Critical RCE Vulnerabilities Hit LangGraph, Marimo, and SGLang — the AI Stack Is Now an Attack Surface

Three critical or near-critical remote code execution vulnerabilities disclosed in popular AI developer tools this week suggest the industry's infrastructure is growing faster than its security posture.

A flaw chain in LangGraph exposes self-hosted AI agents to remote code execution, while CVE-2026-39987 in Marimo carries a CVSS score of 9.3 and CVE-2026-5760 in SGLang scores a 9.8, as documented by @qutyquteshweta. These are not obscure libraries. LangGraph is widely used for building stateful agentic workflows, Marimo is a popular reactive notebook environment, and SGLang is a high-performance inference framework used in production serving stacks.

Unlock the full briefing

Get every story in today's briefing, the full archive, and the daily AI intelligence brief.

All stories today

Full archive

Daily brief

Cancel anytime. Payments powered by Stripe.