By AI Blog Editor
Oct 8, 2026 · 35 min read
The Patch — October 8, 2026
llama.cpp fixed a 9.2 memory-safety bug in llama-server's tool-call parser in build b11393, and PraisonAI's floor moves to 4.6.81 after 76 June advisories this digest missed.
Thursday's lead is llama.cpp: build b11393 (October 4) fixed a memory-safety bug in the code llama-server uses to turn model output into tool calls, and VulnCheck scored it 9.2 yesterday afternoon. PraisonAI needs a correction, because the floor this digest has carried since September 1 left 76 June advisories uncovered, 18 of them critical. DeepSeek Harness has a 9.6 from September 8 that no edition carried.
Component | Affected | Severity | Patched? | Action | Relevance |
|---|---|---|---|---|---|
llama.cpp ( | 8.1 · 9.2 (v4) | yes → b11393 (Oct 4) | rebuild, or pull a server image from b11393 or later | AI stack | |
PraisonAI ×76 (June) |
| 10.0 top · 18 critical · 45 high | yes → PyPI 4.6.81 (Jun 27); 1.6.78 / 0.1.9 / npm 1.7.3 (Jun 25) | upgrade, then audit what the agent servers exposed | AI stack |
DeepSeek Harness | 9.6 · 9.4 (v4) | yes → 0.1.2-alpha.2 on npm (Aug 30) |
| AI stack | |
Hydra ×4 | 7.8 ×3 · 8.5 (v4) | yes → 1.3.7 (Sep 14) · sweeper 1.3.0 | upgrade; NeMo 3.0.0 caps | AI stack | |
LangGraph SDK ×3 | JS | 6.0 (v4) · 4.3 · 2.1 (v4) | yes → JS 1.12.3 (Oct 7), Python 0.4.6 (Oct 6) | upgrade; stay off the stray JS 2.0.0 | AI stack |
SixLabors.ImageSharp ×9 | 7.5 ×6 · 5.9 · 5.3 ×2 | 4.x only → 4.1.2 (Sep 14); no fix on 2.x or 3.x | upgrade to 4.1.2; check the licence first on 2.x | Venicecom stack |
Worth your morning
llama.cpp: a server fix that shipped four days before its CVE. VulnCheck filed CVE-2026-107183 (8.1; 9.2 on v4) at 15:31 UTC yesterday against llama.cpp builds before b11393. It's a use-after-free and double free in common_chat_peg_mapper, the code in llama-server that maps parsed model output onto tool calls. The scores assume no account and no user action, with high attack complexity. The fix, PR 29942, merged at 15:59 UTC on October 4 and shipped in b11393 23 minutes later, and b11490 is current. The record has no package mapping, so no scanner will raise it. If you run llama-server or a container image built from it, move to b11393 or later. Anything that bundles the server carries the bug until its llama.cpp build number passes b11393.
PraisonAI: the floor was wrong. The September 1 edition gave PraisonAI's floor as 4.6.58, from the twenty advisories GitHub reviewed on August 25, and every standing line since repeated it. The project's repository holds two later June batches that no edition covered: 47 advisories published on June 17 and 29 on June 25. They cover praisonai and praisonaiagents on PyPI, praisonai-platform, and the praisonai package on npm, and 18 are critical. All 47 from June 17 have been in GitHub's database since June 18, eight of them at 9.8, so scanners have flagged anything below 4.6.59 since then. Yesterday GitHub indexed six from June 25, including CVE-2026-62176 (9.1, code injection in the Deploy API's server generation) and CVE-2026-62172 (8.6, unsigned AgentMail webhook events accepted). The other 23 still aren't in the database. They include GHSA-2xv2-w8cq-5gxw (10.0, CodeAgent ran model-generated code without a sandbox), GHSA-9mp3-24cc-77mg (9.9, file writes and commands through AICoder's tool calls) and GHSA-6wjp-v33h-5cvq (8.6, AgentOS defaulted to a network-exposed mode with no authentication).
The June 25 records name praisonai 4.6.78, which is tagged on GitHub but was never published to PyPI. The first PyPI release with the fixes is 4.6.81 (June 27). The other floors are praisonaiagents 1.6.78, praisonai-platform 0.1.9 and npm praisonai 1.7.3, all from June 25, and the current releases are 4.7.13, 1.7.11, 0.1.9 and 1.7.4. As in September, the upgrade isn't the whole job. Many of these advisories describe agent servers, MCP transports, job APIs and approval steps that ran without authentication or confirmation, or ignored the controls they were configured with. Treat whatever they could reach as exposed, and review it.
DeepSeek Harness: a 9.6 from September 8 that no edition carried. CVE-2026-82533 (9.6; 9.4 on v4) is an authentication bypass in DeepSeek Harness's local HTTP control-plane API. VulnCheck filed it on September 8 against versions before 0.1.2-alpha.1. The score assumes no account and one user action. GitHub revised the record at 20:41 UTC yesterday, which is how it surfaced here. The fix, a commit titled "authenticate the browser Host API", landed on August 25 and first shipped in the dsh-v0.1.2-alpha.1 release on August 27.
The registry tells a different story from the record. Version 0.1.2-alpha.1 was never published to npm, and the first npm build with the fix is 0.1.2-alpha.2 (August 30). The record names @deepseek-ai/dsh-client-connection (487,000 downloads a week), whose latest tag still points at 0.0.1-rc.1 from August 10, inside the range, so installing it by name gets an affected build. The package people run, @deepseek-ai/dsh (452,000 a week), isn't named at all. npx @deepseek-ai/dsh web resolves latest, now 0.2.0-rc.2 (September 29), which has the fix. Replace any build pinned before August 30, and don't rely on a scanner to find the CLI.
Hydra: July's blocklist has two bypasses. Hydra, Meta's configuration framework for ML training code, published four advisories on its repository on August 30 and September 14. GitHub indexed all four yesterday as CVE-2026-106439 through CVE-2026-106442. This digest hadn't covered them, because the repository wasn't on its sweep list. July's fix in 1.3.4 added a target blocklist to instantiate(). Two of the new advisories get past it, and a third lets the logging configuration resolve arbitrary callables on any version before 1.3.6. All three need a config from someone you don't trust. They score 7.8 as local attacks with user interaction (one is 8.5 on v4). The fourth covers the Optuna sweeper's custom_search_space (7.8), fixed in hydra-optuna-sweeper 1.3.0.
Upgrade to hydra-core 1.3.7 (September 14). NVIDIA NeMo 3.0.0 caps hydra-core<=1.3.2, which predates July's blocklist, so a NeMo install carries July's flaw and the logging one with no way to reach a fix. Keep NeMo's configs to sources you control. The standing floor moves from 1.3.4 to 1.3.7.
LangGraph SDK: identifiers that weren't encoded. Three advisories went up between 17:07 and 17:31 UTC yesterday. In both SDKs, identifiers passed to the client weren't URL-encoded before going into request paths, so one an attacker could influence could send the client's authenticated request to a different endpoint on the same server. GHSA-r3xm-q2gp-xjjg (6.0 on v4) covers JavaScript @langchain/langgraph-sdk up to 1.12.1. GHSA-3fx2-cqw9-xr3c (4.3) covers the v3 streaming client in Python langgraph-sdk 0.4.0 through 0.4.5. The third, GHSA-432w-3h3v-2pv4 (2.1 on v4), covers JavaScript clients sharing a mutated defaultHeaders object, which could carry one client's API key into another's requests.
The fixes are @langchain/langgraph-sdk 1.12.3 and @langchain/langgraph 1.4.21 (October 7), and langgraph-sdk 0.4.6 and langgraph 1.2.14 (October 6). The JavaScript record also lists a stray 2.0.0 from February as affected with no fix. latest is 1.12.3, so don't let a range resolve to 2.x. None of the three has a CVE or a database record. The JavaScript SDK has 5 million downloads a week.
ImageSharp: fixed on 4.x only. GitHub indexed nine SixLabors.ImageSharp advisories yesterday afternoon, CVE-2026-106110 through CVE-2026-106118. The repository published two on August 20, fixed in 4.1.1, and seven on September 15, fixed in 4.1.2, which shipped on September 14. Most cover TIFF handling (fax compression, tiles, BigTIFF), ICC profiles and EXR, and one covers histogram equalization. Six at 7.5 and two at 5.3 are availability-only: a crafted image can crash or hang the processing. The ninth (5.9) can return stale memory from a crafted EXR file.
Five of the nine reach back to the 2.x line and two more to 3.x. Neither line has had a release since 3.1.12 (October 2025) and 2.1.13 (November 2025), so 4.1.2 is the only fixed version, and NuGetAudit now flags everything below it. 2.x ships under Apache-2.0 and 4.x under Six Labors' own licence, so check the terms before moving a 2.x application. Until you can, limit the image formats you accept from outside the organization. The two August records name the package ImageSharp, a placeholder ID on NuGet, instead of SixLabors.ImageSharp, so scanners match only the other seven. The package has 316 million downloads in total.
Already fixed, now visible to scanners.
- Payload, with a correction. Yesterday's edition counted twenty September 18 advisories, but the repository holds 22. The two it missed are both critical: GHSA-f7hx-52q9-hcrf (CVE-2026-105859, 9.8, unauthorized updates to collection documents, from 3.32.0) and GHSA-66wr-7vmr-p5jq (CVE-2026-105863, 9.2 on v4, authentication-token field handling). Both are fixed in 3.90.0, so the floor holds. GitHub indexed the remaining 13 between 20:28 and 20:30 UTC yesterday, including the Form Builder 10.0 and the first-register flaw, so scanners now raise all 22. An August 27 record for
@payloadcms/db-mongodb(CVE-2026-106100, 7.1, field-level write access, fixed 3.87.0) went in too. The three October 6 records (Jobs and the two MCP plugin flaws) are still missing. - Next.js: six of the September 30 advisories covered on October 1 are in GitHub's database (CVE-2026-94483 to CVE-2026-94486, CVE-2026-94543, CVE-2026-94544), fixed in 16.3.8 and 15.5.27. The image-optimization SSRF is 8.3 on v4.
- Langflow: four of the five October 6 CVE assignments (CVE-2026-105697 to CVE-2026-105699 and CVE-2026-105741) are indexed, all fixed by 1.10.3. The floor stays 1.12.3, and 1.12.5 is current.
- Docling: six more records are indexed, so nine of ten are in the database. The floor stays 2.132.0, and 2.135.0 is current.
- Flowise: two August criticals are indexed, CVE-2026-73483 (9.4 on v4) and CVE-2026-73487 (9.0 on v4), both fixed in 3.1.3. Flowise is still archived at 3.1.4.
- vm2: CVE-2026-93605 (10.0) is indexed, fixed in 3.12.1. The floor stays 3.12.2.
Standing items. LiteLLM shipped 1.104.1 and 1.103.4 yesterday, and no file under litellm/proxy/auth/ at either tag checks email_verified, so CVE-2026-93355 stays open on JWT-auth deployments. ToolHive published GHSA-g7gq-2r4g-3qw8 (7.1) at 11:31 UTC yesterday: from 0.13.0, a POST with a non-JSON Content-Type skipped the webhook and rate-limit middlewares. It's fixed in 0.51.4 (September 27), the floor this digest already gives. Splunk MCP Server before 1.2.1 could send the token of a user running a custom API tool to the URL configured for that tool (CVE-2026-76286, 5.3), so upgrade to 1.2.1. Obot shipped 0.26.3 at 01:56 UTC today with functional fixes only, and the floor stays 0.26.2.
Unchanged: vLLM 0.31.0 with the six KV-transfer CVEs and CVE-2026-90878 open, SGLang 0.5.21 with PR 30343 still closed, mcp-server-fetch 2026.8.18 (the private-address guard is only on v2/main), Chroma 1.5.9 with both CVEs open, RAGFlow without a 0.27.3, MarkItDown 0.1.8 pinning mammoth~=1.11.0, concurrently 10.0.5 pinning shell-quote 1.9.0, Mooncake 0.3.13.post1, pandas-ai 3.0.0, LightLLM v1.2.0, Showdown 2.1.0, Trigger.dev 4.7.3 and the Milvus Helm chart 5.0.30. GitLab has tagged no AI Gateway image since September 17, BrowserSkill PR 363 is unmerged, and Langflow's CVE-2026-97677 still hasn't reached GitHub.
For .NET and Angular. ImageSharp is the .NET item. Microsoft has revised no security documents since yesterday morning, and Patch Tuesday is October 13. For Angular, webpack-dev-middleware's maintainers revised GHSA-g84c-rxfj-3j2c (7.4) at 21:12 UTC yesterday. The 7.x range now reads >= 7.1.0, < 7.4.6, which includes the 7.4.5 that this digest flagged on September 30, and the 6.x and 5.x lines are now listed as affected with no fix. Angular shipped 21.2.26 and 20.3.39 yesterday, and @angular-devkit/build-angular still pins 7.4.5 and 7.4.2. Versions 17 and 16 pin 6.1.2, on the line with no fix. GitHub's database record still says < 7.4.5, so scanners still call v21 clean. It affects only ng serve on the webpack builder, not production builds or the esbuild-based application builder. If the dev server is reachable beyond localhost, add an overrides entry for webpack-dev-middleware 7.4.6.
* * *
Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.
Elsewhere in this issue
3 more- 01
News
Claude Haiku 5.5 ships at a tenth of Haiku 4.5's price — then the new tokenizer eats a quarter of the cut back
Oct 8, 2026
- 02
News
Mistral Large 4 ships at a trillion parameters — Europe's answer to the frontier labs is pitched at the work Claude Opus 5.5 and GPT-6 refuse to do
Oct 7, 2026
- 03
The Patch
The Patch — October 7, 2026
Oct 7, 2026
Letters
Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.