News Grower

Independent coverage of AI, startups, and technology.

Ars Technica May 26, 2026 at 19:50 Big Tech Rising Hot

Millions of AI agents imperiled by critical vulnerability in open source package

"BadHost" was found in Starlette, a package with 325 million weekly downloads.

Signal weather

Rising

Momentum is building quickly, so this card is a good early entry point into the topic.

By Dan Goodin Original source
Millions of AI agents imperiled by critical vulnerability in open source package

Millions of AI agents and tools around the world have been imperiled by a critical vulnerability that can allow hackers to breach the servers running them and make off with sensitive data and credentials to third-party accounts, a security researcher is warning. The vulnerability is present in Starlette, an open source framework that its developer says receives 325 million downloads per week. Thousands of other open source projects are also vulnerable because they require Starlette to work. The framework is an implementation of the ASGI (asynchronous server gateway interface), which allows large numbers of requests to be efficiently processed simultaneously. Starlette is the base of FastAPI and other widely used frameworks for building services in Python apps, as well as many others. Trivial to exploit, millions of servers exposed ASGI, and by extension Starlette, have access to servers running the MCP (model context protocol), which allows AI agents from major providers to access external sources, including user data bases, email and calendar accounts, and all manner of other resources. To connect with these external systems, MCP servers store credentials for each one, making them especially valuable storehouses for attackers to breach. Read full article Comments

Stay on the signal

Follow Millions of AI agents imperiled by critical vulnerability in open source package

Follow this story beyond a single article: new follow-ups, adjacent sources, and the evolving storyline.

We send a confirmation link first, then only meaningful digests.

Story map

Understand this topic fast

A quick entry into the story: why it matters now, who is involved, and where to go next for context.

Why it matters now

Fresh coverage with immediate momentum.
There are already 6 connected articles in the same storyline to continue from here.
The story keeps orbiting around Ars Technica, BadHost, and Critical Vulnerability, so the entity pages are the fastest way to build context.
Ars Technica already has 4 follow-up stories on the same theme.

Topic constellation

Open the live map for this story

See which entities, story threads, sources, and follow-up articles shape this story right now.

Click nodes to continue

Entity Cluster Article Hub Source

Story timeline

Continue with this story

A short sequence of events and follow-up stories to understand the arc quickly.

May 26, 2026 at 22:27 Ars Technica

Is Peter Thiel the target of Pope Leo's Gandalf quote? An investigation.

Parsing a papal proclamation.

May 26, 2026 at 21:23 Ars Technica

Musk says US military suicide drones used Starlink in violation of SpaceX rules

Musk says drones used Starlink instead of Starshield, blames military contractor.

May 26, 2026 at 21:03 Ars Technica

NASA takes steps toward building Moon Base, including discussing a "perimeter"

"We also obviously want to be very mindful of the Outer Space Treaty."

May 26, 2026 at 20:47 Ars Technica

We're starting to see some PC makers respond to Apple's MacBook Neo

Sub-$600 laptops have existed for years, but consistently good ones remain rare.

May 26, 2026 at 19:50 Ars Technica

Millions of AI agents imperiled by critical vulnerability in open source package

"BadHost" was found in Starlette, a package with 325 million weekly downloads.

May 26, 2026 at 18:30 Ars Technica

Want an oxygen-rich atmosphere? Stuff oxygen’s friends in the mantle.

Getting carbon and sulfur into Earth’s interior may be part of oxygen’s story.

How reliable this looks

Signal and trust for Ars Technica

This source works at a rapid pace: 100% of recent stories land in the hot window, and 0% carry visible search signal.

Trusted

Reliability

92

Freshness

100

Sources in storyline

1

Related articles

More stories that share tags, source, or category context.

More from Ars Technica

Fresh reporting and follow-up coverage from the same newsroom.

Open source page