The Lab · 2026-04-18 06:22:38 · GitHub Issues
A critical security flaw has been patched in the Sentinel AI plugin, where its image generation feature was vulnerable to server-side request forgery (SSRF). The vulnerability resided in the `AIPS_Generator` class, specifically within the `generate_and_upload_featured_image` method. This function used the `wp_remote_ge...
The Lab · 2026-05-05 12:31:40 · GitHub Issues
A newly documented vulnerability in the Model Context Protocol (MCP) tool execution pipeline allows untrusted tool results to enter LLM conversations without sanitization, injection warnings, or structural boundary markers. The issue, filed as a GitHub security concern, details how the `MCPManager.CallTool()` method jo...
The Lab · 2026-05-11 20:18:29 · GitHub Issues
An AI endpoint accessible at http://34.16.47.248:8882 was found to be leaking protected health information (PHI), including patient names, Social Security Numbers, diagnoses, insurance details, and lab results. The vulnerability was identified through automated red team testing, which successfully prompted the system t...