A recent report from Protect AI Inc. has identified critical vulnerabilities in several widely used open-source tools for building AI systems, revealing potential security threats within the AI software supply chain. The vulnerabilities, discovered through Protect AI’s “huntr” bug bounty program, include severe flaws in Setuptools, Lunary, and Netaddr, which could lead to unauthorized code execution, data manipulation, and network intrusions. These vulnerabilities, which have now been patched, underscore the importance of robust security measures in the rapidly expanding AI landscape.