Advisories
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
93 items
The task_create tool in DeepSeek TUI spawns durable sub-agents that default to allow_shell=true (config.rs:1499) and auto_approve=true (task_manager.rs:297). A user who approves a benign-looking task_create call therefore unknowingly grants the sub-agent unapproved shell access, which can follow attacker-controlled instructions in a cloned repository's AGENTS.md file and run commands without a further approval prompt. The reporter demonstrates remote code execution through a proof of concept that triggers a callback to a collaborator server.
Fix: Default allow_shell to false for durable tasks (config.rs:1499: self.allow_shell.unwrap_or(false)); default auto_approve to false for durable tasks (task_manager.rs:297: auto_approve: None, instead of Some(true)); and, when the model requests task_create with allow_shell=true, surface that in the approval prompt so the user knows they are granting shell access.
GitHub Advisory DatabaseThe run_tests tool in DeepSeek TUI executes cargo test with ApprovalRequirement::Auto, so it runs without a user approval prompt. Because cargo test compiles and executes test binaries, build.rs scripts and proc macros, a malicious repository can run arbitrary shell commands with no approval, and the source states AGENTS.md can instruct the model to call run_tests at session start.
Fix: Change run_tests to require approval, matching exec_shell: fn approval_requirement(&self) -> ApprovalRequirement { ApprovalRequirement::Required }
An authenticated user who can create or modify workflows can trigger global prototype pollution in n8n through an unvalidated pagination parameter in the HTTP Request node. Combined with other techniques, this can lead to RCE on the instance.
Fix: Fixed in n8n versions 1.123.43, 2.20.7, and 2.22.1. Upgrade to one of these versions or later. If upgrading is not immediately possible, limit workflow creation and editing permissions to fully trusted users only, and disable the HTTP Request node by adding `n8n-nodes-base.httpRequest` to the `NODES_EXCLUDE` environment variable. These workarounds do not fully remediate the risk and are short-term measures only.
CVE-2026-44484 affects PyTorch Lightning, a deep learning framework for pretraining and finetuning AI models. The description states that versions 2.6.2 and 2.6.2 introduced functionality consistent with a credential harvesting mechanism, and GitHub, Inc. maps the weakness to CWE-506, Embedded Malicious Code, with a CVSS 4.0 base score of 9.3 (Critical).
Flowise's POST /api/v1/node-custom-function endpoint has no route-level permission middleware, so any authenticated user or API key can submit arbitrary JavaScript to the Custom JS Function node. When E2B_APIKEY is unset, which the source describes as the common deployment case, the code runs in a NodeVM sandbox that can be escaped by abusing an Error object that crosses the sandbox boundary to recover the host Function constructor. The attacker then reaches process and child_process and runs system commands on the server host, a CVSS v3.1 score of 9.9 (Critical).
CVE-2026-42048 affects Langflow versions prior to 1.9.0 in the Knowledge Bases API (DELETE /api/v1/knowledge_bases). User-supplied knowledge base names are concatenated directly into file paths without sanitization or boundary validation. An authenticated attacker can delete arbitrary directories on the server's filesystem, causing data loss and potential service disruption.
Fix: Fixed in 1.9.0.
NVD/CVE DatabaseCVE-2026-31238 affects the Ludwig framework through version 0.10.4, in its model serving component (CWE-502). When a model server starts with the ludwig serve command, the framework loads model weight files with torch.load() without setting weights_only=True, so arbitrary Python objects can be deserialized via the pickle module. An attacker who supplies a maliciously crafted PyTorch model file can achieve arbitrary code execution on the host running the Ludwig model server.
CVE-2026-43992 affects JunoClaw, an agentic AI platform built on Juno Network, prior to 0.x.y-security-1. Every MCP write tool, including send_tokens, execute_contract, instantiate_contract, upload_wasm and ibc_transfer, accepted 'mnemonic: string' as an explicit tool-call parameter. As a result, the BIP-39 seed was embedded in the LLM tool-call JSON and exposed to any transport, log or telemetry surface between the LLM provider and the MCP process.
GHSA-m77w-p5jj-xmhg reports that OpenClaude's BashTool input schema exposes `dangerouslyDisableSandbox` to the model, which the project's own threat model treats as an untrusted principal. In `shouldUseSandbox()` in `src/tools/BashTool/shouldUseSandbox.ts`, that flag skips the sandbox when `areUnsandboxedCommandsAllowed()` returns true, and that check defaults to true in `src/utils/sandbox/sandbox-adapter.ts`. A prompt-injected model can therefore set the flag in a `tool_use` block and run arbitrary host commands under default configuration.
CVE-2026-31228 affects the Adversarial Robustness Toolbox (ART) through 1.20.1, in its Kubeflow component. The robustness evaluation function for PyTorch models passes user-supplied strings for the LossFn and Optimizer parameters to eval() without sanitization, so an attacker can supply a crafted string containing arbitrary Python code. That code runs when eval() is called, giving the attacker full control of the system running the ART evaluation.
CVE-2026-31223 affects the snorkel library through v0.10.0 and is classified as CWE-502, insecure deserialization. The BaseLabeler.load() method passes user-supplied file paths to pickle.load() with no validation or security controls. A remote attacker who supplies a maliciously crafted pickle file can achieve arbitrary code execution when the file is loaded through this method.
CVE-2026-43899 affects DeepChat, an open-source AI agent platform, prior to v1.0.4-beta.1. An incomplete fix for CVE-2025-55733 left native Electron pop-up window handlers unsanitized, so a malicious Markdown link with target="_blank" can route a URL through tabPresenter.ts directly to shell.openExternal(url), bypassing the isValidExternalUrl check. A compromised AI endpoint or attacker can trigger this, enabling arbitrary protocol execution.
Fix: Fixed in v1.0.4-beta.1.
CVE-2026-42869 affects SOCFortress CoPilot before 0.1.57. The backend ships a hardcoded JWT signing secret as a fallback in backend/app/auth/utils.py:28 and repeats it in .env.example. Deployments that leave JWT_SECRET unset, including the default Docker Compose setup, sign every authentication token with this public value, letting an unauthenticated attacker forge admin-scoped JWTs and take full control of the application and the security tools it manages.
Fixed in 0.1.57.
A vulnerability in fishaudio Bert-VITS2 up to commit 8f7fbd8c4770965225d258db548da27dc8dd934c affects the generate_config function in webui_preprocess.py, part of the Gradio Interface component. Manipulating the data_dir argument leads to path traversal, and the attack can be launched remotely. The exploit is public and may be used, and the vendor did not respond after early contact.
CVE-2026-45401 affects Open WebUI versions prior to 0.9.5. The validate_url() function in backend/open_webui/retrieval/web/utils.py checks only the initial URL, and the downstream HTTP clients follow 3xx redirects without re-validating the target against the private-IP and metadata-IP block list. Any authenticated user can submit a public URL that redirects to an internal address and read the internal response body through /api/v1/retrieval/process/web and other routes that call these helpers.
Fixed in 0.9.5.
Open WebUI versions prior to 0.9.0 expose the /responses endpoint in the OpenAI router, which accepts any authenticated user. The endpoint forwards requests straight to upstream LLM providers without the model ownership, group membership and AccessGrants checks that generate_chat_completion enforces. Any authenticated user can therefore use any configured model by POSTing an arbitrary model ID to /api/openai/responses.
Fix: Fixed in 0.9.0.
GHSA-rpj4-7x2v-wjrf (CWE-918) affects Budibase. The processUrlFile function in packages/server/src/automations/steps/ai/extract.ts calls fetch(fileUrl) directly, skipping the IP blacklist validation that other automation steps apply through fetchWithBlacklist. An authenticated builder user can therefore make the server request internal addresses such as 169.254.169.254, which may expose cloud metadata credentials and internal services.
Fix: The source text is cut off mid-sentence at "Replace" under Proposed Fix and does not state a concrete fix, so: N/A -- no mitigation discussed in source.
From 0.5.4 to 0.12.4, two primitive integrators in apm-cli enumerate package files with Path.glob() and Path.rglob() and read matches with Path.read_text(), following symbolic links transparently. A symlink committed inside a remote APM dependency under .apm/prompts/ or .apm/agents/ is preserved into apm_modules/ on clone, then dereferenced during integration, and the resolved content is written as a regular file into the project's deploy directories. The package content_hash, the pre-deploy SecurityGate scan, and apm audit do not flag this.
Fixed in 0.13.0.
Microsoft APM, an open-source dependency manager for AI agents, is affected prior to 0.8.12. When it normalizes marketplace plugins, it copies components referenced in plugin.json into .apm/ without checking that the attacker-controlled agents, skills, commands, and hooks paths stay inside the plugin directory. A malicious plugin can use absolute or ../ traversal paths to copy arbitrary readable files or directories from the installer's machine during apm install.
Pipecat's development runner, started with the --folder flag, exposes a GET /files/{filename:path} endpoint in src/pipecat/runner/run.py that joins the filename directly onto args.folder without a containment check. Starlette decodes %2F after routing, so a request such as ..%2F..%2Fetc%2Fpasswd escapes the folder, and the endpoint has no authentication. The advisory confirms this on pipecat-ai 1.1.0 and commit f078df78058ae82a02ce5b23e9e3a99a0917a53d.
Fix: This vulnerability is fixed in 0.x.y-security-1.
NVD/CVE DatabaseFix: Fixed in 0.8.12.
NVD/CVE Database