Advisories
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
59 items
LiteLLM's OIDC userinfo cache keys JWT tokens by their first 20 characters (`token[:20]`) when `enable_jwt_auth: true` is set. Because tokens from the same signing algorithm share identical leading characters, an unauthenticated attacker can craft a token that hits a legitimate user's cache entry and inherits that user's identity and permissions. The option is not enabled by default, so most instances are not affected.
Fix: Fixed in v1.83.0. The cache key now uses the full hash of the JWT token. Workaround: disable OIDC userinfo caching by setting the cache TTL to 0, or disable JWT authentication entirely.
GitHub Advisory DatabaseCVE-2026-0545 affects mlflow/mlflow: the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` lack authentication and authorization when the `basic-auth` app is enabled, in the latest version of the repository. When job execution is enabled (`MLFLOW_SERVER_ENABLE_JOB_EXECUTION=true`) and any job function is allowlisted, any network client can submit, read, search, and cancel jobs without credentials, bypassing basic-auth. If allowed jobs perform privileged actions such as shell execution or filesystem changes, this can lead to unauthenticated remote code execution. Even with safe jobs, the flaw still enables job spam, denial of service, or data exposure in job results.
The execute_code() function in praisonai-agents runs attacker-controlled Python inside a three-layer sandbox. Passing a str subclass with an overridden startswith() method to the _safe_getattr wrapper bypasses the sandbox, allowing arbitrary OS command execution on the host as the process user. Deployments using bot.py, autonomy_mode.py, or bots_cli.py set PRAISONAI_AUTO_APPROVE=true by default, so the tool can fire without human confirmation when triggered via indirect prompt injection.
GHSA-vv7q-7jx5-f767 affects the OpenAPIProvider in FastMCP, which parses OpenAPI specifications to expose internal APIs to MCP clients. The _build_url() method in fastmcp/utilities/openapi/director.py substitutes path parameter values into URL templates without URL-encoding, and urljoin() then resolves ../ sequences, letting an attacker reach arbitrary backend endpoints. Because requests carry the MCP provider's configured authorization headers, the flaw results in authenticated SSRF.
CVE-2026-34162 affects FastGPT, an AI Agent building platform, prior to version 4.14.9.5. The HTTP tools testing endpoint /api/core/app/httpTools/runTool is exposed without any authentication and acts as a full HTTP proxy, accepting a user-supplied baseUrl, toolPath, method, headers and body, then returning the complete server-side response to the caller. It is classified as CWE-306 (Missing Authentication for Critical Function) and CWE-918 (Server-Side Request Forgery).
This issue has been patched in version 4.14.9.5.
CVE-2026-2287 affects CrewAI. The framework does not properly verify that Docker is still running at runtime, and it falls back to a sandbox setting that allows remote code execution (RCE). The NVD had not yet provided an assessment at publication, and CERT/CC is listed as the source.
The mobile_open_url tool in @mobilenext/mobile-mcp passes user-supplied URLs straight to Android's intent system through adb shell am start without scheme validation. Because MCP servers are driven by AI agents that can be manipulated through prompt injection, a malicious document or website could make the agent open tel:, sms:, mailto:, content:// or market:// URLs, enabling USSD codes, calls, SMS drafts, content provider access and app installation prompts.
Upgrade to version 0.0.50 or later, which restricts mobile_open_url to http:// and https:// schemes by default. Users who need other URL schemes can opt in by setting MOBILEMCP_ALLOW_UNSAFE_URLS=1.
BentoML's generate_containerfile() in src/bentoml/_internal/container/generate.py renders user-supplied dockerfile_template files with an unsandboxed jinja2.Environment that loads the jinja2.ext.do and jinja2.ext.debug extensions. A malicious bento archive containing a crafted template runs arbitrary Python on the host when a victim imports it and runs bentoml containerize, before any Docker container is created, bypassing container isolation.
BentoML's commit ce53491 added shlex.quote to fix command injection via system_packages in Dockerfile templates and images.py, but the cloud deployment path in src/bentoml/_internal/cloud/deployment.py was left out. Line 1648 of that file joins system_packages values from bentofile.yaml into an apt-get install shell command with an f-string and no quoting. The generated setup.sh is uploaded to BentoCloud and run on the cloud build infrastructure, so a malicious bentofile.yaml can execute arbitrary commands there during deployment, including during Deployment.watch() dev-mode deployments.
LiteLLM's /config/update endpoint does not enforce admin role authorization, so any authenticated user can reach it. From there, an attacker can change proxy configuration and environment variables, register pass-through endpoint handlers that run attacker-controlled Python code (remote code execution), read arbitrary server files via UI_LOGO_PATH and /get_image, and take over privileged accounts by overwriting UI_USERNAME and UI_PASSWORD.
Fix: Fixed in v1.83.0. The endpoint now requires the proxy_admin role. Workaround: restrict API key distribution. There is no configuration-level workaround.
The Mesop framework's WebSocket handler, `handle_websocket` in `mesop/server/server.py`, starts a new `threading.Thread` for every parsed `ui_request` with no thread pool, message queue or rate limit. An unauthenticated attacker can send a rapid stream of messages over one connection to exhaust threads and memory, causing a denial of service for applications built on the framework.
Fix: Use a bounded thread pool (e.g., ThreadPoolExecutor with max_workers), introduce per-connection rate limiting, implement a message queue with backpressure, or consider migrating to an async event loop model instead of spawning OS threads.
OpenClaw's openclaw npm package, versions <=2026.3.24, lets an LLM agent silently disable exec approval through the config.patch function, bypassing user consent for command execution. Maintainers fixed it in commit 76411b2afc4ae721e36c12e0ea24fd23e2fed61e, shipped in v2026.3.28, and rate the issue high severity.
Fix: Fixed in v2026.3.28 (commit 76411b2afc4ae721e36c12e0ea24fd23e2fed61e); upgrade openclaw to >= 2026.3.28.
GitHub Advisory DatabaseCVE-2026-34524 affects SillyTavern versions prior to 1.17.0. A path traversal flaw in the chat endpoints lets an authenticated attacker read and delete arbitrary files under their user data root, such as secrets.json and settings.json, by supplying avatar_url="..". The weakness is classified as CWE-22.
Fix: Fixed in version 1.17.0.
NVD/CVE DatabaseCVE-2026-34522 affects SillyTavern, a locally installed user interface for text generation large language models, image generation engines, and text-to-speech voice models, prior to version 1.17.0. An authenticated attacker can inject traversal sequences into character_name in /api/chats/import to write attacker-controlled files outside the intended chats directory. The weakness is classified as CWE-22 and CWE-73.
Fix: This issue has been patched in version 1.17.0.
The ONNX save_external_data method in onnx/external_data_helper.py is reported to contain a local TOCTOU flaw, enabling arbitrary file read and write. Between os.path.isfile and open, the code creates no atomic file and does not use O_NOFOLLOW, so an attacker can swap in a symlink and overwrite victim files under the same privilege scope. A possible path validation bypass on Windows, using absolute paths such as C:\ with a single path part, is described but not verified by the reporter.
GHSA-44c2-3rw4-5gvh reports an SSRF flaw in FileTools.download_file() in praisonaiagents. The function checks the destination path but passes the caller-supplied url directly to httpx.stream() with follow_redirects=True, so an attacker who controls the URL can reach any host the server can access, including cloud metadata services and internal services. On EC2 instances with IMDSv1 enabled, IAM credentials can be retrieved and written to disk, and the flaw is reachable through indirect prompt injection without authentication.
Suggested fix: validate the url before the request by allowing only the http and https schemes and blocking loopback, link-local (169.254.0.0/16), and private RFC 1918 address ranges, as shown in the source's _validate_url() example.
In PraisonAI, `SubprocessSandbox` runs commands through `subprocess.run()` with `shell=True` and blocks dangerous commands only by string-pattern matching. The blocklist omits `sh` and `bash`, so in STRICT mode a call such as `sh -c 'id'` escapes the sandbox, and blocked commands like curl, wget, nc and ssh become reachable. Combined with agent prompt injection, an attacker could reach the network, filesystem and cloud metadata services. The source reports testing on praisonai==4.5.87.
The source suggests replacing `shell=True` with `shell=False` and passing `shlex.split(command)` to `subprocess.run()`. It does not state a fixed version.
The praisonai package's passthrough() and apassthrough() functions take a caller-controlled api_base parameter and concatenate it with endpoint, sending the request via httpx.Client.request() when the litellm primary path raises AttributeError. No scheme validation, private IP filtering or domain allowlist is applied, enabling server-side request forgery to any host reachable from the server. On EC2 with IMDSv1, the source says an attacker can retrieve IAM credentials, and internal services such as Redis, Elasticsearch and the Kubernetes API can be reached without authentication from within the VPC.
PraisonAI's `run_python()` in `praisonai` builds a shell command by placing user-controlled code inside `python3 -c "<code>"` and runs it with `subprocess.run(..., shell=True)`. Its escaping only handles `\` and `"`, so `$()` and backtick substitutions execute as OS commands before Python starts, enabling arbitrary command execution as the process user. The advisory notes the function is reachable through indirect prompt injection, and the auto-generated Flask server ships with `AUTH_ENABLED = False` when no token is configured.
The Model Context Protocol (MCP) Go SDK does not enable DNS rebinding protection by default for HTTP-based servers. A malicious website could use DNS rebinding to bypass same-origin restrictions and send requests to an HTTP-based MCP server running on localhost without authentication, using `StreamableHTTPHandler` or `SSEHandler`. This could let an attacker invoke tools or access resources on the user's behalf, and servers using stdio transport are not affected.
Fixed in 1.4.0: servers created via `StreamableHTTPHandler` or `SSEHandler` now have DNS rebinding protection enabled by default when binding to `localhost`. Users are advised to update to version 1.4.0.
Fix: Fixed in commit ce53491 for the Dockerfile templates and images.py paths only. The cloud deployment path in src/bentoml/_internal/cloud/deployment.py, line 1648, remained unfixed in the source text. N/A -- no mitigation discussed in source. for that path.