AgentsCVE-2026-27966 Langflow CSV Agent RCE CVSS 9.8TheHackerWire·high signalXBlueskyLinkedInCopy linkLangflow CSV Agent hardcodes allow_dangerous_code=True exposing python_repl_ast. CVSS 9.8 critical. Patched v1.8.0. Same eval epidemic vulnerability class.SourceSource pageTheHackerWire↳ Follow the threadStack layer / Threat patternClaude Code 2.1.269 Ships a Plugin Eval Runner and a Knob to Raise the Workflow Tool's Concurrent Agent Cap to 256Anthropic (claude-code CHANGELOG)Policy dependency / Stack layerSGLang Hit With Unauthenticated Pickle RCE via /update_weights_from_tensor, the Fourth Critical Inference-Stack CVE in Four WeeksCERT Coordination CenterStack layer / Threat patternGreyNoise Traced One Attacker Running OpenAI's Codex Harness With a DeepSeek Model Through 395 Organizations in 48 CountriesHelp Net SecurityStack layer / Threat patternSalesforce frames its agent stack as an 'Enterprise AI Harness' with a separate AI Control PlaneSalesforcePolicy dependency / Stack layerA replay of 68,266 real Claude Code requests says plain LRU beats the clever KV-cache policiesGitHubPolicy dependency / Threat patternBloomberg Maps How AI Cases Are Jamming the US Court System, Anchored on the Florida State Shooting Suit Against OpenAIBloombergStack layer / Threat patternMCPHub before 1.0.32 lets an intercepted OAuth authorization code be redeemed for tokensNVDStack layer / Threat patternClaude Code 2.1.270 walks back a permission regression the previous day's security release introducedGitHub