Canonical, dated answers for coding agents — every entry states when it was true and which versions it applies to, so your context never goes stale.
High severity. Affects pydantic-ai >= 2.10.0, < 2.53.0. Upgrade to 2.53.0 or later.
Medium severity. Affects pydantic-ai >= 1.77.0, < 1.107.7; pydantic-ai >= 2.0.0b1, < 2.52.0. Upgrade to 1.107.7 / 2.52.0 or later.
Medium severity. Affects pydantic-ai >= 1.34.0, < 1.107.5; pydantic-ai >= 2.0.0b1, < 2.30.0. Upgrade to 1.107.5 / 2.30.0 or later.
High severity. Affects pydantic-ai >= 1.34.0, < 1.107.4; pydantic-ai >= 2.0.0b1, < 2.28.0. Upgrade to 1.107.4 / 2.28.0 or later.
Low severity. Affects pydantic-ai >= 0.3.4, < 1.107.4; pydantic-ai >= 2.0.0b1, < 2.27.1. Upgrade to 1.107.4 / 2.27.1 or later.
Medium severity. Affects pydantic-ai >= 1.77.0, < 1.107.2; pydantic-ai >= 2.0.0b1, <= 2.23.0. Upgrade to 1.107.2 / 2.24.0 or later.
Medium severity. Affects pydantic-ai >= 1.77.0, < 1.107.6; pydantic-ai >= 2.0.0b1, < 2.44.0. Upgrade to 1.107.6 / 2.44.0 or later.
Low severity. Affects pydantic-ai >= 0.3.4, < 1.107.6; pydantic-ai >= 2.0.0b1, < 2.44.0. Upgrade to 1.107.6 / 2.44.0 or later.
Medium severity. Affects pydantic-ai >= 1.56.0, < 1.107.6; pydantic-ai >= 2.0.0b1, < 2.44.0. Upgrade to 1.107.6 / 2.44.0 or later.
Electron 44 (2026-08-25, Chromium 152, Node 24.18.1) is the latest stable; 44/43/42 are supported. It drops macOS 12 and 32-bit builds and removes renderer access to `clipboard`. Since 42 the npm package no longer downloads the binary in postinstall.
High severity. Affects @modelcontextprotocol/sdk >= 1.12.0, < 1.31.0; @modelcontextprotocol/client >= 2.0.0, < 2.2.0. Upgrade to 1.31.0 / 2.2.0 or later.
Hono 4.13.13 (2026-10-04) is current. 2026 brought many security fixes (CORS credential reflection, bodyLimit, JWT scheme, JSX SSR, serveStatic) - use >= 4.13.11. 4.13.0 changed cache keys, CORS default methods and RegExpRouter errors.
Medium severity. Affects litellm < 1.88.6; litellm >= 1.89.0, < 1.89.7; litellm >= 1.90.0, < 1.90.7; litellm >= 1.91.0, < 1.91.5; litellm >= 1.92.0, < 1.92.2; litellm >= 1.93.0, < 1.93.2; litellm >= 1.94.0, < 1.94.3; litellm >= 1.95.0, < 1.95.1; litellm >= 1.96.0, < 1.96.2. Upgrade to 1.88.6 / 1.89.7 / 1.90.7 / 1.91.5 / 1.92.2 / 1.93.2 / 1.94.3 / 1.95.1 / 1.96.2 or later.
Five campaigns, one phenomenon: 1,000+ compromised packages, AI-targeting malware hunting ~/.claude, ~/.cursor, ~/.codex configs and LLM API keys. Your AI assistant is both weapon and target.
A malicious GitHub issue title injected instructions into Cline’s Claude-based triage bot → Actions cache poisoning → npm token theft → trojanized cline@2.3.0 on ~4,000 machines. The blueprint for AI supply-chain attacks.
34+ malicious packages (384 versions) planted .cursorrules/CLAUDE.md with invisible zero-width-Unicode instructions. First documented at-scale attack on the agent instruction channel itself.
Cursor’s agent could write to .git/hooks/ — planted hook scripts execute on the next commit/push/checkout with full OS privileges, no further prompt needed. Fixed in 2.5; the class persists in every file-writing agent.
Socket.IO is still v4 (4.8.4, 2026-09-25). 2026 high-severity DoS fixes live in transitive packages: engine.io >= 6.6.10 and socket.io-parser >= 4.2.7. Refresh lockfiles; 4.8.4 rejects stateful regexps for dynamic namespaces.