Millions of high-risk AI agents in open source packages



Millions of AI agents and devices around the world have been exposed to a major vulnerability that could allow hackers to breach the servers they’re running and steal sensitive information and third-party account information, a security researcher has warned.

This threat exists in Starlette, an open-source format whose creator says it gets 325 million downloads a week. Thousands of other projects are at risk because they need Starlette to work. The process is to implement ASGI (asynchronous server gateway interface), which allows multiple requests to be processed efficiently at the same time. Starlette is the basis for FastAPI and other widely used frameworks for building Python applications, as well as many others.

Easy to use, millions of servers exposed

ASGI, and by extension Starlette, has access to servers running MCP (model context protocol), which allows AI agents from major agents to access external sources, including user data, email and calendar accounts, and all kinds of other things. To support these external systems, MCP servers store all kinds of information, making them valuable databases for attackers to breach.

The vulnerability, identified as CVE-2026-48710 and under the name BadHost, is small in scope and works against many systems that are not behind well-configured firewalls. Besides FastAPI, other commonly used packages – including vLLM, and LiteLLM – are also affected. BadHost affects versions of Starlette prior to 1.0.1, which was released on Friday.

“One person logged into the HTTP Host header bypasses authorization from Starlette, the core of FastAPI,” Secwest researchers wrote. “Through FastAPI, this vulnerability (now tracked as CVE-2026-48710 and named BadHost by its discoverers) reaches a large part of the Python AI tooling ecosystem: vLLM (where the bug was discovered), LiteLLM, Text Generation Inference, many OpenAI-shim proxies, hardash servers, MCP servers. Model management UIs.”

BadHost has a strict score of 7 out of 10. Secwest said that the group “reduces” the risk that makes people use other programs that rely on Starlette. X41 D-Sec, the security firm that discovered it, said it was “very serious.” X41 D-Sec partnered with another security firm Nemesis to produce it online scanner which will check if a given server is vulnerable.



Source link

اترك ردّاً

لن يتم نشر عنوان بريدك الإلكتروني. الحقول الإلزامية مشار إليها بـ *