{"data":{"id":"4dde9bb4-8f0c-4966-9212-66498626a4dc","title":"CVE-2026-58195: Agentic-Flow is an AI agent orchestration platform. Prior to 2.0.14, agentic-flow MCP server tools in src/mcp/standalone","summary":"Agentic-Flow, an AI agent orchestration platform (a system that manages and coordinates multiple AI agents working together), had a critical vulnerability in versions before 2.0.14 where user-controlled input was directly inserted into shell commands without proper safety checks, allowing attackers to execute arbitrary operating system commands with the server's permissions.","solution":"Update to version 2.0.14 or later, which fixes this vulnerability.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-58195","publishedAt":"2026-07-17T19:17:17.410Z","cveId":"CVE-2026-58195","cweIds":["CWE-78"],"cvssScore":"8.8","cvssSeverity":"high","severity":"high","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["Agentic-Flow"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-07-17T19:17:17.410Z","capecIds":["CAPEC-88"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":["AML.T0010"]}}