Overview
News
Technologies
Salaries
Products
People
Growth
Financials

Overview

Your logs show what agents report. RAXE records what they actually do – gateway claims, SDK events, cloud activity, kernel-observed file access – sealed as evidence and linked to the exact agent session.

News

Blog 3 months ago
RAXE-2026-062: Ollama GGUF Heap Out-of-Bounds Read: Memory Disclosure via /api/create + Exfiltration via /api/push (CVE-2026-7482)
HIGH CVSS 8.8 RAXE Labs has independently verified CVE-2026-7482, an unauthenticated heap out-of-bounds read in Ollama's GGUF model loader for versions before 0.17.1, disclosed by the Echo CNA on 2026-05-04 and credited to the Cyera Research Team (Dor Att
Read more
Report
Blog 4 months ago
RAXE-2026-061: NVIDIA BioNeMo Framework Deserialization of Untrusted Data Enables Remote Code Execution (CVE-2026-24164)
CRITICAL CVSS 9.8 NVIDIA BioNeMo Framework, NVIDIA's open-source biomedical-AI framework, distributed both as source in the public github.com/NVIDIA/bionemo-framework repository and as pre-built images in the NVIDIA NGC container registry, contains a dese
Read more
Report
Blog 4 months ago
RAXE-2026-058: Flowise CSV Agent Pyodide Sandbox Escape, Third Advisory in the 3.0.13 Wave (CVE-2026-41264)
CRITICAL CVSS 9.8 A third advisory against FlowiseAI's flowise = 3.0.13 release line was published on 2026-04-21, GHSA-3hjv-c53m-58jj / CVE-2026-41264, a prompt-injection-to-remote-code-execution vulnerability in the CSV Agent chatflow node (GHSA-3hjv-c53
Read more
Report
Blog 4 months ago
RAXE-2026-059: Claude Code Sandbox Escape via Symlink Following Enables Arbitrary File Write Outside Workspace (CVE-2026-39861)
CRITICAL Anthropic's Claude Code CLI (@anthropic-ai/claude-code) before version 2.1.64 contains a sandbox-boundary failure: sandboxed processes were permitted to create symbolic links pointing outside the Claude Code workspace, and the CLI's unsandboxed p
Read more
Report
Blog 4 months ago
RAXE-2026-060: PraisonAI Post-Cluster Wave: execute_command OS Command Injection + Multi-Backend SQL Injection Incomplete-Fix (CVE-2026-40088, CVE-2026-40315)
CRITICAL CVSS 9.6 A three-advisory post-cluster wave landed against MervinPraison's PraisonAI multi-agent framework on PyPI between 2026-04-09 and 2026-04-17, a month after RAXE's earlier nine-CVE cluster publication against the same codebase.
Read more
Report
Pro access
Upgrade to see all 39 mentions
Upgrade to a paid plan to read every media mention of this company - funding news, awards, product launches and press releases from all the outlets writing about it.
Every media mention and press release
Funding news, awards and product launches
Fresh coverage from every outlet writing about the company
Upgrade now
Cancel anytime. Secure checkout. Instant activation.