CVE CRITICAL CVE-2026-2651

artifacts belonging to other users. This can lead to unauthorized cross-user writes, model supply chain poisoning, and arbitrary code execution when compromised models are loaded. The issue

CVSS 9.0 mlflow/mlflow View details
CVE CRITICAL CVE-2026-50027

mcp-memory-service: Missing Authentication on Document API Endpoints Allows

CVSS 9.8 mcp-memory-service View details
CVE CRITICAL CVE-2026-44336

PraisonAI MCP `tools/call` path-traversal => RCE via Python `.pth` injection

CVSS 9.6 PraisonAI View details