CVE-2026-52887 is a critical SQL injection vulnerability affecting NocoBase, an AI-powered no-code/low-code platform. The flaw allows unauthenticated remote attackers to execute arbitrary SQL queries via the…
Research presented at DEFCON 34 revealed 14 critical and high severity vulnerabilities across seven AI orchestration platforms, including NocoBase, Flowise, Langflow, Dify, Activepieces, Kestra, and Apache Airflow.…