Advisories
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
40 items
A critical remote code execution flaw in WeKnora's database query tool lets an unauthenticated attacker run arbitrary code on the database server with database user privileges. The Phase 5 validateNode() function in internal/utils/inject.go has no handler for ArrayExpr or RowExpr nodes, so dangerous PostgreSQL functions such as pg_read_file() nested inside array expressions skip validation and pass all seven checks.
WeKnora's tenant management endpoints (GET /api/v1/tenants, GET, PUT and DELETE /api/v1/tenants/{id}) do not check that the caller owns the tenant or holds cross-tenant privileges. Any authenticated user can therefore read, modify or delete any tenant by ID, and because account registration is open, an unauthenticated attacker can register and exploit this. The reporter demonstrates that listing tenants exposes other tenants' API keys, which grant actions on those accounts.
PinchTab, a standalone HTTP server that gives AI agents direct control over a Chrome browser, contains a Server-Side Request Forgery (SSRF) flaw in its /download endpoint in versions prior to 0.7.7 (CWE-918). Any user with API access can make the server request arbitrary URLs, including internal network services and local system files, and exfiltrate the full response content.
Fix: This issue has been patched in version 0.7.7.
NVD/CVE DatabaseWeKnora's database query tool fails to enforce tenant isolation on the models, messages and embeddings tables, which are allowed by WithSecurityDefaults() but absent from the tenantID-filtered list in internal/utils/inject.go. Any authenticated tenant can run SELECT queries against these tables and read other tenants' data, including API keys, model configurations and private messages, with no extra precondition beyond ordinary user access.
Flowise's global authentication middleware whitelists the `/api/v1/nvidia-nim` route through `WHITELIST_URLS` in `packages/server/src/utils/constants.ts`, so no JWT or API-key check runs for any endpoint under `/api/v1/nvidia-nim/*`, and the controllers in `packages/server/src/controllers/nvidia-nim/index.ts` perform no authentication of their own. Unauthenticated callers can reach `/get-token`, which returns a valid NVIDIA API token, and endpoints that list, start, stop and pull Docker containers and images. The issue is rated CVSS 3.1 8.6 (High) under CWE-306.
GHSA-cwc3-p92j-g7qm describes an Insecure Direct Object Reference in the PUT /api/v1/loginmethod endpoint of the Flowise platform. The endpoint accepts an organizationId from the JSON body and updates that organization's record without checking that the authenticated user owns it or has admin rights, so any low-privileged user, including Free plan users, can overwrite another organization's SSO configuration. The source states this enables Account Takeover by replacing the victim's OAuth credentials with attacker-controlled ones, and enabling Enterprise-only SSO features without a license.
A mass assignment flaw in the `/api/v1/leads` endpoint of Flowise lets unauthenticated users set internal entity fields (`id`, `createdDate`, `chatId`) by including them in the request body. The `createLead` function in `/packages/server/src/services/leads/index.ts` calls `Object.assign(newLead, body)` without filtering fields, overwriting the auto-generated values before save. The endpoint is listed in `WHITELIST_URLS` in `/packages/server/src/utils/constants.ts`, so no authentication is required. The source is tagged CWE-915.
The `/api/v1/attachments/:chatflowId/:chatId` endpoint in Flowise is listed in `WHITELIST_URLS`, so it accepts uploads without authentication. The server checks uploads against the MIME types in `chatbotConfig.fullFileUpload.allowedUploadFileTypes` but trusts the client-supplied `Content-Type` header without checking file contents or extension. An attacker can upload scripts or other arbitrary files by declaring a permitted type such as `application/pdf`, and the files persist in backend storage. Chained with static hosting or file retrieval, this can lead to Stored XSS, malicious file hosting, or Remote Code Execution.
Flowise trusts any HTTP client that sends the header `x-request-from: internal`, so an authenticated tenant session with only a browser cookie can bypass the authorization checks on `/api/v1/**`. The flaw sits in the global middleware at `external/Flowise/packages/server/src/index.ts:214`, which calls `verifyToken` for that header and runs no further permission checks. The source says the bypass grants access to internal administration endpoints such as `/api/v1/apikey`, `/api/v1/credentials`, `/api/v1/tools` and `/api/v1/node-custom-function`, and that all self-hosted Flowise 3.0.8 deployments using the default middleware are affected.
GitHub Copilot CLI's shell tool contains a vulnerability in which crafted bash parameter expansion patterns (such as ${var@P}, assignment forms like ${var=value}, indirect ${!var}, and nested $(cmd) inside ${...}) can hide command execution inside commands the safety assessment classifies as read-only. An attacker who can influence the commands the agent runs, for example through prompt injection in repository files, MCP server responses, or user instructions, could achieve arbitrary code execution on the user's workstation, even in modes that require approval for write operations. The issue affects versions prior to 0.0.423.
CVE-2026-28795 is a path traversal flaw (CWE-22) in the save_report tool in openchatbi/tool/save_report.py of OpenChatBI, an LLM-powered chat BI tool. Prior to version 0.2.2, insufficient sanitization of the file_format parameter lets it traverse paths. GitHub, Inc. rated it CVSS 4.0 8.7 (HIGH) with network attack vector, low complexity, no privileges and no user interaction required, with high confidentiality impact.
Fix: This issue has been patched in version 0.2.2.
CVE-2026-28677 affects OpenSift, an AI study tool that uses semantic search and generative AI, in versions prior to 1.6.3-alpha. Its URL ingest pipeline accepted user-controlled remote URLs with incomplete destination restrictions, so private and local host checks were missing coverage for credentialed URLs, non-standard ports, and cross-host redirects, leaving SSRF-class abuse paths in non-localhost deployments. The issue is classified as CWE-918.
Fix: This issue has been patched in version 1.6.3-alpha.
CVE-2026-28676 affects OpenSift, an AI study tool that uses semantic search and generative AI. Prior to version 1.6.3-alpha, multiple storage helpers did not uniformly enforce base-directory containment in their path construction, creating path-injection risk in file read, write and delete flows when malicious path-like values were introduced. The weakness is classified as CWE-22.
Fix: This issue has been patched in version 1.6.3-alpha.
NLTK versions <=3.9.2 are affected by CVE-2026-0848, an improper input validation flaw in the StanfordSegmenter module. The module loads external Java .jar files without verification or sandboxing, and the JAR is executed via subprocess with unvalidated classpath input. An attacker who supplies or replaces the JAR can run arbitrary Java bytecode at import time, reachable through model poisoning, MITM attacks, or dependency poisoning.
Trivy VSCode Extension version 1.8.12, distributed through the OpenVSX marketplace, was compromised and contained malicious code. The code was designed to use a local AI coding agent to collect and exfiltrate sensitive information. The malicious artifact has been removed from the marketplace, and no other affected artifacts have been identified.
A URL parameter injection flaw in LangSmith Studio, part of the langchain-ai/helm charts prior to version 0.12.71, could send an authenticated user's bearer token, user ID and workspace ID to an attacker-controlled server. The flaw affects both LangSmith Cloud and self-hosted deployments. Exploitation requires a victim to click a crafted link, and the stolen tokens expire after 5 minutes, though repeated attacks against the same user remain possible.
Fix: Fixed in 0.12.71, which requires user-defined allowed origins for the baseUrl parameter so tokens cannot be sent to unauthorized servers. No known workarounds are available; self-hosted customers must upgrade to the patched version.
fickling versions up to and including 0.1.8 have an incomplete UNSAFE_IMPORTS blocklist that omits the stdlib modules uuid, _osx_support and _aix_support. Functions in these modules, such as uuid._get_command_stdout, _aix_support._read_cmd_output and _osx_support._find_build_tool, call subprocess.Popen() or os.system() with attacker-controlled arguments. A malicious pickle importing them passes fickling's UnsafeImports and NonStandardImports checks, and pickle.loads() runs the command.
Fix: Assessment: the modules uuid, _osx_support and _aix_support were added to the blocklist of unsafe imports (https://github.com/trailofbits/fickling/commit/ffac3479dbb97a7a1592d85991888562d34dd05b).
OpenClaw's gateway function `authorizeCanvasRequest()` in `src/gateway/server-http.ts` grants canvas endpoints (`/__openclaw__/a2ui/`, `/__openclaw__/canvas/`, `/__openclaw__/ws`) access to any HTTP request from a private IP that matches an authenticated WebSocket client, without checking the request's own credentials. Tested on openclaw 2026.2.17 on macOS 26.3, the flaw lets an unauthenticated attacker sharing an IP with a legitimate client, such as behind corporate NAT or in Kubernetes or Docker shared networking, gain full canvas access.
CVE-2026-0847 affects NLTK versions up to and including 3.9.2. Several CorpusReader classes, including WordListCorpusReader, TaggedCorpusReader, and BracketParseCorpusReader, fail to sanitize or validate file paths, which lets an attacker traverse directories and read arbitrary files on the server. The flaw is especially serious where user-controlled file inputs are processed, such as in ML APIs, chatbots, or NLP pipelines, and it can expose system files, SSH private keys, and API tokens. The source notes it may escalate to remote code execution when combined with other vulnerabilities.
OpenClaw versions `<= 2026.2.24` accepted some Slack interactive callbacks (`block_action`, `view_submission`, `view_closed`) before full sender authorization checks in shared workspace deployments that use sender restrictions. An unauthorized workspace member could enqueue system-event text into an active session, but the issue did not by itself provide unauthenticated access, cross-gateway isolation bypass, or host-level privilege escalation.
Fix: Fixed in `2026.2.25` (planned next npm release), via commit `ce8c67c314b93f570f53c2a9abc124e1e3a54715`. The source states that OpenClaw does not support adversarial multi-user isolation on a single shared gateway instance; the supported model is one trust boundary per gateway, with separate gateways or hosts for mutually untrusted users.
Fix: Fixed in 0.0.423. The fix adds parse-time detection that downgrades commands containing dangerous ${...} expansion operators or nested command/process substitutions from read-only to write-capable, and unconditionally blocks such commands at the tool execution layer regardless of permission mode, including --yolo / autopilot.
Fix: Users of the affected artifact are advised to immediately remove it and rotate environment secrets.
NVD/CVE Database