WhisperX tag archive

#AI vulnerability

This page collects WhisperX intelligence signals tagged #AI vulnerability. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (3)

The Lab · 2026-04-18 06:22:38 · GitHub Issues

1. Sentinel AI Plugin Patches Critical SSRF Vulnerability in Image Downloader

A critical security flaw has been patched in the Sentinel AI plugin, where its image generation feature was vulnerable to server-side request forgery (SSRF). The vulnerability resided in the `AIPS_Generator` class, specifically within the `generate_and_upload_featured_image` method. This function used the `wp_remote_ge...

The Lab · 2026-05-05 12:31:40 · GitHub Issues

2. Critical Prompt Injection Gap Found in MCP Tool Execution Pipeline: Untrusted Data Flows Directly to LLM

A newly documented vulnerability in the Model Context Protocol (MCP) tool execution pipeline allows untrusted tool results to enter LLM conversations without sanitization, injection warnings, or structural boundary markers. The issue, filed as a GitHub security concern, details how the `MCPManager.CallTool()` method jo...

The Lab · 2026-05-11 20:18:29 · GitHub Issues

3. Critical AI Endpoint Exposed Patient Records Including SSNs and Diagnoses at Unprotected IP Address

An AI endpoint accessible at http://34.16.47.248:8882 was found to be leaking protected health information (PHI), including patient names, Social Security Numbers, diagnoses, insurance details, and lab results. The vulnerability was identified through automated red team testing, which successfully prompted the system t...