NewsLangChain SSRF Bypass CVE-2026-26019Cybersecurity News·high signalXBlueskyLinkedInCopy linkSSRF bypass in LangChain Community RecursiveUrlLoader. Weak domain validation enables access to internal services. Fixed in 1.1.14.SourceSource pageCybersecurity News↳ Follow the threadPolicy dependency / Stack layerA Bun packaging quirk left a vulnerable undici in Cline after the CVE was supposedly remediatedGitHubStack layer / Update threadAgentic Awesome Skills shipped v17.3.0 this morning with 2,122 skills and zero open issuesGitHubPolicy dependency / Stack layerRIPPLE: an edit confined to one prompt-policy segment changes downstream behavior, so replay candidate edits after previously accepted ones before persistingarXiv 2609.12127Threat patternContextForge's SSRF guard checks the resolved address then throws it away before connectingNVDStack layer / Update threadApple code shows Siri AI can be swapped for Claude or ChatGPT wholesale, not just queriedMacRumors (via r/ClaudeAI, 683 upvotes)Policy dependency / Stack layerPython's Import Statement Is an Execution Boundary: 90% of Initialization-Activated Advisory Vulnerabilities Are High or CriticalarXiv 2609.14791Stack layer / Threat patternElva Launches Against Postman With Flat Workspace Pricing and Specs Generated From Repo CommitsElva (surfaced via the Product Hunt daily leaderboard for 2026-09-14)Threat patternMCP Atlassian's Confluence upload tools read any path on the server and post it to AtlassianNVD