AI agents with self-execution privileges become an attack vector in the software supply chain when they install tampered packages without human approval.
LiteLLM contains critical SQL injection and code execution vulnerabilities that allow complete database access and remote code execution as a system service.