Announcements

BerriAI LiteLLM: BerriAI LiteLLM Improper Authentication Vulnerability

  • 5th September 2026

BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-59822

Continue reading

Google Chromium V8: Google Chromium V8 Type Confusion Vulnerability

  • 5th September 2026
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.Source: CISA Known Exploited ...
Continue reading