Advisories
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
61 items
PraisonAI's browser bridge, started with `praisonai browser start`, binds to `0.0.0.0` by default, and its `/ws` endpoint accepts WebSocket clients that send no `Origin` header, because origin checks run only when that header is present. An unauthenticated network client can connect as a controller, send `start_session`, have the server forward `start_automation` to another idle extension WebSocket, and receive that session's action and status stream. The reporter verified this on praisonai version 4.5.134 at commit 365f75040f4e279736160f4b6bdb2bdb7a3968d4.
PraisonAIAgents, prior to 1.5.128, passes a user-controlled command string directly to subprocess.run() with shell=True in the memory hooks executor at src/praisonai-agents/praisonaiagents/memory/hooks.py, with no sanitization, so /bin/sh interprets shell metacharacters. Two attack surfaces exist: the pre_run_command and post_run_command hook event types, and the .praisonai/hooks.json lifecycle configuration, where BEFORE_TOOL and AFTER_TOOL hooks fire automatically. An agent that gains file-write access through prompt injection can overwrite hooks.json and run its payload silently at later lifecycle events.
PraisonAI's `execute_command` function, workflow shell steps (`_exec_shell` in `cli/features/job_workflow.py`) and action orchestrator pass user-controlled input to `subprocess.run()` with `shell=True`. Input from YAML workflow definitions, `agents.yaml` files, recipe steps and LLM-generated tool calls can therefore inject arbitrary shell commands through metacharacters such as `;`, `|`, `&&` and `$()`.
The `execute_code()` function in `praisonaiagents.tools.python_tools` defaults to `sandbox_mode="sandbox"`, which runs code in a subprocess with an AST blocklist. The subprocess wrapper's inline `blocked_attrs` set (line 143) omits `__traceback__`, `tb_frame`, `f_back` and `f_builtins`, which the direct-mode list blocks, letting attackers chain them through a caught exception to reach the wrapper's `builtins` and call `exec`. Tested on praisonaiagents 1.5.113 and rated CVSS 9.9 Critical.
Anthropic's Claude Code CLI and Claude Agent SDK run authentication helper configuration values through a shell (shell=true) without input validation. An attacker who can influence authentication settings, such as apiKeyHelper, awsAuthRefresh, awsCredentialExport, or gcpAuthRefresh, can inject shell metacharacters. This executes arbitrary commands with the privileges of the user or automation environment, enabling credential theft and environment variable exfiltration.
CVE-2026-35050 affects text-generation-webui before 4.1.1, a web interface for running Large Language Models. Users can save extension settings in "py" format to the app root directory, which lets them overwrite Python files such as "download-model.py". That file can then be executed from the "Model" menu when downloading a new model. The weakness is classified as CWE-22, Path Traversal.
Fix: Fixed in 4.1.1.
CVE-2026-6129 affects an unknown function of the Agent Mode Service in zhayujie chatgpt-on-wechat CowAgent, up to version 2.0.4. Missing authentication allows remote manipulation, and a public exploit is available. The project was informed through an issue report but had not responded at the time of publication.
CVE-2026-6126 is a weakness in zhayujie chatgpt-on-wechat CowAgent 2.0.4, in an unknown function of the Administrative HTTP Endpoint component. The flaw is missing authentication (CWE-287, CWE-306) and can be exploited remotely, and a public exploit is available. The project was informed through an issue report but had not responded at the time of publication.
Several HTTP transport endpoints in n8n-mcp lacked proper authentication, and its health check endpoint exposed sensitive operational metadata without credentials. An unauthenticated attacker with network access to the HTTP server could disrupt active MCP sessions and gather information useful for further attacks.
Fix: Fixed in v2.47.6. All MCP session endpoints now require Bearer authentication, and the health check endpoint has been reduced to a minimal liveness response. If upgrading is not immediately possible, restrict network access to the HTTP server with firewall rules, reverse proxy IP allowlists, or a VPN, or use stdio mode (MCP_MODE=stdio) instead of HTTP mode. Upgrading to v2.47.6 is still strongly recommended.
CVE-2026-40217 affects LiteLLM through 2026-04-08. The source says remote attackers can execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI. The weakness is classified as CWE-420 (Unprotected Alternate Channel), and NVD has not yet provided an assessment.
PraisonAIAgents, a multi-agent teams system, has a flaw in the web_crawl() function in praisonaiagents/tools/web_crawl_tools.py, affecting versions prior to 1.5.128. The function fetches arbitrary URLs supplied by AI agents without scheme allowlisting, hostname or IP blocklisting, or private network checks. An attacker, or prompt injection in crawled content, could force the agent to fetch cloud metadata endpoints, internal services, or local files via file:// URLs.
Fix: Fixed in 1.5.128.
CVE-2026-40116 affects PraisonAI, a multi-agent teams system, prior to 4.5.128. The /media-stream WebSocket endpoint in its call module accepts connections without authentication or Twilio signature validation, and each connection opens a session to OpenAI's Realtime API using the server's API key. With no limits on concurrent connections, message rate, or message size, an unauthenticated attacker can exhaust server resources and drain the victim's OpenAI API credits.
Fixed in 4.5.128.
PraisonAI, a multi-agent teams system, builds the gcloud run deploy --set-env-vars argument by directly interpolating openai_model, openai_key, and openai_base into a comma-delimited string without checking for commas. Because gcloud uses commas as the separator for key-value pairs, a comma in any of these values causes trailing text to be parsed as additional KEY=VALUE definitions, injecting arbitrary environment variables into the deployed Cloud Run service. The flaw is in deploy.py in versions prior to 4.5.128.
Fixed in 4.5.128.
CVE-2026-39981 affects AGiXT, an AI Agent Automation Platform, before version 1.9.2. The safe_join() function in the essential_abilities extension does not check that resolved file paths stay within the designated agent workspace. An authenticated attacker can use directory traversal sequences to read, write, or delete arbitrary files on the server hosting the AGiXT instance.
Fix: Fixed in 1.9.2.
NVD/CVE DatabaseOpenClaw's exec environment denylist omits HGRCPATH, CARGO_BUILD_RUSTC_WRAPPER, RUSTC_WRAPPER and MAKEFLAGS, so hostile build-tool environment variables can influence host exec commands. The advisory states this enables RCE and is scoped to OpenClaw's user-controlled local assistant trust model, not a multi-tenant service. Affected versions are openclaw (npm) before 2026.4.8.
Fix: Fixed in openclaw 2026.4.8 (patched npm version); the verified fixed tree is commit d7c3210cd6f5fdfdc1beff4c9541673e814354d5.
GHSA-4ggg-h7ph-26qr describes an authenticated SSRF in n8n-mcp affecting versions up to and including 2.47.3. A caller holding a valid AUTH_TOKEN can make the server request arbitrary URLs supplied through multi-tenant HTTP headers, and response bodies are returned through JSON-RPC. Cloud instance metadata endpoints and internal network services are readable, and single-tenant stdio and non-multi-tenant HTTP deployments are not affected.
Fix: Upgrade to n8n-mcp 2.47.4 or later. No configuration changes are required. Until upgrading, the advisory suggests egress filtering of RFC1918, link-local and other internal ranges, unsetting ENABLE_MULTI_TENANT and not accepting x-n8n-url / x-n8n-key headers at the reverse proxy, and restricting distribution of AUTH_TOKEN to fully trusted operators.
CVE-2026-34724 affects Zammad, a web based open source helpdesk and customer support system, before 7.0.1. A server-side template injection flaw in the AI Agent leads to RCE, and the impact is limited to environments where an attacker can control or influence type_enrichment_data, typically high-privilege administrative configuration. The issue is tracked as GHSA-fg9w-jg8f-4j94 and mapped to CWE-94 and CWE-1336, with a CVSS 4.0 base score of 8.7 (HIGH) from GitHub, while NVD had not yet provided an assessment.
Fixed in 7.0.1.
CVE-2026-3357 affects IBM Langflow Desktop versions 1.6.0 through 1.8.2. An authenticated user could execute arbitrary code on the system because an insecure default setting permits deserialization of untrusted data in the FAISS component. The weakness is classified as CWE-502, Deserialization of Untrusted Data.
LiteLLM stores user passwords as unsalted SHA-256 hashes and returns the password hash field from /user/info, /user/update and /spend/users to any authenticated user regardless of role. The /v2/login endpoint accepts the raw SHA-256 hash as a valid password, so an authenticated user can retrieve another user's hash and log in as that user, escalating privileges in three HTTP requests.
Fix: Fixed in v1.83.0. Passwords are now hashed with scrypt (random 16-byte salt, n=16384, r=8, p=1), password hashes are stripped from all API responses, and existing SHA-256 hashes are transparently migrated on next login.
The java-sdk MCP server contained a DNS rebinding vulnerability because it performed no Origin header validation before version 1.0.0, contrary to the MCP specification. An attacker can use a malicious website opened in a victim's browser to make arbitrary tool calls to a locally or privately networked MCP server, acting as a locally connected AI agent. Servers built on frameworks with built-in Origin validation, such as Spring AI, are not affected.
Fix: Fixed in 1.0.0 (Origin validation was absent prior to that release). Workarounds: run the MCP server behind a reverse proxy such as Nginx or HAProxy configured to strictly validate the Host and Origin headers, or use a framework that enforces strict CORS and Origin validation, such as Spring AI.
Fix: Fixed in 1.5.128.