#LLM Security
All CosmicBytez Labs articles tagged #LLM Security, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-61539: Xinference Llama3 Tool-Call eval() Remote Code Execution
CVSS 10.0: Xinference passes attacker-controlled Llama3 tool-call output directly to eval(), enabling unauthenticated RCE on all versions ≤ 2.5.0.
- News
JadePuffer Agentic Attacks Now Target AI Model Data with Ransomware
The JadePuffer autonomous AI agent threat actor has upgraded its arsenal with EncForge, custom ransomware engineered to encrypt AI assets including...
- Security
CVE-2025-71327: Flowise Authentication Bypass Grants Full API Access
A critical authentication bypass in Flowise allows unauthenticated attackers to register accounts via an unprotected API endpoint and gain full platform...
- News
New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration
OpenAI has begun rolling out a new Lockdown Mode to ChatGPT for eligible personal accounts, restricting tool capabilities that could be exploited in prompt…
- Security
CVE-2026-4035: MLflow AI Gateway Credential Exfiltration via Env Variable Resolution
A CVSS 9.1 critical flaw in MLflow AI Gateway allows server-side environment variables in api_key fields to be resolved and exfiltrated to attacker-controlled…
- News
Ollama Out-of-Bounds Read Flaw Allows Remote Process Memory
Researchers have disclosed a critical out-of-bounds read vulnerability in Ollama that enables remote unauthenticated attackers to leak the entire process...
- Security
CVE-2026-42208: LiteLLM AI Gateway Pre-Auth SQL Injection
A critical SQL injection vulnerability in LiteLLM's proxy server allows unauthenticated attackers to manipulate database queries during API key...