{"data":[{"id":"8482a398-0076-428b-8362-83d5e0417b81","title":"Connecting AI agents to enterprise knowledge","summary":"A survey of 300 data, AI, and technology executives by MIT Technology Review Insights finds that only about a third (34%) of organizations' agentic AI projects reach production. Legacy data systems, security and privacy concerns, and a lack of knowledge and context are the main points of failure. Data fragmentation was the top challenge to expanding agent access to knowledge, cited by 55% of respondents, while production leaders more often pointed to security and privacy concerns (72%).","sourceUrl":"https://www.technologyreview.com/2026/10/05/1145580/connecting-ai-agents-to-enterprise-knowledge/","publishedAt":"2026-10-05T15:47:52.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["industry","research"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"patchAvailable":null,"disclosureDate":"2026-10-05T15:47:52.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":null,"aiComponentTargeted":null,"llmSpecific":false,"classifierConfidence":0.8,"researchCategory":null,"atlasIds":null},{"id":"88bd1cd6-6a9c-4c4e-b773-5bd7e9a904ad","title":"New AI-powered government website uses Gemini, Grok, Trump official Gebbia says","summary":"The Trump administration's new chatbot on America.gov, which helps Americans navigate official government websites, is powered by AI from Google's Gemini and xAI's Grok, according to U.S. Chief Design Officer Joe Gebbia. Gebbia said the tool scans roughly 29,000 government websites to give personalized answers drawn only from official sources. The site was unveiled at a Washington event attended by President Donald Trump and Vice President JD Vance.","sourceUrl":"https://www.cnbc.com/2026/09/29/trump-ai-gemini-grok.html","publishedAt":"2026-09-29T16:55:13.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["industry","policy"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":["Google"],"affectedVendorsRaw":["Gemini","Grok","America.gov"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"patchAvailable":null,"disclosureDate":"2026-09-29T16:55:13.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":null,"aiComponentTargeted":null,"llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null},{"id":"00b5cdbe-674d-4404-84fd-6f095e2d8063","title":"CVE-2026-18875: IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook…","summary":"IBM Financial Transaction Manager (FTM) for RedHat OpenShift is affected by CVE-2026-18875, a RAG poisoning flaw (CWE-74) caused by an unauthenticated runbook upsert in the FTM AI agent server at api.vectordb.runbooks.js:51. An unauthenticated attacker can insert malicious runbook content into the agent's vector database. This can steer AI-driven MCP tool calls, potentially triggering unauthorized payment actions or exfiltrating payment data.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-18875","publishedAt":"2026-09-23T16:16:41.850Z","severity":"high","cvssSeverity":"high","cvssScore":"7.3","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-18875","cweIds":["CWE-74"],"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["IBM Financial Transaction Manager (FTM) AI agent server","MCP tools"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["rag_poisoning"],"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00218,"epssCheckedAt":"2026-10-10T02:59:17.261Z","kevDateAdded":null,"patchAvailable":null,"disclosureDate":"2026-09-23T16:16:41.850Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["integrity","confidentiality"],"aiComponentTargeted":"rag","llmSpecific":false,"classifierConfidence":0.93,"researchCategory":null,"atlasIds":["AML.T0020","AML.T0051.001"]},{"id":"05556d9c-4841-4236-9268-4633e14e93a5","title":"CVE-2026-85709: LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw…","summary":"LightRAG's API server, before version 1.5.5, returns raw Python exception text from error handlers in document_routes.py, graph_routes.py, query_routes.py, ollama_api.py and lightrag_server.py. A network client that triggers an error can read server filesystem paths, database host, port, user and database names, language-model provider diagnostics, configuration details and library internals, and with URI-configured backends possibly connection strings containing credentials. The default unauthenticated configuration makes these responses reachable without credentials.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-85709","publishedAt":"2026-09-22T17:17:27.020Z","severity":"medium","cvssSeverity":"medium","cvssScore":"5.3","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-85709","cweIds":["CWE-209"],"affectedPackages":["lightrag-hku@<= 1.5.4 (fixed: 1.5.5)"],"affectedVendors":[],"affectedVendorsRaw":["LightRAG"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Fixed in 1.5.5.","attackType":["other"],"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00386,"epssCheckedAt":"2026-10-10T03:00:36.826Z","kevDateAdded":null,"patchAvailable":true,"disclosureDate":"2026-09-22T17:17:27.020Z","capecIds":["CAPEC-54"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null},{"id":"cbdc4565-46e9-4989-b3bc-643916d0ec40","title":"CVE-2026-53557: SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated…","summary":"SQLBot, a Text-to-SQL system built on large language models and RAG, is affected prior to version 1.9.0. An authenticated user can submit a crafted sheet[\"tableName\"] value through POST /api/v1/datasource/, which is stored without safe identifier handling. When the datasource is later removed via DELETE /api/v1/datasource/{id}, PostgreSQL executes the stored value in cleanup SQL, allowing COPY TO PROGRAM and arbitrary operating-system commands under the postgres process privileges inside the SQLBot container.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-53557","publishedAt":"2026-09-17T22:17:00.243Z","severity":"critical","cvssSeverity":null,"cvssScore":null,"labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-53557","cweIds":["CWE-89"],"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["SQLBot"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Fixed in version 1.9.0.","attackType":["other"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00336,"epssCheckedAt":"2026-10-10T02:57:23.167Z","kevDateAdded":null,"patchAvailable":null,"disclosureDate":"2026-09-17T22:17:00.243Z","capecIds":["CAPEC-66"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":["AML.T0020","AML.T0051.001"]},{"id":"c791eb33-2c63-4b6f-9e44-1e749dfa4d66","title":"CVE-2026-53556: SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST…","summary":"SQLBot, a Text-to-SQL system built on large language models and RAG, is affected by CVE-2026-53556 before version 1.9.0. The POST /api/v1/datasource/previewData endpoint places the client-controlled table_name value into generated SQL without safe identifier handling. An authenticated user can use a crafted table_name to call pg_read_file(), pg_read_binary_file() or pg_ls_dir() through a datasource pointed at the internal PostgreSQL service, reading filesystem content such as /etc/hosts and /etc/passwd, and potentially configuration, credentials and source code. In the default tested trusted loopback authentication configuration, the connection runs with PostgreSQL superuser privileges.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-53556","publishedAt":"2026-09-17T22:17:00.073Z","severity":"high","cvssSeverity":null,"cvssScore":null,"labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-53556","cweIds":["CWE-89"],"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["SQLBot"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"This issue is fixed in version 1.9.0.","attackType":["other"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00482,"epssCheckedAt":"2026-10-10T02:57:07.563Z","kevDateAdded":null,"patchAvailable":null,"disclosureDate":"2026-09-17T22:17:00.073Z","capecIds":["CAPEC-66"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"rag","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null},{"id":"bd960cd1-7e7c-4950-b7d5-59af39732666","title":"CVE-2026-53555: SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated…","summary":"SQLBot, a Text-to-SQL system built on large language models and RAG, stores uploaded image/svg+xml assistant UI logos without sanitizing embedded active content before version 1.9.0. An authenticated uploader can submit such a file through PATCH /api/v1/system/assistant/ui, and SQLBot serves it inline from the same origin via GET /api/v1/system/assistant/picture/{filename}. When another user loads the file, embedded JavaScript runs in the SQLBot web application context with access to the victim's session data and actions.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-53555","publishedAt":"2026-09-17T22:16:59.917Z","severity":"medium","cvssSeverity":null,"cvssScore":null,"labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-53555","cweIds":["CWE-79"],"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["SQLBot"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Fixed in 1.9.0.","attackType":["other"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00483,"epssCheckedAt":"2026-10-10T02:56:51.777Z","kevDateAdded":null,"patchAvailable":null,"disclosureDate":"2026-09-17T22:16:59.917Z","capecIds":["CAPEC-198","CAPEC-86"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"framework","llmSpecific":true,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null},{"id":"931ea1e0-e2f1-4e02-85e7-4fdb5f08ea80","title":"CVE-2026-53554: SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST…","summary":"CVE-2026-53554 affects SQLBot, a Text-to-SQL system built on large language models and RAG, prior to 1.9.0. The POST /api/v1/datasource/parseExcel endpoint trusts attacker-controlled multipart filenames when choosing storage, and it writes uploaded content before spreadsheet parsing and validation finish. A crafted upload can plant a Python file in /opt/sqlbot/app/alembic/versions/ even when parsing fails and the endpoint returns an error. On the next startup or migration, Alembic imports that file and runs its module-level statements inside the SQLBot runtime.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-53554","publishedAt":"2026-09-17T22:16:59.770Z","severity":"high","cvssSeverity":null,"cvssScore":null,"labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-53554","cweIds":["CWE-22"],"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["SQLBot"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Fixed in 1.9.0.","attackType":["other"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00415,"epssCheckedAt":"2026-10-10T02:55:14.110Z","kevDateAdded":null,"patchAvailable":null,"disclosureDate":"2026-09-17T22:16:59.770Z","capecIds":["CAPEC-126"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":["AML.T0010"]},{"id":"d6f88aea-897d-44e9-a0d4-e4dfb936b89e","title":"When the prompt becomes the payload: A practical pen-testing guide for GenAI, LLM and RAG applications","summary":"A practical pen-testing guide for generative AI, LLM and RAG applications argues that the security question has shifted from whether a model says something it should not to whether manipulated language can reach protected data or trigger unauthorized business actions. It recommends starting with an architecture walk-through that maps prompts, retrieval, tools, identities and logging, then treating prompt injection as a multi-turn campaign rather than a single-phrase test.","sourceUrl":"https://www.csoonline.com/article/4219801/when-the-prompt-becomes-the-payload-a-practical-pen-testing-guide-for-genai-llm-and-rag-applications.html","publishedAt":"2026-09-09T10:00:00.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["prompt_injection","jailbreak"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"patchAvailable":null,"disclosureDate":"2026-09-09T10:00:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity","safety"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null},{"id":"4c76ce80-fd5e-4087-a74d-6445cee1e7eb","title":"Towards Trustworthy Retrieval Augmented Generation for Large Language Models: A Survey","summary":"This survey reviews trustworthiness in Retrieval Augmented Generation (RAG) for large language models. The source text provided is limited to the bibliographic line (ACM Computing Surveys, Volume 58, Issue 15, Pages 1-36, November 2026) and does not include the article body, so no findings or methods can be reported.","sourceUrl":"https://dl.acm.org/doi/abs/10.1145/3837074?af=R","publishedAt":"2026-09-05T12:01:33.241Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"patchAvailable":null,"disclosureDate":null,"capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":null,"aiComponentTargeted":"rag","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"31fe5829-c975-422f-86d6-f3cbeda56276","title":"DP2-RAG: An Efficient Full-Process Differential Privacy Implementation in Retrieval-Augmented Generation","summary":"DP2-RAG is a framework that adds end-to-end differential privacy to Retrieval-Augmented Generation, covering both the retrieval stage and the generation stage. It introduces Noise-Aware Retrieval with Correction (NARC), which enforces chunk-level DP with calibrated noise and ranking-bias correction, and the Dual Utility-Exponent Mechanism (DUEM), which provides token-level DP for generated surrogates. Evaluated on six benchmarks, it reduces privacy leakage by over 15% relative to strong baselines while keeping near-baseline Top-k retrieval accuracy.","sourceUrl":"http://ieeexplore.ieee.org/document/11660753","publishedAt":"2026-08-20T13:16:16.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["research","privacy"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["data_extraction","pii_leakage"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"patchAvailable":null,"disclosureDate":"2026-08-20T13:16:16.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"rag","llmSpecific":true,"classifierConfidence":0.93,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"759f5c3d-2b46-431c-854b-ffc604f84e1d","title":"How avatarin built a 24/7 retail agent with GPT-Realtime","summary":"avatarin, an AI customer service company spun out of ANA Holdings, partnered with Yamada Holdings to build a 24/7 multilingual shopping agent called the Kurashi-Marugoto AI Agent, built on OpenAI's GPT-Realtime. In a two-week public campaign on Yamada Denki's online store, approximately 30,000 people used the agent, and 92% of survey responses were positive.","sourceUrl":"https://openai.com/index/avatarin","publishedAt":"2026-07-30T00:00:00.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["industry"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":["OpenAI"],"affectedVendorsRaw":["OpenAI","GPT-Realtime","avatarin","Kurashi-Marugoto AI Agent","Yamada Denki"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"patchAvailable":null,"disclosureDate":"2026-07-30T00:00:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":null,"aiComponentTargeted":null,"llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null},{"id":"d9a3a228-cafb-40a7-9a5e-244dc1598157","title":"CVE-2026-56273: Flowise before 3.1.0 contains a path traversal vulnerability in Faiss and SimpleStore vector store implementations that…","summary":"CVE-2026-56273 affects Flowise before 3.1.0. The Faiss and SimpleStore vector store implementations accept unsanitized basePath parameters from authenticated users, a path traversal flaw (CWE-22). An attacker with a valid API token can write vector store data to arbitrary filesystem locations, which the source says could enable code execution or data exfiltration.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-56273","publishedAt":"2026-07-08T14:17:15.800Z","severity":"medium","cvssSeverity":"medium","cvssScore":"6.5","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-56273","cweIds":["CWE-22"],"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Flowise"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Fixed in 3.1.0. Upgrade Flowise to version 3.1.0 or later.","attackType":["other"],"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.005,"epssCheckedAt":"2026-10-10T02:57:56.487Z","kevDateAdded":null,"patchAvailable":null,"disclosureDate":"2026-07-08T14:17:15.800Z","capecIds":["CAPEC-126"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity"],"aiComponentTargeted":"rag","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":["AML.T0010"]},{"id":"55a1e963-1a73-4541-b53b-04b2a9287c7e","title":"The foundational elements of AI architecture that IT leaders need to scale","summary":"Sponsored content from a news source argues that IT leaders should invest in four foundational elements of AI architecture that will last as models advance: data quality, context engineering, governance, and human expertise. It frames these as a stable basis for deploying AI agents that retrieve information, make decisions, and run workflows across systems.","sourceUrl":"https://www.technologyreview.com/2026/07/07/1139413/the-foundational-elements-of-ai-architecture-that-it-leaders-need-to-scale/","publishedAt":"2026-07-07T11:10:52.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["industry","policy"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Elastic"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"patchAvailable":null,"disclosureDate":"2026-07-07T11:10:52.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":null,"aiComponentTargeted":null,"llmSpecific":false,"classifierConfidence":0.8,"researchCategory":null,"atlasIds":null},{"id":"ef27725e-c2b9-444c-93b7-6da1347526ed","title":"Bias Amplification in RAG: Poisoning Knowledge Retrieval to Steer LLMs","summary":"Researchers show that poisoning a retrieval-augmented generation (RAG) system can amplify bias in an LLM's outputs, even for gender-neutral queries. Their Bias Retrieval and Reward Attack (BRRA) framework generates adversarial documents using multi-objective reward functions, manipulates retrieval with subspace projection, and uses a cyclic feedback mechanism, with experiments on several mainstream models showing significant bias increases. The paper also explores a dual-stage defense mechanism to mitigate the attack.","sourceUrl":"http://ieeexplore.ieee.org/document/11593155","publishedAt":"2026-07-02T13:17:56.000Z","severity":"low","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"The source mentions a dual-stage defense mechanism that it says can effectively mitigate the impacts of the attack, but it does not describe its specifics, configuration or implementation.","attackType":["rag_poisoning"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"patchAvailable":null,"disclosureDate":"2026-07-02T13:17:56.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["integrity"],"aiComponentTargeted":"rag","llmSpecific":true,"classifierConfidence":0.93,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"a363128a-0286-475c-ac5d-94eb768d3db1","title":"External Data Extraction Attacks Against Retrieval-Augmented Large Language Models","summary":"This paper formalizes external data extraction attacks (EDEAs) against retrieval-augmented LLMs (RA-LLMs), where sensitive or copyrighted knowledge-base data can be extracted verbatim. The authors propose a framework built from extraction instruction, jailbreak operator, and retrieval trigger, and implement an attack called Secret. Across 4 models, including 3 commercial LLMs, Secret outperforms prior attacks and succeeds against all 16 tested RAG instances, extracting 35% of the data from RAG powered by Claude 3.7 Sonnet where other attacks yield 0%.","sourceUrl":"http://ieeexplore.ieee.org/document/11570932","publishedAt":"2026-06-18T13:16:36.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":["Anthropic"],"affectedVendorsRaw":["Claude 3.7 Sonnet","RAG-powered LLMs"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["data_extraction","jailbreak"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"patchAvailable":null,"disclosureDate":"2026-06-18T13:16:36.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality"],"aiComponentTargeted":"rag","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"c3d0d5cc-1711-44e1-ad5f-19bcc241eeec","title":"Trigger as Entity: Backdoor Attacks to Graph-Based Retrieval-Augmented Generation of Large Language Models","summary":"Researchers present the first backdoor attacks against graph-based Retrieval-Augmented Generation (RAG) systems used with LLMs. The attacker poisons a crafted corpus in the external database so that trigger entities are inserted into the knowledge graph, causing the model to give attacker-chosen answers only for trigger-containing queries while answering other queries correctly. The authors evaluate three trigger types (word-level, topic-level and semantic-level) with increasing stealth across multiple knowledge databases and language models, and warn of risks to chatbots and agents built on such systems.","sourceUrl":"http://ieeexplore.ieee.org/document/11547227","publishedAt":"2026-06-02T13:17:17.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["LLMs","graph-based RAG systems","chatbots","agents"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["rag_poisoning","jailbreak"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"patchAvailable":null,"disclosureDate":"2026-06-02T13:17:17.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["integrity","safety"],"aiComponentTargeted":"rag","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"6cc859ea-0ba1-454e-bac0-84ae52183830","title":"CVE-2026-45312: RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template…","summary":"CVE-2026-45312 affects RAGFlow, an open-source RAG engine, in version 0.24.0 and earlier. A Jinja2 template injection in the prompt generator (rag/prompts/generator.py) lets any authenticated user execute arbitrary OS commands on the server. Any normal user can register, create a Canvas workflow with a DuckDuckGo + LLM component chain, and trigger the flaw. The weakness is classified as CWE-1336.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-45312","publishedAt":"2026-05-29T13:16:22.770Z","severity":"critical","cvssSeverity":"critical","cvssScore":"9.9","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-45312","cweIds":["CWE-1336"],"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["RAGFlow"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["other"],"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00518,"epssCheckedAt":"2026-10-10T02:53:51.752Z","kevDateAdded":null,"patchAvailable":null,"disclosureDate":"2026-05-29T13:16:22.770Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.93,"researchCategory":null,"atlasIds":["AML.T0020","AML.T0051.001"]},{"id":"62926c0a-583c-4734-a7ac-e37277fcb537","title":"ParaVul: A Parallel Large Language Model and Retrieval-Augmented Framework for Smart Contract Vulnerability Detection","summary":"ParaVul is a framework that combines parallel LLM fine-tuning with retrieval-augmented generation to detect smart contract vulnerabilities more accurately than static analysis and formal verification. It introduces Sparse Low-Rank Adaptation (SLoRA), which inserts parallel sparse and low-rank branches after the attention projection and feed-forward block, and a hybrid RAG system combining Okapi BM25 with dense retrieval. Simulation results report F1 scores of 0.9398 for single-label and 0.9930 for multi-label detection.","sourceUrl":"http://ieeexplore.ieee.org/document/11523597","publishedAt":"2026-05-18T13:18:18.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["research","security"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"patchAvailable":null,"disclosureDate":"2026-05-18T13:18:18.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":null,"aiComponentTargeted":null,"llmSpecific":true,"classifierConfidence":0.85,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"11613dd4-9487-4828-bb68-4b0e0798b88a","title":"GHSA-r472-mw7m-967f: Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints","summary":"Multiple Open WebUI endpoints accept a user-supplied `file_id` and attach that file to a resource the caller controls without checking the caller's access to the file. Path 1 is `POST /api/v1/folders/{id}/update` through the folder knowledge consumer in `backend/open_webui/utils/middleware.py`, where the referenced file becomes RAG context for chat completions. Path 2 is the knowledge-base attach endpoints in `backend/open_webui/routers/knowledge.py`, which grant read and write access to the file through `/api/v1/files/{id}/content` and `/api/v1/files/{id}/data/content/update`. An authenticated user who knows another user's file UUID can exfiltrate that file, and on Path 2 also overwrite it.","sourceUrl":"https://github.com/advisories/GHSA-r472-mw7m-967f","publishedAt":"2026-05-14T20:27:35.000Z","severity":"high","cvssSeverity":"high","cvssScore":null,"labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-45402","cweIds":null,"affectedPackages":["open-webui@<= 0.9.4 (fixed: 0.9.5)"],"affectedVendors":[],"affectedVendorsRaw":["Open WebUI"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["other"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00393,"epssCheckedAt":"2026-10-10T03:00:37.498Z","kevDateAdded":null,"patchAvailable":true,"disclosureDate":"2026-05-14T20:27:35.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"rag","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}],"meta":{"total":40,"limit":20,"offset":0}}