Millions of AI agents imperiled by critical vulnerability in open source package
325M weekly downloads. One critical vulnerability. Here's why your AI agent infrastructure just became a board-level risk.

Why it matters
A critical security flaw in Starlette—a foundational open-source package used across AI agent deployments—exposes millions of AI systems to compromise. This elevates supply-chain security from a CTO talking point to an existential infrastructure risk for any org running autonomous agents in production.
The key facts
5 to knowVulnerability found in Starlette package
Starlette has 325 million weekly downloads
Affects millions of AI agents
Open source supply chain risk
Published May 26, 2026
Go to the source
Ars Technicaarstechnica.com
Publisher excerpt: "BadHost" was found in Starlette, a package with 325 million weekly downloads.
