Advisories
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
68 items
All components built on BaseFileComponent in Langflow are vulnerable, including the Read File node, which processes user-controlled files. A crafted tar archive containing a symlink, extracted in _unpack_bundle, lets an attacker read any file by absolute path, such as Langflow's secret_key used to sign JWTs. With that key an attacker can forge tokens for any user and execute code through a Python Interpreter node. Any user ingesting untrusted data with these components is affected, and the code execution risk depends on the scenario.
Fix: Fixed in 1.9.2 via PR #12945. BaseFileComponent._unpack_bundle now rejects symlink and hardlink members and any non-regular entries during TAR extraction, with additional symlink filtering during directory recursion and after extraction. Upgrade to 1.9.2 or later.
GitHub Advisory DatabaseGHSA-qrpv-q767-xqq2 is an insecure direct object reference (IDOR) in Langflow's `/api/v1/responses` endpoint. The helper `get_flow_by_id_or_endpoint_name` in `src/backend/base/langflow/helpers/flow.py` looks up flows by UUID without checking ownership, so any authenticated user can execute another user's flow by supplying its flow ID. The source says attackers can run any flow, access data its processing handles, and consume the victim's resources.
Network-AI's agent sandbox checks shell commands against an allowlist by glob-matching the whole command string, but ShellExecutor passes that string to /bin/sh -c. A wildcard allow such as git * therefore also matches git status; id, so any agent with a single wildcard allow can run arbitrary commands as the orchestrator process. A proof of concept against network-ai@5.8.5 confirmed the injected id command ran.
Fix: Fixed in v5.9.1 (commit 379f776): ShellExecutor now runs commands via spawn(file, args, { shell: false }) using a quote-aware parsed argv, and SandboxPolicy.isCommandAllowed and the new SandboxPolicy.tokenizeCommand reject unquoted shell metacharacters and unterminated quotes before the allowlist glob match.
The fix for CVE-2026-46701 in Network-AI, npm package network-ai, is incomplete on the latest v5.7.1. The 5.4.5 release restricted Access-Control-Allow-Origin to localhost origins, but the SSE MCP server still defaults to an empty secret, and _isAuthorized() returns true when the secret is empty. Any non-browser caller can therefore invoke all 22 MCP tools without credentials, including config_set, agent_spawn, blackboard_write and token_* tools.
Implement the advisory's remediation #1: refuse to start SSE mode with an empty secret (unless --stdio), and/or make _isAuthorized fail closed so an empty configured secret denies requests. The CORS allowlist alone does not authenticate non-browser callers.
The `multiedit` tool in PraisonAI (`src/praisonai/praisonai/tools/multiedit.py`) passes the `filepath` parameter directly to `open()` for reads and writes, with no path traversal check, workspace boundary validation, protected path guard or symlink resolution. An attacker who can influence agent tool arguments, through crafted prompts, chat bot input or malicious YAML workflow configs, can read sensitive files and overwrite arbitrary files the process user can access. The advisory's proof of concept confirmed an arbitrary file write to a file outside the workspace.
Langflow's deprecated POST /api/v1/upload/{flow_id} endpoint in langflow/api/v1/endpoints.py had no authentication and no validation of flow_id, so unauthenticated users with network access could upload unlimited data. The upload wrote to local disk, enabling space exhaustion and denial of service, and the response disclosed the absolute server path of the uploaded file, an information leak. The issue was tested on commit 2d67402b1dbaefcbce85a244d4a6cd5e4bda1cfe.
Fixed in 1.9.1 via PR #12831. The endpoint now uses the get_flow dependency, requiring an authenticated user and flow ownership, and enforces the max_file_size_upload limit (HTTP 413). Upgrade to 1.9.1 or later. The response still returns file_path, but only to the authenticated flow owner.
A Host-header parsing flaw in the LiteLLM proxy could let unauthenticated callers reach protected management routes. The auth layer derived the route from request.url.path, which Starlette rebuilds from the Host header, so a crafted Host made the gate check a different route than the one FastAPI dispatched. Most deployments are not affected, since upstream CDNs, WAFs, reverse proxies or load balancers that validate Host block the bypass, and LiteLLM Cloud customers are not affected.
Fixed in 1.84.0. Upgrade to 1.84.0 or later; no configuration change is required. If upgrading is not immediately possible, place the proxy behind an upstream component that validates or normalizes the Host header (a CDN/WAF, a reverse proxy with explicit server_name allowlists, or a cloud load balancer with host-based routing rules), or otherwise restrict network access to the proxy listener.
GHSA-365w-hqf6-vxfg describes multiple security vulnerabilities in the Crawl4AI Docker API server, affecting crawling, markdown/LLM extraction, screenshot, PDF, webhook, monitoring, JavaScript execution and configuration endpoints. The flaws include arbitrary file write via output_path on /screenshot and /pdf, SSRF through webhook URLs and direct crawl endpoints, an authentication bypass on monitor endpoints, stored XSS in the monitor dashboard, arbitrary JavaScript execution via /execute_js, and a hardcoded JWT secret defaulting to "mysecret".
Fix: Upgrade to the patched version (recommended). Other workarounds: set CRAWL4AI_API_TOKEN to enable authentication, set a strong SECRET_KEY (min 32 chars) if using JWT, and restrict network access to the Docker API. Per-issue fixes include validate_output_path() restricting writes to CRAWL4AI_OUTPUT_DIR, validate_webhook_url() blocking private and metadata addresses, token_dep on the monitor router, disabling /execute_js by default via CRAWL4AI_EXECUTE_JS_ENABLED, removing the default JWT key, and normalizing IPv6-mapped IPv4 addresses before the blocklist check.
GHSA-94f4-hr76-p5j6 is a vulnerability in vLLM's OpenAI-compatible API server that allows authentication bypass of the AuthenticationMiddleware. The flaw stems from starlette reconstructing the URL from an unfiltered Host header on ASGI servers such as uvicorn, letting an attacker control url.path and reach /v1 endpoints without the configured VLLM_API_KEY or --api-key. Instances behind an RFC-conforming web server such as nginx are not affected.
Langflow's Shareable Playground, also called Public Flows in the code, contains a critical remote code execution flaw. The route /api/v1/build_public_tmp executes any public flow given its flow ID, and the data.nodes[X].data.node.template.code.value field accepts arbitrary Python code from the JSON payload. The source states the impact as unauthenticated RCE on any deployment with a shareable playground, and tested on commit 2d67402b1dbaefcbce85a244d4a6cd5e4bda1cfe.
vLLM versions 0.10.2 up to but not including 0.13.0 lack sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor invariant checks by default, crafted embedding requests with malformed (negative or out-of-bounds) tensor indices can crash the server or exhaust resources when the prompt-embeds feature is enabled. The source also notes potential out-of-bounds write (write-what-where) memory corruption. This continues CVE-2025-62164, whose earlier fix only disabled the feature by default.
A flaw in the LangSmith SDK's TracingMiddleware lets an attacker who can send HTTP requests to a server running it make that server read an arbitrary local file and upload the contents to LangSmith as a trace attachment. Retrieving the contents requires read access to the destination LangSmith workspace, and triggering the read may not require authentication, depending on deployment. The flaw combines an unvalidated tracing-propagation header field (CWE-346), a type check that never engages (CWE-843), and a path traversal read (CWE-22).
Fix: Upgrade the Python SDK to `>= 0.8.18`. Until upgrading, do not expose `TracingMiddleware` to untrusted HTTP traffic, and limit workspace trace-read access to trusted members.
The `web_url_read` tool in `mcp-searxng` is vulnerable to SSRF via DNS rebinding. The `assertUrlAllowed()` function in `src/url-reader.ts` checks only the hostname string against a private address blocklist and performs no DNS resolution, so a domain that resolves to a private or loopback IP bypasses the check. In default HTTP mode, where `requireAuth` is `false`, an attacker can read arbitrary internal HTTP services reachable from the server host without authentication.
Fix: The source recommends resolving the hostname with `node:dns/promises` inside `assertUrlAllowed()` before the fetch is issued, rejecting non-http(s) protocols, and checking the resolved addresses against the private IPv4 and IPv6 checks, with `assertUrlAllowed()` made async and awaited at both call sites.
The `web_url_read` tool in mcp-searxng enforces its 5 MiB response limit only by checking the `Content-Length` header from a preliminary HEAD request. When a server omits that header, `checkContentLength()` returns `null`, the guard evaluates to `false`, and `response.text()` reads the full body with no byte cap. An unauthenticated attacker who controls or can redirect to an HTTP endpoint can force unbounded memory and CPU use, causing a Denial of Service.
Fix: Replace both `response.text()` calls with a streaming reader that aborts once the byte counter exceeds `maxContentLengthBytes`.
Network-AI's EnvironmentManager.listBackups() trusts the path field in each backup's _manifest.json, and pruneBackups() passes that path directly to rmSync with recursive and force set. An attacker who can write a manifest under data/<env>/.backups/<name>/ can make network-ai env backup prune, or any call to pruneBackups(), recursively delete an arbitrary path the Network-AI process user can access. The issue was confirmed in Network-AI 5.12.1, and the advisory notes no RCE chain was confirmed.
Fix: Fixed in v5.12.2 (commit a59c13a). The deletion path is now recomputed from a format-validated entry.backupId, and a dirname containment check limits deletion to one level under the backups directory. Install with npm install network-ai@5.12.2.
Langflow's `/api/v1/files/upload/` endpoint processes multipart form data before any authentication check, so an unauthenticated attacker can send a request with an oversized run of hyphens after the boundary and make the server unusable for all users indefinitely. The attacker does not need a valid flow ID, since the server parses the body even when the path ID is random, and the request can be repeated at will.
Fix: Fixed in 1.0.19 via PR #3923. A `check_boundary` HTTP middleware validates the multipart boundary against `^[\w\-]{1,70}$` and rejects malformed requests with HTTP 422 before the body is parsed, and the upload endpoint gained an authentication and flow-ownership check (`get_current_active_user`, HTTP 403 on mismatch). Upgrade to 1.0.19 or later.
agentic-flow versions <= 2.0.13 interpolated MCP tool parameters such as agent, task, name, language and agentdb arguments directly into shell command strings passed to execSync(). A malicious value can break out of the double-quoted argument and run arbitrary OS commands with the privileges of the user running the MCP server. The HTTP/SSE transports expose the same sinks without authentication or Origin/Host validation.
Fix: Fixed in agentic-flow@2.0.14, which rewrites every affected call site to use execFileSync(file, argv, { shell: false }). Upgrade to agentic-flow >= 2.0.14. There is no in-product configuration that mitigates this without upgrading.
GHSA-jv2h-4p9v-wf5w affects ouroboros-ai, where the fix for CVE-2026-47211 in 0.39.0 left the `_UNTRUSTED_ENV_DENYLIST` incomplete. A malicious cloned repository can ship a `.env` that is auto-loaded at import and set keys such as `CODEX_HOME`, `OUROBOROS_MCP_CONFIG` and `OUROBOROS_ALLOW_LOCAL_TRANSPORT`, which lead to arbitrary command execution. The MCP bridge also auto-loaded `./.ouroboros/mcp_servers.yaml` from the working directory, so running `ooo` inside a malicious repo could spawn the committed server `command` without any `.env`.
Fix: Fixed in 0.42.1. All listed keys were added to `_UNTRUSTED_ENV_DENYLIST`, the cwd auto-discovery branch was removed, and the regression suite now derives from the source denylist. Workaround: do not run Ouroboros from an untrusted or cloned repository directory, and remove any project-directory `.env` and `./.ouroboros/mcp_servers.yaml` before running.
AgenticMail's inbound mail handlers act on privileged effects without verifying the sender is the operator. In a configured headless-bridge deployment, an external email routed to the bridge inbox makes the dispatcher resume the operator's Claude Code session with permissionMode 'bypassPermissions', embedding the attacker-controlled from, subject and preview verbatim into the prompt. The gap is structural: the bridge-wake path lacks the isOperatorReplySender check that its sibling operator-query reply hook uses in the same repo.
The pipecat development runner exposes a `/ws` WebSocket endpoint for telephony testing that accepts connections without authentication. An unauthenticated attacker can send a crafted Twilio stream-start message with an attacker-supplied `callSid`, causing the server to send a hang-up request to Twilio's REST API using the operator's own account credentials. The source says this may let an attacker terminate an active call on a victim's Twilio account if they know or obtain a valid call SID, and that equivalent sinks exist for Telnyx and Plivo.
Fix: Fixed in PR #12832 (`fix(security): close IDOR in get_flow_by_id_or_endpoint_name`), merged 2026-04-22 and released in Langflow 1.9.1. The helper now enforces ownership on both the UUID and endpoint_name lookup branches, returns 404 for cross-user lookups, and fails closed on a malformed user_id.
GitHub Advisory Database