Advisories
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
48 items
Langflow versions prior to 1.9.0 contain CVE-2026-33873 in the Agentic Assistant feature. Its validation phase executes LLM-generated Python code, reaching dynamic execution sinks and instantiating the generated class server-side. Where an attacker can access the feature and influence model output, this allows arbitrary server-side Python execution.
Fix: Version 1.9.0 fixes the issue.
NVD/CVE DatabaseGitHub's Advisory Database published GHSA-5mg7-485q-xm76 on March 25, 2026, covering two malicious releases of the pip package litellm. Versions >= 1.82.7 and <= 1.82.8 were published containing credential harvesting malware, and the advisory lists no patched versions.
NVIDIA APEX for Linux contains a vulnerability, tracked as CVE-2025-33244 and classified as CWE-502 (Deserialization of Untrusted Data), that lets an unauthorized attacker cause deserialization of untrusted data. The flaw affects environments that use PyTorch versions earlier than 2.6. A successful exploit might lead to code execution, denial of service, escalation of privileges, data tampering, and information disclosure.
Multiple GitHub Actions workflows in the Langflow repository prior to version 1.9.0 interpolate GitHub context variables such as `${{ github.head_ref }}` directly into `run:` steps without sanitization. A malicious branch name or pull request title lets an unauthenticated attacker inject and execute arbitrary shell commands during CI/CD runs, potentially exposing secrets such as `GITHUB_TOKEN`, manipulating infrastructure, or compromising the supply chain. The proof of concept sends the CI token to an external URL.
Fixed in 1.9.0. The advisory's suggested fix is to refactor affected workflows to pass user-controlled values through environment variables and wrap them in double quotes, and to avoid direct `${{ ... }}` interpolation inside `run:` for user-controlled values.
CVE-2026-5002 affects PromtEngineer localGPT up to commit 4d41c7d1713b16b216d8e062e51a5dd88b20b054. The flaw sits in the function _route_using_overviews in backend/server.py, within the LLM Prompt Handler component, and manipulation there leads to injection. The attack can be performed remotely, and public exploit code may be used.
giskard-agents versions up to 0.3.3 and the 1.0.x alpha line pass the string argument of ChatWorkflow.chat() directly into an unsandboxed Jinja2 Environment, so user input is parsed as a template. A developer who passes user input to this method exposes the server to remote code execution through Jinja2 class traversal, which can run system commands, read files and access environment variables.
Fix: Update to 0.3.4 (or 1.0.2b1 for the pre-release branch), which replaces the unsandboxed Jinja2 Environment with SandboxedEnvironment.
CVE-2026-33654 affects nanobot, a personal AI assistant, prior to version 0.1.6. An indirect prompt injection flaw in the email channel processing module (`nanobot/channels/email.py`) lets a remote, unauthenticated attacker run arbitrary LLM instructions, and then system tools, by sending an email to the bot's monitored address. The bot polls and processes that content as highly trusted input, bypassing channel isolation, so the attack needs no action from the bot owner.
LibreChat versions 0.8.2-rc2 through 0.8.2 are vulnerable to server-side request forgery (SSRF) when agent actions or MCP are used. The earlier fix for GHSA-rgjq-4q58-m3q8 added hostname validation but does not check whether DNS resolution yields a private IP address, so an attacker can bypass it and reach internal resources such as an internal RAG API or cloud instance metadata endpoints.
Fix: Version 0.8.3-rc1 contains a patch.
CVE-2026-31943 affects LibreChat before version 0.8.3. The function `isPrivateIP()` in `packages/api/src/auth/domain.ts` fails to detect IPv4-mapped IPv6 addresses in hex-normalized form. Any authenticated user can exploit this to bypass SSRF protection and make the server send HTTP requests to internal resources, including cloud metadata services such as `169.254.169.254`, loopback, and RFC1918 ranges.
Fix: Fixed in 0.8.3.
Multiple functions in `langchain_core.prompts.loading` read files from paths in deserialized config dicts without checking for absolute paths or `..` traversal. When an application passes user-influenced prompt configurations to `load_prompt()` or `load_prompt_from_config()`, an attacker can read arbitrary host files, limited only by `.txt`, `.json`, `.yaml` and `.yml` extension checks.
Fix: Update `langchain-core` to >= 1.2.22. The fix rejects absolute paths and `..` sequences by default, with an `allow_dangerous_paths=True` argument for trusted inputs. The legacy APIs are deprecated and will be removed in 2.0.0; migrate to `dumpd`/`dumps`/`load`/`loads` from `langchain_core.load`.
Langflow's `_read_flow` helper in `src/backend/base/langflow/api/v1/flows.py` omitted an ownership check when `AUTO_LOGIN` was `False`, so any authenticated user could read, modify, or delete another user's flow via `GET/PATCH/DELETE /api/v1/flow/{flow_id}`. Exposed data included embedded plaintext API keys, and attackers could alter other users' AI agent logic. The flaw was introduced by conditional logic meant to support public example flows (`user_id = NULL`) under auto-login mode.
Fixed in PR #8956, which removes the `AUTO_LOGIN` conditional and unconditionally scopes the query to the requesting user with `Flow.user_id == user_id`. A cross-user isolation test, `test_read_flows_user_isolation`, was added to prevent regression.
The @mobilenext/mobile-mcp server has a path traversal flaw in the mobile_save_screenshot and mobile_start_screen_recording tools. The saveTo and output parameters are passed directly to filesystem write operations (fs.writeFileSync in src/server.ts) with no path validation, so an attacker can write files outside the intended workspace.
adx-mcp-server, at latest and commit 48b2933, contains KQL injection in three MCP tool handlers: get_table_schema, sample_table_data and get_table_details. The table_name parameter is interpolated into KQL via f-strings with no validation, so a caller or a prompt-injected agent can run arbitrary KQL against the Azure Data Explorer cluster, including reading other tables and issuing management commands such as .drop table. The flaw bypasses client trust boundaries because these tools are presented as safe metadata tools.
Any authenticated Open WebUI user can overwrite any file by ID through the POST /api/v1/retrieval/process/files/batch endpoint, because process_files_batch() in backend/open_webui/routers/retrieval.py has no ownership check before writing. Attackers can obtain valid file UUIDs from GET /api/v1/knowledge/{id}/files for any knowledge base they can read, and the overwritten content is then served to the LLM via RAG. Tested on Open WebUI 0.8.3 in a default Docker configuration.
Suggested fix: add an ownership check before writing, rejecting the file with "Permission denied: not file owner" unless db_file.user_id matches the requesting user or the user is an admin. No released fixed version is stated in the source.
CVE-2026-30304 affects AI Code's automatic terminal command execution. Its "Execute safe commands" option runs commands the model classifies as safe without user approval, but the design is highly susceptible to prompt injection. An attacker can wrap any malicious command in a generic template to make the model misclassify it as safe, bypassing approval and enabling arbitrary command execution.
CVE-2026-29871 is a path traversal vulnerability in the awesome-llm-apps project at commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-01-19), in the Beifong AI News and Podcast Agent FastAPI backend. The stream_audio function in routers/podcast_router.py, reached through the stream-audio endpoint, concatenates a user-controlled path parameter into a filesystem path without validation or restriction. An unauthenticated remote attacker can read arbitrary files from the server filesystem, potentially exposing configuration files and credentials.
CVE-2026-33718 affects OpenHands starting in version 1.5.0. The `path` parameter of the `/api/conversations/{conversation_id}/git/diff` endpoint is passed unsanitized to a shell command in `get_git_diff()` at `openhands/runtime/utils/git_handler.py:134`. An authenticated attacker can execute arbitrary commands in the agent sandbox, bypassing the normal channels through which the user may already instruct the agent to run commands.
Fix: Fixed in 1.5.0.
CVE-2026-27893 affects vLLM, an inference and serving engine for large language models, from version 0.10.1 before 0.18.0. Two model implementation files hardcode `trust_remote_code=True` when loading sub-components, overriding a user's explicit `--trust-remote-code=False` opt-out. This enables remote code execution through malicious model repositories even when remote code trust is disabled.
Fix: Version 0.18.0 patches the issue.
The patch for CVE-2026-32013 added symlink resolution and workspace boundary checks to agents.files.get and agents.files.set, but the agents.create and agents.update handlers in src/gateway/server-methods/agents.ts still call fs.appendFile on IDENTITY.md with no symlink containment check. An attacker who can plant a symlink in the agent workspace can redirect that write to an arbitrary file, such as /etc/crontab, and inject agent name, emoji and avatar content into it.
PinchTab v0.8.3 through v0.8.5 let a caller with the server token run arbitrary JavaScript in a tab through POST /wait and POST /tabs/{id}/wait when fn mode is used, even with security.allowEvaluate disabled. POST /evaluate enforces that guard, but /wait embedded the user-supplied fn expression into executable JavaScript without checking it. The flaw is a policy bypass rather than an authentication bypass, since authenticated API access is still required.
Fix: The current worktree applies the same policy boundary to fn mode in /wait that already exists on /evaluate, while preserving the non-code wait modes. As of publication, a patched version is not yet available.
Fix: Version 0.1.6 patches the issue. Upgrade to 0.1.6 or later.
NVD/CVE Database