Skip to content

Corrections

Every change made to a record's classification after it was published, with the reason. Reports come from the form on each record page; the classifier audit and the maintainer's own review find the rest. Dataset releases are frozen, so a correction applies to the live site and to the next release.

Corrections
633
Reports received
0
Reports declined
0
Reports open
0

Each correction is listed as its own row. Group bulk changes

DateRecordChangeReasonFound by
2026-10-10CVE-2026-27167: Gradio token leak through mocked OAuth login routeCVE-2026-27167Severity: none to infoThe source rates this CVE as CVSS none (base score 0.0). The site has no such level and records it as info, its lowest.Maintainer review
2026-10-10CVE 2020-16977: VS Code Python Extension Remote Code ExecutionSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Malicious Python Packages and Code Execution via pip downloadSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10ChatGPT Plugins: Data Exfiltration via Images & Cross Plugin Request ForgerySeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Video: Data Exfiltration Vulnerabilities in LLM apps (Bing Chat, ChatGPT, Claude)Severity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Malicious ChatGPT Agents: How GPTs Can Quietly Grab Your Data (Demo)Severity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10ChatGPT: Lack of Isolation between Code Interpreter sessions of GPTsSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10GitHub Copilot Chat: From Prompt Injection to Data ExfiltrationSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Microsoft Copilot: From Prompt Injection to Exfiltration of Personal InformationSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Spyware Injection Into Your ChatGPT's Long-Term Memory (SpAIware)Severity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10DeepSeek AI: From Prompt Injection To Account TakeoverSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Security Advisory: Anthropic's Slack MCP Server Vulnerable to Data ExfiltrationSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Exfiltrating Your ChatGPT Chat History and Memories With Prompt InjectionSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Turning ChatGPT Codex Into A ZombAI AgentSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Anthropic Filesystem MCP Server: Directory Access Bypass via Improper Path ValidationSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Cursor IDE: Arbitrary Data Exfiltration Via Mermaid (CVE-2025-54132)Severity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Amp Code: Arbitrary Command Execution via Prompt Injection FixedSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10I Spent $500 To Test Devin AI For Prompt Injection So That You Don't Have ToSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10How Devin AI Can Leak Your Secrets via Multiple MeansSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10AI Kill Chain in Action: Devin AI Exposes Ports to the Internet with Prompt InjectionSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10OpenHands and the Lethal Trifecta: How Prompt Injection Can Leak Access TokensSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10ZombAI Exploit with OpenHands: Prompt Injection To Remote Code ExecutionSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Claude Code: Data Exfiltration with DNS (CVE-2025-55284)Severity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10GitHub Copilot: Remote Code Execution via Prompt Injection (CVE-2025-53773)Severity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Google Jules: Vulnerable to Multiple Data Exfiltration IssuesSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Jules Zombie Agent: From Prompt Injection to Remote ControlSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Google Jules is Vulnerable To Invisible Prompt InjectionSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Amazon Q Developer: Secrets Leaked via DNS and Prompt InjectionSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Amazon Q Developer: Remote Code Execution with Prompt InjectionSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Amazon Q Developer for VS Code Vulnerable to Invisible Prompt InjectionSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Hijacking Windsurf: How Prompt Injection Leaks Developer SecretsSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10How Prompt Injection Exposes Manus' VS Code Server to the InternetSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10AWS Kiro: Arbitrary Code Execution via Indirect Prompt InjectionSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Cline: Vulnerable To Data Exfiltration And How To Protect Your DataSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10AgentHopper: An AI VirusSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Cross-Agent Privilege Escalation: When Agents Free Each OtherSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Prompt injection to RCE in AI agentsSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Claude Pirate: Abusing Anthropic's File API For Data ExfiltrationSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Antigravity Grounded! Security Vulnerabilities in Google's Latest IDESeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Lack of isolation in agentic browsers resurfaces old vulnerabilitiesSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Moltbook, the Social Network for AI Agents, Exposed Real Humans’ DataSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10What CISOs need to know about the OpenClaw security nightmareSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Google says hackers are abusing Gemini AI for all attacks stagesSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Fake AI Chrome extensions with 300K users steal credentials, emailsSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Google Reports State-Backed Hackers Using Gemini AI for Recon and Attack SupportSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Google fears massive attempt to clone Gemini AI through model extractionSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Claude LLM artifacts abused to push Mac infostealers in ClickFix attackSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Infostealer malware found stealing OpenClaw secrets for first timeSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Infostealer Steals OpenClaw AI Agent Configuration Files and Gateway TokensSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Was CISOs über OpenClaw wissen solltenSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit