{
  "study": "The AI Stack Security Ledger: Eight of Its Ten Worst CVEs Are the Same Bug",
  "url": "https://provenbrief.com/story/the-ai-stack-security-ledger-eight-of-its-ten-worst-cves-are-the-same-bug",
  "publisher": "ProvenBrief",
  "contentUpdatedAt": "2026-10-08T01:37:01.140Z",
  "terms": "Free to use with attribution to ProvenBrief and a link to the source page.",
  "tables": [
    {
      "key": "ai-stack-criticals",
      "title": "The AI stack ledger's first build: highest-severity CVEs per product",
      "measure": "CVSS v3.1 base score recorded in NVD (primary score where assigned, secondary otherwise)",
      "unit": "CVSS v3.1 base score",
      "rows": [
        {
          "key": "langchain-2023-29374",
          "label": "LangChain LLMMathChain (CVE-2023-29374)",
          "value": 9.8,
          "note": "prompt injection executes arbitrary code via Python exec; disclosed 2023-04-05",
          "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-29374"
        },
        {
          "key": "langchain-2023-34540",
          "label": "LangChain JiraAPIWrapper (CVE-2023-34540)",
          "value": 9.8,
          "note": "remote code execution via crafted input; disclosed 2023-06-14",
          "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-34540"
        },
        {
          "key": "langchain-2023-34541",
          "label": "LangChain load_prompt (CVE-2023-34541)",
          "value": 9.8,
          "note": "arbitrary code execution; disclosed 2023-06-20",
          "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-34541"
        },
        {
          "key": "langflow-2024-37014",
          "label": "Langflow custom_component endpoint (CVE-2024-37014)",
          "value": 9.8,
          "note": "endpoint executes a Python script supplied in the request; disclosed 2024-06-10",
          "source": "https://nvd.nist.gov/vuln/detail/CVE-2024-37014"
        },
        {
          "key": "langflow-2025-3248",
          "label": "Langflow /api/v1/validate/code (CVE-2025-3248)",
          "value": 9.8,
          "note": "unauthenticated code injection; CISA KEV added 2025-05-05",
          "source": "https://nvd.nist.gov/vuln/detail/CVE-2025-3248"
        },
        {
          "key": "ray-2023-48022",
          "label": "Anyscale Ray job submission API (CVE-2023-48022)",
          "value": 9.8,
          "note": "arbitrary code execution; record carries the disputed tag after vendor objection",
          "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-48022"
        },
        {
          "key": "mlflow-2023-6018",
          "label": "MLflow file overwrite (CVE-2023-6018)",
          "value": 9.8,
          "note": "unauthenticated overwrite of any file on the host; finder rates OS command injection (CWE-78)",
          "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-6018"
        },
        {
          "key": "marimo-2026-39987",
          "label": "Marimo /terminal/ws (CVE-2026-39987)",
          "value": 9.8,
          "note": "pre-auth remote code execution via terminal WebSocket; CVSS 4.0 score 9.3 Critical; CISA KEV added 2026-04-23",
          "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-39987"
        },
        {
          "key": "litellm-2026-42271",
          "label": "LiteLLM MCP test endpoints (CVE-2026-42271)",
          "value": 8.8,
          "note": "command injection; CVSS 4.0 secondary score 8.7 High; CISA KEV added 2026-06-08; patched in 1.83.7",
          "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-42271"
        },
        {
          "key": "ollama-2024-37032",
          "label": "Ollama model path digest (CVE-2024-37032)",
          "value": 8.8,
          "note": "path traversal via unvalidated digest; score from NVD's secondary scoring source",
          "source": "https://nvd.nist.gov/vuln/detail/CVE-2024-37032"
        }
      ]
    },
    {
      "key": "kev-lag",
      "title": "Days from CVE publication to CISA listing the bug as exploited in the wild",
      "measure": "calendar days between the CVE's NVD publication date and CISA's KEV addition date, as computed for this ledger from the two dates each NVD record carries",
      "unit": "days",
      "rows": [
        {
          "key": "marimo-2026-39987",
          "label": "Marimo CVE-2026-39987",
          "value": 14,
          "note": "published 2026-04-09, KEV added 2026-04-23; Sysdig observed first exploitation attempt 9h41m after the GitHub advisory",
          "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-39987"
        },
        {
          "key": "langflow-2025-3248",
          "label": "Langflow CVE-2025-3248",
          "value": 28,
          "note": "published 2025-04-07, KEV added 2025-05-05",
          "source": "https://nvd.nist.gov/vuln/detail/CVE-2025-3248"
        },
        {
          "key": "litellm-2026-42271",
          "label": "LiteLLM CVE-2026-42271",
          "value": 31,
          "note": "published 2026-05-08, KEV added 2026-06-08",
          "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-42271"
        }
      ]
    }
  ]
}