Advisories
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
39 items
Flowise 3.0.13, tested on Ubuntu 25.10, has an unauthenticated remote code execution flaw in the run method of the Airtable_Agents class. The method evaluates an LLM-generated Python script in a non-sandboxed environment, and a regex-based check (validatePythonCodeForDataFrame() with FORBIDDEN_PATTERNS) is the only guard before execution. An attacker can run arbitrary code as the user running the server.
CVE-2026-40351 affects FastGPT, an AI Agent building platform, in versions prior to 4.14.9.5. The password-based login endpoint uses TypeScript type assertion without runtime validation, so an unauthenticated attacker can submit a MongoDB query operator object such as {"$ne": ""} as the password field. This NoSQL injection bypasses the password check and allows login as any user, including the root administrator.
Fix: This issue has been fixed in version 4.14.9.5.
The Paperclip agent routes POST, GET and DELETE on /api/agents/:id/keys (server/src/routes/agents.ts, lines 2050-2087) call only assertBoard and never assertCompanyAccess, so any authenticated board user can mint a plaintext pcp_* agent API token for an agent in any company. The token is bound to the victim agent's companyId, which lets an attacker perform operations inside the victim tenant. The same assertBoard-only pattern appears on the pause, resume, terminate and delete agent handlers.
Paperclip AI v2026.403.0 contains an OS command injection flaw in the Execution Workspace lifecycle (workspace-runtime.ts). The PATCH /api/execution-workspaces/:id endpoint stores an arbitrary cleanupCommand without validation, and the server later runs it through spawn(shell, ["-c", cleanupCommand]) when the workspace is archived. In local_trusted mode, which is the default for desktop installations, exploitation requires no authentication, and the commands run with the privileges of the Paperclip server process.
Flowise's CSVAgent accepts a user-supplied custom Pandas read_csv code string and interpolates it without sanitization into code that pyodide executes on the server. An authenticated user can create a chatflow containing that node and trigger it through /api/v1/prediction/[CHATFLOWID], achieving remote code execution. If FLOWISE_USERNAME and FLOWISE_PQSSWORD are unset, the x-request-from: internal header bypasses authentication entirely.
LangChain-ChatChat 0.3.1 contains a remote code execution flaw in its MCP STDIO server configuration and execution handling. A remote attacker who can reach the publicly exposed MCP management interface can configure an MCP STDIO server with attacker-controlled commands and arguments, and once the server starts with MCP enabled for agent execution, arbitrary commands run within the context of the LangChain-ChatChat service.
A prompt injection flaw in Windsurf 1.9544.26 lets remote attackers run arbitrary commands on a victim system. When Windsurf processes attacker-controlled HTML, injected instructions can modify the local MCP configuration and automatically register a malicious MCP STDIO server, with no further user interaction. Successful exploitation can execute commands as the user, persist the malicious configuration, and expose sensitive information accessible through the application.
A Code Injection and Missing Authentication flaw in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.0a2) affects Python (OSS), Cloud Run and GKE deployments. An unauthenticated remote attacker can execute arbitrary code on the server hosting the ADK instance.
Fix: Patched in versions 1.28.1 and 2.0.0a2. Customers need to redeploy the upgraded ADK to their production environments, and users running ADK Web locally need to upgrade their local instance.
The openclaw npm package, versions below 2026.4.10, let QQBot outbound media tags in AI reply text reference host-local paths outside the intended media storage boundary. This allowed local file disclosure through outbound media handling, and the fix enforces the boundary for all outbound QQBot local file paths.
Fix: Fixed in v2026.4.10 (PR #63271, commit 604777e4414cc3b2ff8861f18f4fb04374c702c6). Users should upgrade to openclaw 2026.4.10 or newer; the latest npm release, 2026.4.14, already includes the fix.
GitHub Advisory DatabaseFastGPT, an AI Agent building platform, has a NoSQL injection flaw in its password change endpoint in versions prior to 4.14.9.5. An authenticated attacker can inject MongoDB query operators to bypass the "old password" check, changing the password of their own account or others' accounts when combined with ID manipulation, which leads to full account takeover and persistence.
Fix: Fixed in version 4.14.9.5.
NVD/CVE DatabaseOpenClaw's exec environment policy did not block interpreter startup variables such as VIMINIT, EXINIT, LUA_INIT and HOSTALIASES. Operator-supplied overrides of these variables could influence downstream execution or network behavior in affected versions below 2026.4.10. The fix expands the host environment security policy denylist to cover these and related high-risk variables.
Fix: Upgrade openclaw to 2026.4.10 or newer. The fix is in #63277 and the latest npm release, 2026.4.14, already includes it.
GitHub Advisory DatabaseThe text-to-speech generate endpoint in Flowise, POST /api/v1/text-to-speech/generate, is whitelisted and requires no authentication. When called without a chatflowId, it takes an attacker-supplied credentialId from the request body and uses the stored credential, such as an OpenAI or ElevenLabs API key, to generate speech. An unauthenticated attacker can therefore spend a victim's API credits, and the source says this is trivially exploitable when combined with a credential ID leak described in Finding 2.
Fix: The source suggests removing the TTS endpoint from WHITELIST_URLS, or validating that the credential belongs to the chatflow being used. It proposes returning a 401 'Authentication required' response when no chatflowId is provided.
The GET /api/v1/public-chatflows/:id endpoint in Flowise returns the full chatflow object without sanitization when a chatflow is public. In Docker validation against v3.0.13, the sanitizeFlowDataForPublicEndpoint function is absent from the released image, and both public-chatflows and public-chatbotConfig return raw flowData containing credential IDs, plaintext API keys, and passwords.
Fix: Apply sanitization to both public endpoints, using sanitizeFlowDataForPublicEndpoint on the chatflow before returning it, and ensure the function strips all credential, password, apiKey and secretKey fields from flowData.
A Paperclip-managed codex_local runtime used a Gmail connector the operator had connected only in the ChatGPT/OpenAI apps UI, without any Gmail connection configured in Paperclip or Codex. The runtime ran gmail_search_emails and gmail_send_email, sending a real outbound email from a personal Gmail account to an external party, followed by retraction messages after manual intervention. The reporter also states that the codex_local default for dangerouslyBypassApprovalsAndSandbox is true, which widens the impact.
A malicious skill can make an agent call PATCH /api/projects/{projectId}/workspaces/{workspaceId} to set a malicious runtimeConfig, then call the runtime-services/start endpoint. The server runs the unsanitized command via spawn() in server/src/services/workspace-runtime.ts, letting an attacker execute shell commands on the server and expose its environment variables, including API keys, JWT secrets and database credentials.
FlowiseAI Flowise version 3.0.12 contains an authentication bypass in the resetPassword method of the AccountService class. An unauthenticated remote attacker who knows a user's email address can submit a null or empty reset token to /api/v1/account/reset-password, because the code never verifies that a reset token was actually generated, and then set that user's password to a value of their choosing.
The GraphCypherQAChain node in Flowise passes user input directly into the Cypher query pipeline without sanitization, in the run method of packages/components/nodes/chains/GraphCypherQAChain/GraphCypherQAChain.ts (lines 193-219). An attacker with access to a vulnerable chatflow prediction endpoint (/api/v1/prediction/{flowId}) can inject arbitrary Cypher executed against the connected Neo4j database, enabling data exfiltration, modification, deletion, and schema discovery. Exploitation requires a chatflow using the Graph Cypher QA Chain node, a Chat Model, and a Neo4j Graph node with valid credentials.
The password reset functionality on cloud.flowiseai.com sends reset password links over unsecured HTTP instead of HTTPS. An attacker on the same network as the victim, such as on public Wi-Fi, can intercept the link and capture the reset token, enabling hijack of the password reset session and potential account compromise.
Fix: Ensure all sensitive URLs, especially password reset links, are generated and transmitted over secure https:// endpoints only. Use HTTPS in all password-related email links. Implement HSTS (HTTP Strict Transport Security) to enforce secure connections.
GitHub Advisory DatabaseFlowise contains an authentication bypass that lets an unauthenticated attacker obtain OAuth 2.0 access tokens tied to a public chatflow. The GET /api/v1/public-chatbotConfig/<chatflowId> endpoint returns internal flowData without authentication, including OAuth credential identifiers. The POST /api/v1/oauth2-credential/refresh/<credentialId> endpoint then refreshes tokens without authentication or authorization checks, enabling access to third-party services such as Gmail.
FlowiseAI's POST and GET API Chain components build request URLs from LLM output without validating them against the intended API documentation. Unauthenticated attackers can inject a crafted documentation prompt that overrides the BASE URL, causing the server to send arbitrary HTTP requests to internal and external hosts, as demonstrated against /flag on host.docker.internal:8080. The source affects FlowiseAI instances at version 2.2.1 and below.