Advisories
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
52 items
Gemini CLI (`@google/gemini-cli`) and the `run-gemini-cli` GitHub Action are updated to harden workspace trust and tool allowlisting, especially in untrusted environments such as GitHub Actions. In headless mode, earlier versions automatically trusted workspace folders, so malicious environment variables in a local `.gemini/` directory could lead to remote code execution, and under `--yolo` the fine-grained tool allowlist in `~/.gemini/settings.json` was ignored. The update requires explicit folder trust and makes the policy engine evaluate tool allowlisting under `--yolo` (version `0.39.1`), which can break existing CI/CD workflows.
Fix: The folder trust and tool allowlisting mitigations are available in `@google/gemini-cli` version `0.39.1` and `0.40.0-preview.3`. Users must review their workflows and take one of two approaches: 1. If the workflow runs on trusted inputs, set `GEMINI_TRUST_WORKSPACE: 'true'` in the workflow. 2. If the workflow runs on untrusted inputs, review the guidance in google-github-actions/run-gemini-cli to harden the workflow against malicious content, and set the environment variable. If the workflow specifies a version via `gemini_cli_version`, upgrade to one of the patched versions and audit the workflow settings that use Gemini CLI.
GitHub Advisory DatabaseLiteLLM's proxy API key verification mixed the caller-supplied key value into a database query instead of passing it as a separate parameter, enabling SQL injection. An unauthenticated attacker can send a crafted Authorization header to any LLM API route, such as POST /chat/completions, and reach the query through the proxy's error-handling path. The attacker can read proxy database data and may modify it, gaining unauthorised access to the proxy and the credentials it manages.
Fix: Fixed in 1.83.7. The caller-supplied value is now always passed to the database as a separate parameter. Upgrade to 1.83.7 or later. If upgrading is not immediately possible, set disable_error_logs: true under general_settings, which removes the path through which unauthenticated input reaches the vulnerable query.
CVE-2026-41274 affects Flowise, a drag and drop user interface for building customized large language model flows, prior to 3.1.0. The GraphCypherQAChain node passes user-provided input directly into the Cypher query execution pipeline without proper sanitization, letting an attacker inject arbitrary Cypher commands that run against the underlying Neo4j database. The flaw enables data exfiltration, modification, or deletion, and GitHub rates it CRITICAL with CVSS 4.0 base score 9.3, while NIST has not yet provided an assessment.
Fixed in 3.1.0.
CVE-2026-33102 is an open redirect (CWE-601) in M365 Copilot, a hosted service. The flaw is a URL redirection to an untrusted site, which allows an unauthorized attacker to elevate privileges over a network. NVD has not yet provided an assessment; Microsoft Corporation is the source, and NVD published the entry on 04/23/2026.
A critical flaw in Pipecat's LivekitFrameSerializer, an optional, non-default, undocumented serializer deprecated in version 0.0.90, passes untrusted WebSocket message data directly to pickle.loads() in deserialize() in src/pipecat/serializers/livekit.py. A remote client that can reach a server using this serializer, for example one bound to 0.0.0.0, can send a crafted pickle payload to execute arbitrary code on the server with the Pipecat service's privileges.
CVE-2026-41276 affects Flowise versions prior to 3.1.0, a drag-and-drop interface for building customized large language model flows. Remote attackers can bypass authentication without credentials by sending a null or empty reset token to the /api/v1/account/reset-password endpoint, provided they know the victim's email address. The resetPassword method of the AccountService class fails to verify that a reset token was actually generated, letting the attacker set the user's password to any value.
This vulnerability is fixed in 3.1.0.
CVE-2026-41268 affects Flowise, a drag-and-drop interface for building customized LLM flows, prior to 3.1.0. A parameter override bypass using the FILE-STORAGE:: keyword, combined with NODE_OPTIONS environment variable injection, lets an unauthenticated attacker run arbitrary system commands with root privileges inside the containerized Flowise instance. Exploitation needs only a single HTTP request and no prior knowledge of the instance.
Fix: Fixed in 3.1.0.
CVE-2026-41265 affects Flowise versions prior to 3.1.0. The flaw sits in the run method of the Airtable_Agents class, which evaluates an LLM-generated Python script without proper sandboxing. An unauthenticated attacker who can send prompts to a chatflow using the Airtable Agent node can use prompt injection to make the LLM return a malicious script, which then runs attacker-controlled commands on the Flowise server.
Fix: Fixed in 3.1.0.
CVE-2026-41138 affects Flowise, a drag and drop interface for building customized large language model flows, prior to 3.1.0. The flaw lies in AirtableAgent.ts, where user input is applied directly to the question parameter in the prompt template and passed to Python code using Pandas without sanitization, allowing remote code execution. The weakness is classified as CWE-94, Improper Control of Generation of Code.
Fix: This vulnerability is fixed in 3.1.0.
CVE-2026-41137 affects Flowise, a drag and drop user interface for building customized large language model flows, prior to 3.1.0. The CSVAgent accepts a custom Pandas CSV read code without sanitization, so an attacker can supply a command injection payload that the server interpolates and executes. The issue is rated CRITICAL (CVSS-B 9.4, CVSS:4.0 vector with low privileges required and no user interaction), and is tracked as CWE-94.
Paperclip, a Node.js server and React UI for orchestrating AI agents, is affected by CVE-2026-41679 in versions prior to 2026.416.0. An unauthenticated attacker can achieve full remote code execution on any network-accessible instance running in `authenticated` mode with default configuration, using a six-call API chain requiring no credentials or user interaction.
Fix: Version 2026.416.0 patches the issue.
CVE-2026-39987 is a pre-authorization remote code execution vulnerability in Marimo. An unauthenticated attacker can gain shell access and execute arbitrary system commands. The vulnerability is actively exploited in the wild, per CISA KEV.
Flowise versions prior to 3.1.0 contain a flaw in the MCP adapter's serialization of stdio commands. An authenticated user can add an MCP stdio server through the "Custom MCP" configuration with an arbitrary command, bypassing validateCommandInjection and validateArgsForLocalFileAccess by pairing an allowed command such as "npx" with code execution arguments like "-c touch /tmp/pwn", which achieves command execution on the underlying OS.
Fix: Fixed in 3.1.0.
Trend Micro's Zero Day Initiative reports an unauthenticated remote code execution flaw in FlowiseAI Flowise, tested at version 3.0.13. The flaw sits in the run method of the CSV_Agents class, which evaluates an LLM-generated Python script without proper sandboxing. The input validation that checks for forbidden patterns can be bypassed, allowing arbitrary OS commands to run on the server as the user running it.
A weakness in Toowiredd chatgpt-mcp-server up to 0.1.0 allows OS command injection through an unknown function in src/services/docker.service.ts, affecting the MCP/HTTP component. The issue is remotely exploitable, and a public exploit is available, while the project has not yet responded to the early issue report. VulDB rates it CVSS 4.0 6.9 (MEDIUM); NIST has not yet provided an assessment.
LiteLLM's two MCP preview endpoints, POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list, accepted full server configurations including command, args and env for the stdio transport. Calling them with a stdio configuration spawned the supplied command as a subprocess on the proxy host with the proxy process's privileges. Because the endpoints checked only for a valid proxy API key and no role, any authenticated user, including low-privilege internal-user keys, could run arbitrary commands on the host.
Fix: Fixed in 1.83.7. Both test endpoints now require the PROXY_ADMIN role. If upgrading is not immediately possible, block POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list at the reverse proxy or API gateway.
k8sGPT's auto-remediation pipeline deserializes AI-generated YAML directly into a Deployment object in `object_to_execution.go`, without validating it against the original Deployment object. The issue was fixed after coordination with Alex Jones, and the proof of concept was shared only with the maintainers.
Claude Code used the git worktree `commondir` file to determine folder trust without validating its contents. A crafted repository whose `commondir` points to a path the victim had already trusted could bypass the trust dialog and run malicious hooks defined in `.claude/settings.json`. Exploitation required the victim to clone the malicious repository, run Claude Code inside it, and the attacker to know or guess a previously trusted path.
Fix: Users on standard Claude Code auto-update have already received the fix. Users performing manual updates are advised to update to the latest version.
Ray Data registers three custom Arrow extension types (ray.data.arrow_tensor, ray.data.arrow_tensor_v2, ray.data.arrow_variable_shaped_tensor) globally in PyArrow. When PyArrow reads a Parquet file with one of these types, Ray's __arrow_ext_deserialize__ passes the field metadata bytes to cloudpickle.loads(), enabling arbitrary code execution during schema parsing, before any row data is read. The source states that a related fix from May 2024 was reintroduced in July 2025 via PR #54831.
LiteLLM's POST /prompts/test endpoint rendered user-supplied prompt templates without sandboxing, so a crafted template could run arbitrary code inside the LiteLLM Proxy process. Any caller with a valid proxy API key can reach the endpoint, which may expose environment secrets and allow host commands depending on deployment.
Fix: Fixed in 1.83.7-stable, which switches the prompt template renderer to a sandboxed environment. LiteLLM recommends upgrading to 1.83.7-stable or later. If upgrading is not immediately possible, block POST /prompts/test at your reverse proxy or API gateway, and review and rotate API keys that should not have access to prompt management routes.
Fix: Fixed in 3.1.0.
NVD/CVE DatabaseFix: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Due date: 2026-05-07.
CISA Known Exploited Vulnerabilities