Today's GHSA batch skewed unusually toward the AI-agent tooling stack: Trigger.dev, atomic-agents-stack, Pydantic AI, and vLLM each disclosed a distinct bug — prototype pollution, a dashboard path traversal, an unvalidated file reference, and an unbounded request fan-out. None is catastrophic alone, but four unrelated frameworks hitting the same vintage of bug class in one day says this generation of agent tooling is still working through problems web frameworks solved a decade ago.
Etherpad added three separate medium disclosures of its own — a replayable token-transfer endpoint, a predictable temp-file race, and a header-reflection XSS — worth patching together rather than one at a time. Also going up tonight: three CISA KEV entries added this past Monday (a Metabase SQL injection, a Windows AFD use-after-free, and a Cisco ASA/FTD DoS) that fell through a gap in this pipeline and are backfilled two days late; none show confirmed ransomware use, which is the one piece of good news in the batch.
→ Operational priority for the night patch or isolate any internet-facing Metabase instance before tomorrow's CISA deadline, then work through the AI-framework and Etherpad disclosures in order of exposure.