoadSvg"] }), or run a distribution-built Node.

shell-quote: the May fix left a gap. CVE-2026-102422 (8.1; 9.2 on v4) affects 1.8.4 through 1.10.x, at 97 million downloads a week. quote() can produce a command line that runs more than the caller intended when untrusted strings sit next to comment tokens, including output from parse() mixed with untrusted input. The range starts at 1.8.4 because that release fixed May's CVE-2026-9277 only partway. 1.11.0 (September 29) fixes it, and 1.12.0 is current. launch-editor, which webpack-dev-server depends on, accepts ^1.10.0, so a refresh moves it. concurrently 10.0.5 (26.6 million a week) pins exactly 1.9.0. Whether that use is exposed depends on what it passes to quote(), but the scanner flag won't clear until it releases or you add an overrides entry.

Obot: a login link could mint someone else's API key. GHSA-2qcm-3gv6-2mfc (8.1), published just before midnight, covers the CLI login flow before 0.26.0 (September 17). A signed-in user who opened one crafted link could have a long-lived API key issued to someone else, carrying the user's permissions, including the LLM gateway and MCP servers. For an admin, that is admin access. After upgrading, review your users' API keys and delete any that weren't created on purpose. If you can't upgrade yet, blocking POST /api/token-request at your proxy stops it, but it also breaks CLI login. Three lower advisories, CVE-2026-105138 to CVE-2026-105140, cover catalog entries exposing static configuration values, vMCP profiles not restricting prompts and resources, and a removed group membership coming back briefly. They take the floor to 0.26.2 (October 2), or 0.25.6 on the 0.25 line for the last one. None of the four is in GitHub's database.

Already fixed, now visible to scanners.

  • MCP TypeScript SDK GHSA-6qxp-vccf-f47h (CVE-2026-104850, 7.5), covered on October 3, is in GitHub's database, fixed in 1.31.0. 1.32.1 is current.
  • Langflow GHSA-8qpj (CVE-2026-10561, 9.9) and the SSRF advisory GHSA-j8f7 (6.3 on v4) are indexed, both fixed at or below 1.10.3.
  • LangChain.js: @langchain/redis CVE-2026-105799 (2.3 on v4, filter values not escaped in RediSearch queries) has been fixed since 1.1.1 in April, and yesterday's @langchain/mongodb advisory got CVE-2026-106119.
  • Docling GHSA-3cr3 (CVE-2026-105747) and knowns CVE-2026-86540 (fixed 0.30.0; the floor is 0.32.0) are indexed.

Standing items. Self-hosted Trigger.dev moves to 4.7.3 (October 6) for a 6.5 tenant-filtering bypass in query table placeholders, GHSA-m79r-84cc-xwg9. vLLM 0.31.0 still leaves the six KV-transfer CVEs from September 22 and the chat-template CVE-2026-90878 open. VulDB added two lows against it yesterday, CVE-2026-105775 and CVE-2026-105922 (4.3 each, "up to 0.31.0"). Both come from open bug reports of engine crashes: hybrid Mamba2 models with prefix caching and an explicit --mamba-block-size, and prompt embeddings combined with sampling penalties. Neither has a fix. SGLang's fix for CVE-2026-105245, PR 30343, was closed unmerged at 01:31 UTC today by a bot, for inactivity. The bug is a server-info endpoint that returns the server's API key. Keep those endpoints behind authentication.

Unchanged: mcp-server-fetch 2026.8.18 (the private-address guard is only on v2/main), Chroma 1.5.9 with both CVEs open, RAGFlow without a 0.27.3, MarkItDown 0.1.8 pinning mammoth~=1.11.0, LiteLLM 1.104.0 with CVE-2026-93355 unfixed, SGLang 0.5.21, Mooncake 0.3.13.post1, pandas-ai 3.0.0, LightLLM v1.2.0, Showdown 2.1.0 and the Milvus Helm chart 5.0.30. GitLab has tagged no AI Gateway image since September 17, and BrowserSkill PR 363 is unmerged.

For .NET. CVE-2026-105794 (9.1 on v4) entered GitHub's database yesterday: the OpenSSL build of MsQuic didn't check that the server's certificate matched the host it was connecting to. Microsoft.Native.Quic.MsQuic.OpenSSL is fixed in 2.4.20, 2.5.11 and 2.6.1 (August 28). The advisory names only the NuGet package, so on Linux hosts that use HTTP/3, also check the libmsquic system package against those versions. Kiota 1.35.0 fixes CVE-2026-105796 (8.8), where a malicious OpenAPI description could inject code into generated Java or PHP clients. C# output isn't named. Apache log4net 3.5.0 fixes CVE-2026-105242 (5.3), where a request could suppress its own log entry on ASP.NET for .NET Framework layouts that use %aspnet-request. Microsoft revised two older documents since yesterday, touching only Azure Linux packages and Windows 10 1809. Patch Tuesday is October 13.

* * *

Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.

Elsewhere in this issue

3 more
  1. 01

    News

    Mistral Large 4 ships at a trillion parameters — Europe's answer to the frontier labs is pitched at the work Claude Opus 5.5 and GPT-6 refuse to do

    Oct 7, 2026

  2. 02

    News

    $100,000 to $10,000 — Microsoft and Meta both cut internal Claude use in the same week Anthropic went direct to Barclays

    Oct 6, 2026

  3. 03

    The Patch

    The Patch — October 6, 2026

    Oct 6, 2026

Letters

Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.