JFrog Security Research
Model Threats
Discover
Follow JFrog Security
Home
Model Threats
Discover
Follow JFrog Security
< Back
Software Vulnerabilities
Last Updated On
9 Feb, 2026
183
Vulnerabilities
discovered
JFSA-2026-001653030
mcp-run-python lack of isolation MCP takeover
medium
CVE-2026-25905
CVE-2026-25905
CVE-2026-25905
medium
Discovered By
Natan Nehorai
●
Published on
9 Feb, 2026
●
JFSA-2026-001653029
mcp-run-python Deno SSRF
medium
CVE-2026-25904
CVE-2026-25904
CVE-2026-25904
medium
Discovered By
Natan Nehorai
●
Published on
9 Feb, 2026
●
JFSA-2026-001651697
n8n Expression Node RCE
critical
CVE-2026-1470
CVE-2026-1470
CVE-2026-1470
critical
Discovered By
Natan Nehorai
●
Published on
27 Jan, 2026
●
JFSA-2026-001651077
n8n Python runner sandbox escape
high
CVE-2026-0863
CVE-2026-0863
CVE-2026-0863
high
Discovered By
Natan Nehorai
●
Published on
18 Jan, 2026
●
Node.js filesystem permissions bypass
high
CVE-2025-55130
CVE-2025-55130
CVE-2025-55130
high
Discovered By
Natan Nehorai
●
Published on
13 Jan, 2026
●
JFSA-2025-001648329
python-utcp untrusted Manual command execution
high
CVE-2025-14542
CVE-2025-14542
CVE-2025-14542
high
Discovered By
Or Peles
●
Published on
11 Dec, 2025
●
JFSA-2025-001648159
Litmus Chaos JWT Missing Entropy Privilege Escalation
high
CVE-2025-14261
CVE-2025-14261
CVE-2025-14261
high
Discovered By
Natan Nehorai
●
Published on
8 Dec, 2025
●
n8n Git Node RCE
high
CVE-2025-62726
CVE-2025-62726
CVE-2025-62726
high
Discovered By
Assaf Levkovich
●
Published on
4 Nov, 2025
●
JFSA-2025-001495652
DSPy sandbox escape arbitrary file read
medium
CVE-2025-12695
CVE-2025-12695
CVE-2025-12695
medium
Discovered By
Natan Nehorai
●
Published on
4 Nov, 2025
●
Cursor CLI Untrusted Project RCE
high
CVE-2025-61592
CVE-2025-61592
CVE-2025-61592
high
Discovered By
Assaf Levkovich
●
Published on
4 Nov, 2025
●
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19