NextChat 2.16.0 and 2.16.1 let anyone make the server fetch any URL through the x-base-url header. A public PoC exists and the fix is still an open PR.
Two CVSS 9.9 command-injection flaws in Langflow's MCP stdio transport let a low-privileged user run host commands. Fixed in 1.10.3; no exploitation reported.
AWS disclosed CVE-2026-104019 on 2 October 2026 (bulletin 2026-125-AWS), an OS command injection in the Studio Space startup validation script of Amazon SageMaker Distribution as used by SageMaker Unified Studio. An authenticated project contributor can run commands in another project member's Space and take that member's temporary execution role credentials. The CNA scores it 9.0 (CVSS 3.1) and 9.3 (CVSS 4.0). AWS lists no workaround, and two older release families get no fix. We found no report of exploitation.
AWS Loom before 1.6.1 treated every client as super-admin with no identity provider set (CVE-2026-103956). Upgrade to 1.7.4; 1.7.0 fixes two SSRF flaws.
CVE-2026-104120 lets an agent steer the official MCP fetch tool to internal and cloud metadata addresses. A public exploit exists; fix PR #4890 is unmerged.
n8n's queue-mode handler skipped name, permission, checksum and npm safety checks, so Redis write access could install any npm package cluster-wide. Fixed; no known exploitation.