Advisories
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
50 items
FastGPT, an AI Agent building platform, has an unauthenticated Remote Code Execution flaw in its agent-sandbox component from version 4.14.10 to before 4.14.13. The startup script entrypoint.sh runs code-server with the --auth none flag and binds it to 0.0.0.0:8080, so any user with network access to that port can bypass authentication and gain full control of the sandbox environment.
Fix: Fixed in 4.14.13.
NVD/CVE DatabaseThe kanban npm package, used by the cline CLI, runs a WebSocket server on 127.0.0.1:3484 that does not validate the Origin header on its upgrade requests. Any website a developer visits can connect to the runtime, terminal I/O and control endpoints, leaking workspace paths, task details and agent chat messages. A page can also write input into a running agent's terminal, which the source says leads to remote code execution, or stop active agent sessions. Tested against version 0.1.59.
LiteLLM versions from 1.74.2 up to, but not including, 1.83.7 expose two endpoints, POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list, that accept a full MCP server configuration including the stdio transport's command, args and env fields. Any holder of a valid proxy API key, including low-privilege internal-user keys, can make these endpoints spawn an arbitrary command as a subprocess on the proxy host with the proxy process's privileges, because no role check gates them.
LiteLLM, a proxy server (AI Gateway) for calling LLM APIs, is affected by CVE-2026-42208 in versions 1.81.16 through before 1.83.7. During proxy API key checks, a database query mixed the caller-supplied key value into the query text instead of passing it as a separate parameter. An unauthenticated attacker can send a crafted Authorization header to any LLM API route, such as POST /chat/completions, and reach the query through the error-handling path, potentially reading or modifying proxy database data and gaining unauthorised access to managed credentials.
LiteLLM, an AI gateway proxy that calls LLM APIs in OpenAI or native format, is affected from version 1.80.5 up to but not including 1.83.7. The POST /prompts/test endpoint rendered user-supplied prompt templates without sandboxing, so a crafted template could run arbitrary code inside the LiteLLM Proxy process. Any caller holding a valid proxy API key can reach the endpoint, and depending on deployment this may expose environment secrets such as provider API keys or database credentials and allow commands on the host.
Fixed in 1.83.7.
AxonFlow's GHSA-9h64-2846-7x7f advisory consolidates eight bug fixes in the v7.1.3 to v7.5.0 window, closing multi-tenant isolation, access-control and policy-enforcement defects. Affected versions are below 7.5.0, with individual items affecting different earlier minors. A body-supplied org_id could override the authenticated org, letting one tenant's requests be recorded in another tenant's audit log and evaluated under the wrong policy set.
Fix: Upgrade to AxonFlow platform v7.5.0 or later. No configuration changes are required. For users who cannot upgrade immediately, the source gives item-specific mitigations: for items 1-5, ensure the agent middleware sets X-Org-ID / X-Tenant-ID from authenticated identity at the ingress and never accepts body-supplied identity; for item 8 (Community SaaS), set SQLI_ACTION=block explicitly via the agent task definition, which v7.5.0 makes the default.
SQLBot, a Text-to-SQL system built on large language models and RAG, is affected in versions 1.7.0 and earlier. Its Text2SQL chat interface concatenates the user-provided question directly into the LLM prompt without filtering, and executes the SQL extracted from the LLM response without validation. An authenticated attacker can craft a malicious question to make the LLM generate and run arbitrary SQL, which, when connected to a PostgreSQL data source, can lead to remote code execution via COPY FROM PROGRAM.
CVE-2026-42076 affects Evolver, a GEP-powered self-evolving engine for AI agents, prior to version 1.69.3. A command injection flaw in the _extractLLM() function builds a curl command by string concatenation and passes it to execSync() without sanitization. When the corpus parameter contains shell metacharacters, an attacker can execute arbitrary shell commands on the server, classified as CWE-78.
Fix: This issue has been patched in version 1.69.3.
CVE-2026-7482 affects Ollama before 0.17.1. A heap out-of-bounds read in the GGUF model loader lets an attacker send a crafted GGUF file to the /api/create endpoint, where declared tensor offset and size exceed the file's real length. During quantization in fs/ggml/gguf.go and server/quantization.go (WriteTo()), the server reads past the allocated heap buffer, and the leaked memory may include environment variables, API keys, system prompts and other users' conversation data. The attacker can exfiltrate it by pushing the resulting model artifact through /api/push to an attacker-controlled registry, and neither endpoint requires authentication in the upstream distribution.
CVE-2026-41705 affects Spring AI's MilvusVectorStore#doDelete(List) implementation, which is vulnerable to filter-expression injection through unsanitized document IDs. It is classified under CWE-917, Improper Neutralization of Special Elements used in an Expression Language Statement. NVD published the entry on 05/08/2026, and NVD has not yet provided an assessment.
Fix: Spring AI 1.0.x: upgrade to 1.0.7 or greater. Spring AI 1.1.x: upgrade to 1.1.6 or greater.
CVE-2026-44286 affects FastGPT, an AI Agent building platform, prior to version 4.14.17. An unauthenticated attacker, or an authenticated user with App editing privileges, can make the fetchData function in the lafModule workflow node send arbitrary HTTP requests to internal or private network addresses. The function uses axios on user-controlled URLs without checking them against the isInternalAddress blocklist guard.
Fix: Fixed in 4.14.17.
FastGPT versions 4.14.11 and prior are affected by CVE-2026-42345. The isInternalAddress() function in packages/service/common/system/utils.ts blocks cloud metadata endpoints with a fullUrl.startsWith() check against a hardcoded list, which at least 7 URL encoding techniques bypass to reach the same metadata service. The broader private IP check is disabled by default because CHECK_INTERNAL_IP defaults to false.
CVE-2026-42339 affects New API, an LLM gateway and AI asset management system, in versions 0.11.9-alpha.1 and prior. The SSRF protection added in v0.9.0.5 (CVE-2025-59146) and hardened in v0.9.6 (CVE-2025-62155) fails to block the unspecified address 0.0.0.0, so any valid non-admin API token can send a multimodal request to /v1/chat/completions, /v1/responses, or /v1/messages with 0.0.0.0 as the image or file URL host, making the server issue requests to localhost. The flaw is at minimum a blind SSRF, and through an AWS/Bedrock Claude adaptor the fetched content is inlined into the model response, making it a full-read SSRF.
LangChain's older runtime code paths deserialize run inputs, run outputs, and other application-controlled payloads using overly broad allowlists, sometimes calling `load()` with `allowed_objects="all"`. Attacker-supplied LangChain serialized constructor dictionaries can therefore cause trusted classes to be instantiated with untrusted constructor arguments, when the application accepts untrusted structured input and preserves it in run data. A related `_is_lc_secret` validation bypass in the serialization layer provides an additional path to the same revival logic.
Open WebUI version 0.1.105 has an improper authorization flaw (CWE-285) in which accounts with the pending role can make authenticated API calls as a user. The role check is enforced only at the client presentation layer, while the API does not validate that the user holds the user role. A pending user who signs up through POST /api/v1/auths/signup receives a valid JWT and can call the authenticated GET /ollama/api/tags endpoint to list available models.
banks versions up to and including 2.4.1 render prompt templates with an unsandboxed jinja2.Environment() in src/banks/env.py. Applications that pass user-supplied strings as the template argument to Prompt() are exposed to Server-Side Template Injection, which can lead to Remote Code Execution on the host.
Fix: Fixed in banks 2.4.2 (PR #74), which switches to jinja2.sandbox.SandboxedEnvironment. Developers on banks <= 2.4.1 should upgrade to 2.4.2 and avoid passing untrusted user input as the template argument to Prompt().
n8n-mcp versions before 2.50.1 contain three independently reported issues in deployments that use the n8n API integration. An authenticated MCP caller can supply crafted identifiers that the n8n API client uses as URL path segments, sending the configured n8n API key to other same-origin endpoints and bypassing handler-level controls including DISABLED_TOOLS. Validated webhook, form and chat trigger URLs also follow redirects, returning the response body to the caller, and default opt-in telemetry uploads unredacted operation payloads that can contain bearer tokens, API keys and webhook secrets. CVSS 8.3 (HIGH); exploitation requires an authenticated MCP caller and a configured n8n API key.
Authenticated server-side request forgery in n8n-mcp affects the webhook trigger tools, the n8n API client via N8N_API_URL, and per-request URLs supplied in the x-n8n-url header in multi-tenant HTTP mode. A caller with an MCP session can make the n8n-mcp host send requests to internal services and cloud metadata endpoints, and the response body is returned to the caller. Fixed in n8n-mcp@2.50.2.
Langfuse versions from 3.68.0 up to, but not including, 3.167.0 contain a role-based access control flaw in the LLM connection update flow. An authenticated user with the "member" role in a project can point an existing LLM connection at an attacker-controlled baseUrl, causing Langfuse to reuse the stored provider secret and send the test request to that endpoint, which could expose the plaintext provider LLM API key. The attack requires that the user already belongs to the project with "member" scoped access.
PromptHub, from version 0.4.9 before 0.5.4, has an SSRF flaw in the authenticated POST /api/skills/fetch-remote endpoint in apps/web/src/routes/skills.ts. The private-address check in isPrivateIPv6 in apps/web/src/utils/remote-http.ts can be bypassed with alternate IPv6 representations, letting any authenticated user reach IPv4 loopback, RFC1918 and link-local addresses and read up to 5 MB of the response. On deployments with ALLOW_REGISTRATION=true, any internet user who can register can exploit it.
Fix: Fixed in 1.83.7.
NVD/CVE DatabaseFix: Fixed in 1.83.7.
NVD/CVE DatabaseFix: Fixed in 1.7.1.
NVD/CVE DatabaseFix: LangChain will deprecate `RunnableWithMessageHistory`, `astream_log()` and `astream_events(version="v1")`, and applications should migrate to the currently recommended APIs, including the `stream` API. LangChain will also update `load()` and `loads()` to tighten deserialization so broad object revival is not applied implicitly to untrusted or application-controlled payloads.
Fix: Upgrade to n8n-mcp >= 2.50.1. Workarounds: for the first two issues, restrict network access to the HTTP transport (firewall, reverse-proxy ACL or VPN) or switch to stdio mode; for the telemetry issue, set N8N_MCP_TELEMETRY_DISABLED=true before starting the server or run `npx n8n-mcp telemetry disable` once.
Fix: Fixed in `n8n-mcp@2.50.2`. Operators whose N8N_API_URL points at localhost or a private address should set WEBHOOK_SECURITY_MODE to moderate (allows localhost, still blocks RFC1918 and cloud metadata) or permissive (also allows RFC1918, only safe on a trusted private network); the default strict applies where n8n is on a public hostname. Workarounds for deployments that cannot upgrade: restrict network egress from the host and deny cloud metadata IPs (169.254.169.254, 169.254.170.2, 100.100.100.200, 192.0.0.192, and the GCP metadata.google.internal resolved IP) and RFC1918 networks; run in stdio mode instead of HTTP; or set DISABLED_TOOLS=n8n_trigger_webhook_workflow,n8n_create_workflow,n8n_test_workflow.
GitHub Advisory DatabaseFix: This issue has been patched in version 3.167.0.
NVD/CVE DatabaseFix: Fixed in 0.5.4.
NVD/CVE Database