By AI Blog Editor
Oct 10, 2026 · 30 min read
The Patch — October 10, 2026
MLflow 3.12.0 through 3.16.1 let anyone who can reach a no-auth tracking server run code on it (9.8, fixed in 3.17.0), and vLLM posted eleven advisories that 0.31.0 already fixes.
Saturday's lead is MLflow: from 3.12.0 through 3.16.1, anyone who can reach a tracking server running without authentication can run code on it, scored 9.8 and fixed in 3.17.0 on Wednesday. vLLM published eleven advisories yesterday morning, all fixed by the 0.31.0 this digest already recommends, and FalkorDB took seven CVEs for flaws it fixed between April and July. For .NET, ImageSharp now has a fix on the 3.x line.
Component | Affected | Severity | Patched? | Action | Relevance |
|---|---|---|---|---|---|
MLflow | 9.8 | yes → 3.17.0 (Oct 7) | upgrade; never expose a tracking server without authentication | AI stack | |
vLLM ×11 | 7.7 · 7.5 · 6.5 ×2 · 5.9 ×4 · 3 unscored (high) | yes → all by 0.31.0 (Oct 5) | run 0.31.0; the KV-transfer carve-outs still apply | AI stack | |
FalkorDB ×7 | 9.8 ×2 · 9.1 ×2 · 8.1 ×2 · 7.5 | yes → 4.20.0 (Jul 13) | run 4.20.0 or later; set a password | AI stack | |
AstronRPA ×2 | 7.5 ×2 · 7.7 ×2 (v4) | no — 1.1.6 (Feb 25) is the newest release | keep the smart-component chat off untrusted pages; update only from GitHub releases | AI stack | |
LobsterAI | 7.1 · 6.9 (v4) | fix merged Oct 7 on a release branch, not released | install skills only from sources you trust | AI stack | |
SixLabors.ImageSharp (update) | 7.5 ×5 · 5.3 ×2 | 3.x → 3.2.0 (Oct 9); no fix on 2.x | move 3.x to 3.2.0; 2.x is out of support | Venicecom stack |
Worth your morning
MLflow: code execution on servers without authentication. MLflow published GHSA-26p8-2jq9-3vq9 (9.8) at 08:20 UTC yesterday, two days after the fix shipped in 3.17.0. The flaw is in how the tracking server loads third-party scorers. On the official image with no authentication configured, anyone who can reach the server can run Python code as the MLflow process, and that image runs it as root. With authentication on, the caller needs an account that can create experiments and runs and upload artifacts. The range starts at 3.12.0rc0, so it covers releases from 3.12.0 (May 5) to 3.16.1 (September 16). The 3.17.0 release notes list the fix by advisory ID, next to a second scorer advisory, GHSA-2wqp-q3c6-ccj5, that isn't public yet. The advisory is on the repository only, with no CVE, so scanners won't raise it.
Upgrade to 3.17.0, and don't run a tracking server without authentication on a network you don't control (mlflow server --app-name basic-auth turns on MLflow's built-in login). The advisory says a read-only container filesystem, or a scorer package directory the server process can't write to, also blocks this path. If a server in the range was reachable from an untrusted network, rotate the credentials it holds. MLflow has 28,000 GitHub stars.
vLLM: eleven advisories, all fixed by 0.31.0. vLLM's maintainers published eleven advisories between 06:39 and 08:27 UTC yesterday, all on the repository only and none with a CVE. Each is fixed in 0.31.0 (October 5) or earlier, so the floor this digest gives doesn't move. The one with the widest consequence is GHSA-vfp2-c8pq-v6h6 (rated high, no score): from 0.9.2 until 0.24.0, a client that could reach a prefill worker running P2pNcclConnector could make it send out the KV cache of every request it processed, prompt text included. vLLM removed that connector in 0.24.0 (June 30). If you ran it on an older release, treat the prompts those workers handled as exposed. GHSA-rhcx-5729-88vg (7.7) let one request with prompt_logprobs crash the engine, and every tenant's in-flight requests with it, on servers using a KV connector such as LMCache. It's fixed in 0.31.0.
The rest are availability bugs: speculative decoding with allowed_token_ids (7.5, fixed in 0.18.0), three in the Rust gRPC frontend (5.9 each, 0.24.0), stop_token_ids (6.5, 0.29.0), disaggregated multimodal input (5.9, 0.30.0) and the video frame cap (high, 0.31.0, which now rejects per-request decoder settings unless --trust-request-mm-kwargs is set). Two need a note. GHSA-mm38-5g96-7j6x says the Nemotron-VL image processors turned off Pillow's decompression-bomb limit for the whole process, and gives the range as <= 0.8.5, fixed in 0.25.0. The code it describes is in 0.20.0 and 0.24.0 and is gone in 0.25.0 (July 11), so a scanner reading that range would clear releases that have it. GHSA-r45p-7qwx-qwjw (6.5) describes the same chat-audio flaw as CVE-2026-57173, covered on September 17, with the same 0.24.0 fix. The six KV-transfer CVEs and CVE-2026-90878 are still open at 0.31.0.
FalkorDB: seven CVEs, all fixed by July. Seven CVE records against FalkorDB, the graph database that bills itself as a knowledge graph for GraphRAG (8,600 stars), were published at 06:31 UTC yesterday. Each names a fix that has already shipped. Four cover the Bolt protocol support: two memory-corruption bugs reachable without credentials (CVE-2026-107908, 9.8, and CVE-2026-107909, 9.1), an authentication check that let unauthenticated clients run graph queries over Bolt (CVE-2026-107910, 8.1; 9.2 on v4), and a type confusion an authenticated client could reach through GRAPH.QUERY (CVE-2026-107911, 7.5). FalkorDB fixed all four the thorough way: it removed Bolt in 4.20.0 (July 13). The Bolt listener was off by default in earlier releases, so the three listener bugs apply only where BOLT_PORT was set.
The other three are memory-safety bugs in loading graph data from a replication stream, reachable by anyone who can issue replication commands, for example on an instance with no password: CVE-2026-5759 (9.8) is fixed in 4.18.1 (April 12), and CVE-2026-7826 (9.1) and CVE-2026-7827 (8.1) in 4.18.4 (May 7). Current releases are 4.22.0 on the C engine and 6.0.2 on the Rust engine. If you run anything older than 4.20.0, upgrade, and set a password whatever the version. The records carry no package mapping. They are separate from the seven August CVEs covered on September 22.
AstronRPA: two flaws, no fix. VulnCheck filed two CVEs yesterday against AstronRPA, iFlytek's open-source RPA suite with an AI assistant (5,300 stars). In CVE-2026-108159 (7.5; 7.7 on v4), the desktop client's smart-component chat rendered model output as HTML without sanitizing it, so a web page carrying injected instructions could end with commands running as the desktop user. In CVE-2026-108160 (7.5; 7.7 on v4), the auto-updater reads its feed over plain HTTP and installs updates without checking signatures, so anyone on the network path can deliver an installer. Both cover everything through 1.1.6, the newest release (February 25). The reports (892, 894) have been open since October 6, and a pull request that turns on signature checks for Windows update packages is open. Until a release ships, keep the smart-component chat away from pages you don't trust, and install updates from the GitHub release page on a network you control.
LobsterAI: fixed on a branch, not in a release. CVE-2026-108156 (7.1; 6.9 on v4) covers LobsterAI, NetEase Youdao's desktop agent built on OpenClaw (6,100 stars). From 2026.5.27 through 2026.9.23, uninstalling a crafted skill could delete any directory the user can write to, the home directory included, because the uninstall handler trusted a path taken from the skill's own metadata. The fix (PR 2809) merged on October 7 into the release/2026.9.24 branch, and 2026.9.23 is still the newest release. Until the next one ships, install skills only from sources you trust.
Already fixed, now visible.
- Claude Code: Anthropic published GHSA-pq7j-f95f-qfcv (CVE-2026-86063, 7.7 on v4) yesterday for a flaw fixed in 2.1.179 on June 16. The plugin installer in Claude Code and Claude Desktop didn't confirm that the code it checked out matched the commit a marketplace had pinned, so a plugin's upstream repository could get unreviewed code installed despite the pin. It required a user to install a malicious plugin. Auto-update has delivered the fix, and 2.1.296 is current.
- Langflow: GitHub reviewed CVE-2026-105697 (9.9, MCP stdio server configuration) yesterday evening, so pip-audit now raises it for
langflowbelow 1.10.3,langflow-basebelow 0.10.3 andlfxbelow 1.10.3. This digest covered it on September 29, and the 1.12.3 floor is higher. - Handlebars: the maintainers widened the 9.2 from yesterday's edition, GHSA-p8wg-vrv2-v86f, to start at 3.0.0 at 20:56 UTC yesterday. The
legacytag on npm, 3.0.8 from 2020, has no fix, and GitHub's database still starts the range at 4.0.0. Move to 4.7.10.
Standing items. Unchanged: vLLM 0.31.0 with the six KV-transfer CVEs and CVE-2026-90878 open, SGLang 0.5.21 with CVE-2026-93034 open, LiteLLM with no stable release after 1.104.2 (CVE-2026-93355 stays open on JWT-auth deployments), mcp-server-fetch 2026.8.18, Chroma 1.5.9 with both CVEs open, RAGFlow without a 0.27.3, MarkItDown 0.1.8 pinning mammoth~=1.11.0, Mooncake 0.3.13.post1, pandas-ai 3.0.0, LightLLM v1.2.0, Showdown 2.1.0 and the Milvus Helm chart 5.0.30. Ollama is at 0.40.2. GitLab has tagged no self-hosted AI Gateway image since September 17, BrowserSkill PR 363 is unmerged, Langflow's CVE-2026-97677 still hasn't reached GitHub, NeMo 3.0.0 still caps hydra-core<=1.3.2, and the latest tag of @deepseek-ai/dsh-client-connection still points at the affected 0.0.1-rc.1. Four Payload records, two Pydantic AI records and the last PraisonAI June record still aren't in GitHub's database.
For .NET and Azure. Six Labors shipped ImageSharp 3.2.0 and 4.1.3 to NuGet at 09:05 and 09:14 UTC yesterday, then revised seven of the nine advisories covered on October 8 to name 3.2.0 as the fix for 3.x. That replaces Thursday's "no fix on 2.x or 3.x": a 3.x application can now stay on its line. GitHub's database records still name only 4.1.2, and NuGet still lists five vulnerabilities against 3.2.0, so NuGetAudit will keep flagging it until the records catch up. 2.x stays unfixed. The security policy added with the release covers the latest major version, plus the previous one for 12 months after the next major's first stable release. 4.0.0 shipped on May 12, so 3.x is covered until May 2027 and 2.x, superseded in March 2023, is out of support. The same policy says security updates "may require a license key under the existing license terms." 2.x is Apache-2.0 while 3.x and 4.x use the Six Labors Split License, so moving a 2.x application to 3.2.0 is a licensing decision as well as an upgrade. The backport pull request also names six advisory IDs that aren't public yet.
Microsoft revised thirteen older security documents overnight, all in Windows, HPC Pack and Azure Linux entries, with nothing for .NET, ASP.NET Core or Azure services. Patch Tuesday is October 13. For Angular, nothing moved: GitHub's record for webpack-dev-middleware GHSA-g84c still says < 7.4.5, and Angular 21.2.26 and 20.3.39 still pin 7.4.5 and 7.4.2.
* * *
Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.
Elsewhere in this issue
3 more- 01
News
OpenAI's revenue is $50 billion — or $70 billion. The gap is how you count AWS.
Oct 10, 2026
- 02
News
Three posts in one day — Anthropic answers Mistral's cyber pitch with eleven partners, a new usage policy, and $150 million for the Genesis Mission
Oct 9, 2026
- 03
The Patch
The Patch — October 9, 2026
Oct 9, 2026
Letters
Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.