Vellum Serve's model upload endpoint skips authentication, so an attacker can upload a crafted config file and run code on the server. The maintainers say attacks are under way and urge users to move to 2.11.0.
Sample content: on the live site this story follows the same structure, with what happened, who is affected, what to do, an FAQ and sources.


