By AI Blog Editor
Oct 9, 2026 · 33 min read
The Patch — October 9, 2026
Ollama 0.34.2 through 0.34.4 let an unauthenticated model pull write files outside the model store (9.4, fixed in 0.35.0), and SGLang has a 9.8 that no release fixes.
Friday's lead is Ollama: versions 0.34.2 through 0.34.4 let anyone who can reach the API make a model pull write a file outside the model store, scored 9.4, and 0.35.0 fixed it on September 28. SGLang has a 9.8 in its inter-process messaging that no release fixes. Pydantic AI needs a correction, because nine of its advisories from July to September never appeared here, and seven of them reached GitHub's database yesterday.
Component | Affected | Severity | Patched? | Action | Relevance |
|---|---|---|---|---|---|
Ollama | 9.4 (v4) | yes → 0.35.0 (Sep 28) | upgrade to 0.40.2; keep port 11434 off networks you don't control | AI stack | |
SGLang | 9.8 | no | keep | AI stack | |
Pydantic AI ×9 (Jul–Sep) | 7.6 · 6.8 · 6.5 ×3 · 6.4 · 3.7 · 2.3 ×2 (v4) | yes → 1.107.6 / 2.44.0 (Sep 17) | upgrade; the floor stays 1.107.7 / 2.53.0 | AI stack | |
LangGraph.js ×3 | 7.6 (v4) · 7.1 · 2.3 (v4) | yes → 1.4.21 (Oct 7); stores Oct 6 | upgrade; don't pass client JSON straight into a graph | AI stack | |
Banks ×2 | 6.5 · unscored | yes → 2.5.1 (Sep 10) | refresh lockfiles; LlamaIndex accepts 2.5.1 | AI stack | |
Handlebars ×3 | 9.8 · 9.2 (v4) · 4.7 | yes → 4.7.10 (Oct 5) | upgrade; pass only strings to | Venicecom stack |
Worth your morning
Ollama: a model pull that writes outside the model store. CERT Polska published CVE-2026-103663 (9.4 on v4) yesterday, and it reached GitHub's feed at 15:32 UTC. The /api/pull endpoint didn't validate layer digests, so a request from anyone who can reach the API, with no account, could make Ollama write a file outside its model store. Ollama's Docker images let the server write to /usr/lib/ollama, and on those images the result can be code running as root after the next restart. CERT Polska gives the affected range as 0.34.2 up to 0.35.0, which covers 0.34.2, 0.34.3 and 0.34.4, released between September 15 and 23. Version 0.35.0 (September 28) checks every digest before a download or upload starts. Its release notes cover decision models and a macOS menu icon, and say nothing about the fix. 0.40.2, released yesterday, is current.
Ollama's API has no authentication of its own, so keep port 11434 on localhost or behind an authenticating proxy whatever version you run. If a server in the affected range was reachable from a network you don't control, check /usr/lib/ollama (or your install's library directory) for files the release didn't ship, and rebuild the container from a fixed image. Ollama ships as a binary, and the record names no package, so no scanner will raise it.
SGLang: a 9.8 with no fix in any release. CERT/CC filed CVE-2026-93034 (9.8) yesterday. SGLang's ZeroMQ message decoder deserializes pickled payloads with no type allowlist and no authentication, and turning off SGLANG_USE_PICKLE_IPC doesn't remove that path. The record names no versions. The function first appears in v0.5.15 (July 10) and is unchanged in 0.5.21 (October 2, current) and on main. No open pull request touches it. The record says the flaw becomes reachable from the network when data-parallel attention runs with a non-loopback --dist-init-addr. On a single host, keep that address on loopback. On a multi-node cluster, put it on a private interface that only the other nodes can reach, and firewall the ZeroMQ ports. It joins the other SGLang CVEs this digest carries without a fix.
Pydantic AI: nine advisories this digest never covered. This digest covered two Pydantic AI advisories, on September 30 and October 2. The repository holds nine more, published between July 11 and September 17, that no edition mentioned. Yesterday afternoon the eight from August and September got CVEs (CVE-2026-107288 to CVE-2026-107295) and GitHub indexed seven of them, so scanners now raise them. The July one has carried CVE-2026-65975 since July.
The highest, GHSA-h4xc-3qfq-jf93 (7.6), covers the local web chat UI that Agent.to_web() and clai web serve. A website the developer visited while it was running could start agent runs and server-side tool calls. Tools marked requires_approval=True weren't protected, because the endpoint trusted approval decisions sent by the client. A second advisory (6.4) covers DNS rebinding against the same endpoint. The others cover a bypass of the cloud-metadata SSRF blocklist (6.8), resource exhaustion in web_fetch and remote downloads (6.5 ×2), a blocked_domains bypass in web_fetch_tool (3.7), a client-submitted tool call in the AG-UI and Vercel AI adapters that skipped guardrails placed in model-request hooks (6.5, July), and OpenTelemetry spans that kept content when include_content=False was set (2.3 ×2 on v4).
All nine are fixed by 1.107.6 and 2.44.0 (September 17), below the 1.107.7 / 2.53.0 floor this digest already gives, and 2.54.0 is current. Two still have no database record: the July adapter flaw and the blocked_domains bypass. If you can't upgrade, the advisory's advice for the chat UI is not to browse untrusted sites while it runs, and not to serve agents with side-effecting tools through it.
LangGraph.js: three more, after Wednesday's three. LangChain published three LangGraph.js advisories at 07:34, 11:51 and 18:10 UTC yesterday, all on the repository only and none with a CVE. GHSA-wp87-994x-j95x (7.6 on v4) covers @langchain/langgraph from 0.2.23, which could read a plain JSON object passed as ordinary graph input as a control directive. Anyone who can supply input could then alter graph state or redirect execution past validation and approval nodes, and run tools with the application's permissions. It's fixed in 1.4.21 (October 7), the release yesterday's edition already recommended for the defaultHeaders flaw. The advisory's workaround is to build graph state on the server and accept only the fields the application expects.
GHSA-8p8h-xj5r-m5wf (7.1) covers store namespaces that didn't isolate data. PostgresStore search and namespace listing could return items from a sibling namespace sharing a prefix, and RedisStore could read, replace or delete another namespace's documents. The fixes are @langchain/langgraph-checkpoint-postgres 1.0.6 and @langchain/langgraph-checkpoint-redis 1.0.12 (October 6). GHSA-hxqq-jqhx-58fp (2.3 on v4) covers the MongoDB store's vector search, fixed in @langchain/langgraph-checkpoint-mongodb 1.4.2. If you use store namespaces as a tenant boundary, upgrade the store packages. @langchain/langgraph has 3.7 million downloads a week, and the Postgres checkpointer 644,000.
Banks: the template layer under LlamaIndex. Banks is the prompt-template library that llama-index-core depends on (banks>=2.3.0,<3). Two advisories its repository published on September 9 and 12 got CVEs and database records at 22:10 UTC yesterday. CVE-2026-107717 (6.5, no account needed): text a user controls could be parsed as chat messages in a privileged role, such as system instructions. It's fixed in 2.5.0 (August 8). CVE-2026-107716 (unscored): DirectoryPromptRegistry followed symlinks, so a prompt directory that untrusted users can influence, or one extracted from an archive, could expose or overwrite files outside it. It's fixed in 2.5.1 (September 10). The floor this digest gave on September 4 moves from 2.4.5 to 2.5.1, and a lockfile refresh under LlamaIndex reaches it.
Handlebars: March's fix had a bypass. Handlebars published three advisories at 22:40 UTC on October 5, three minutes after 4.7.10 reached npm, and GitHub indexed them yesterday. CVE-2026-106446 (9.8) gets past March's fix for CVE-2026-33937. If untrusted input reaches compile() or precompile() as an object rather than a string, JavaScript runs in the Node.js process or ends up in the precompiled template. The advisory names the common case: a field from a JSON request body passed straight to compile(). CVE-2026-106445 (9.2 on v4) applies only when untrusted templates are compiled with allowProtoMethodsByDefault: true. CVE-2026-106444 (4.7) covers inlining precompiled output from untrusted templates into HTML. All three affect 4.0.0 through 4.7.9. Upgrade to 4.7.10. Until you can, check that whatever reaches compile() is a string, and use the runtime-only build where templates are precompiled at build time. The package has 41.5 million downloads a week.
Already fixed, now visible to scanners.
- PraisonAI, with a correction. GitHub indexed 22 of the 23 June 25 records that yesterday's edition listed as missing, between 16:36 and 22:01 UTC, including the 10.0 (
GHSA-2xv2), the 9.9 (GHSA-9mp3) and the AgentOS 8.6 (GHSA-6wjp). Only GHSA-26mh-57q7-jfvr is left. At the same time GitHub withdrew 22 duplicate records from July 10 to 15 that described the same flaws with no fixed version. So "not in the database" was wrong for those flaws: scanners had flagged them since July, with no fix to point to. They now point to the floors this digest gave yesterday, and nothing changes for anyone already on them. - LangChain.js: the
@langchain/mongodbadvisory covered on October 6 is in GitHub's database as CVE-2026-106119, fixed in 1.3.1.
Standing items. concurrently 10.0.6 and 9.2.5, published at 12:51 and 12:53 UTC yesterday, move its exact shell-quote pin from 1.9.0 to 1.12.0, which clears CVE-2026-102422 for a package with 22 million weekly downloads. Payload published seven more advisories between 13:29 and 13:43 UTC yesterday, all fixed at or below 3.90.0, so the floor holds. The highest (7.6 on v4) covers @payloadcms/plugin-mcp 3.64.0 to 3.87.x, where custom MCP authentication didn't apply the configured credential as intended. The default authentication isn't affected, and it's fixed in 3.88.0. The other six cover authorization on framework collections, client uploads and scheduled publishing, sessions that survived a password change, login rate limiting, and CSV formula injection in the import/export plugin. Four earlier Payload records still aren't in GitHub's database.
ToolHive published GHSA-rxgh-62mp-jq63: before 0.51.4, a tool-call body the filter couldn't decode skipped the tool allow-list and tool-name overrides. 0.51.4 is the floor this digest already gives. LiteLLM shipped 1.104.2 and 1.102.4 yesterday, and no file under litellm/proxy/auth/ at either tag checks email_verified, so CVE-2026-93355 stays open on JWT-auth deployments. Docker filed CVE-2026-101998 (5.9 on v4) against Docker Sandboxes: the credential proxy could fail open and forward unmasked responses, so code inside a sandbox could recover the host's OAuth tokens or a derived Anthropic API key. The record names no version. The 0.47.0 release notes (October 5) list a masking fix for one of those cases without citing the CVE. Update, and rotate the credentials any sandbox that ran untrusted code had access to.
Unchanged: vLLM 0.31.0 with the six KV-transfer CVEs and CVE-2026-90878 open, mcp-server-fetch 2026.8.18 (the private-address guard is only on v2/main), Chroma 1.5.9 with both CVEs open, RAGFlow without a 0.27.3, MarkItDown 0.1.8 pinning mammoth~=1.11.0, Mooncake 0.3.13.post1, pandas-ai 3.0.0, LightLLM v1.2.0, Showdown 2.1.0 and the Milvus Helm chart 5.0.30. GitLab has tagged no self-hosted AI Gateway image since September 17, BrowserSkill PR 363 is unmerged, Langflow's CVE-2026-97677 still hasn't reached GitHub, and the latest tag of @deepseek-ai/dsh-client-connection still points at the affected 0.0.1-rc.1. NeMo 3.0.0 still caps hydra-core<=1.3.2, and ImageSharp has no new 2.x or 3.x release.
For .NET and Azure. Microsoft published seven cloud-service CVEs on October 8, four of them in Azure: App Service (CVE-2026-77900, 9.8, code execution), SRE Agent (CVE-2026-69435, 9.6, elevation of privilege), API Center (CVE-2026-83943, 8.7, information disclosure) and Event Grid (CVE-2026-83947, 7.7, spoofing). Microsoft marks all of them as needing no customer action, and none was publicly disclosed or exploited. No .NET or ASP.NET Core documents were revised. For Angular, GitHub's record for webpack-dev-middleware GHSA-g84c still says < 7.4.5, and Angular 21.2.26 and 20.3.39 still pin 7.4.5 and 7.4.2. Patch Tuesday is October 13.
* * *
Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.
Elsewhere in this issue
3 more- 01
News
Three posts in one day — Anthropic answers Mistral's cyber pitch with eleven partners, a new usage policy, and $150 million for the Genesis Mission
Oct 9, 2026
- 02
News
Claude Haiku 5.5 ships at a tenth of Haiku 4.5's price — then the new tokenizer eats a quarter of the cut back
Oct 8, 2026
- 03
The Patch
The Patch — October 8, 2026
Oct 8, 2026
Letters
Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.