Advisories
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
43 items
CVE-2026-61447 affects PraisonAI before 1.6.78. The CodeAgent._execute_python() function runs LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. An attacker who influences the model output through prompt injection can exfiltrate all environment secrets and execute arbitrary code on the host.
CVE-2026-59726 affects Ruflo, an agent meta-harness for Claude Code and Codex, before version 3.16.3. The default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without authentication. An unauthenticated network attacker could invoke tools/call to terminal_execute, obtain a shell in the bridge container, read provider API keys, and poison AgentDB learning-store patterns.
CVE-2026-59706 affects mem0 and describes unauthenticated config API endpoints. An unauthenticated attacker can retrieve stored secrets such as OpenAI API keys in plaintext via GET /api/v1/config/, or trigger server-side request forgery by setting ollama_base_url to internal addresses such as cloud IMDS through PUT /api/v1/config/mem0/llm. VulnCheck rates it CVSS 4.0 9.2 CRITICAL, while NVD has not yet provided an assessment.
9Router before 0.4.44 has an OS command injection flaw in the unauthenticated POST /api/tunnel/tailscale-install endpoint, which the dashboard middleware matcher does not cover, so no authorization check applies. The sudoPassword field from the request body is written to the stdin of a 'sudo -S sh' child process; when sudo does not prompt for a password (the process runs as root, NOPASSWD is configured, or a recent sudo timestamp cache exists), sh executes the value as a shell command, letting a remote unauthenticated attacker run arbitrary OS commands. The Shadowserver Foundation first observed exploitation on 2026-07-04 (UTC).
Langroid's Neo4jChatAgent sends LLM-generated Cypher queries directly to the Neo4j driver through its read_query and write_query paths, with no validation, statement-type allowlist, or opt-out gate. Because prompt injection can influence the query text, an attacker can read or destroy graph data and, when APOC or dbms.security procedures are enabled, reach OS-command and filesystem access. The report says this is the same defect class as the SQLChatAgent issue fixed in version 0.63.0 (CVE-2026-25879), and that the fix did not extend to the neo4j module.
9Router, in versions up to and including 0.4.41, exposes its Next.js dashboard API without authentication. The /api/providers endpoints let anyone list, read, create, modify and delete provider connections, while /api/usage/stats returns full plaintext API keys. The /api/usage/request-logs and /api/usage/request-details endpoints also expose other users' request history and full conversation contents, including system prompts and messages.
Langroid's TableChatAgent and VectorStore evaluate LLM-generated tool messages with eval() when full_eval=True, passing an empty dictionary as locals. Because __builtins__ is not removed from the globals mapping, expressions such as __import__('os').system(...) execute, allowing a prompt-injected attacker to achieve unauthenticated remote code execution on the host. The flaw is located in /langroid/agent/special/table_chat_agent.py around line 239 and /langroid/vector_store/base.py around line 225.
Langroid's SQLChatAgent blocks dangerous PostgreSQL functions with a raw-text regex that requires the function name to be followed directly by an opening parenthesis. Quoted identifiers, inline comments, or schema qualification (for example pg_catalog."pg_read_file") pass the regex yet still execute pg_read_file on PostgreSQL, restoring the server-side file-read that CVE-2026-25879 / GHSA-pmch-g965-grmr was meant to block.
PraisonAI versions before 4.6.78 default the prompt injection defense block threshold to CRITICAL severity, so HIGH-level threats pass through unblocked. Attackers can submit single-vector prompt injections, such as instruction overrides or financial manipulation, that are detected at HIGH severity and logged without being blocked, enabling system prompt extraction and unauthorized tool invocations. VulnCheck rates the issue CVSS 4.0 8.7 HIGH, and NVD has not yet provided an assessment.
The mcp-atlassian server's confluence_upload_attachment tool passes a caller-supplied file_path directly to open() in _upload_attachment_direct() in src/mcp_atlassian/confluence/attachments.py, without the validate_safe_path() check that download_attachment() applies. Any authenticated MCP client, or an AI agent steered by prompt injection, can read files the server process can access and upload them to Confluence as attachments. The source reports this was confirmed against v0.21.1 and that /proc/self/environ, which can expose API tokens and other secrets on a Linux deployment, was exfiltrated.
Fix: Add validate_safe_path(file_path) before the open() call in _upload_attachment_direct(), as the source proposes.
BabelDOC's vendored PDF parser deserializes untrusted pickle data when loading CMap files, in `babeldoc/pdfminer/cmapdb.py`. A PDF-controlled CMap name is passed to `os.path.join()` and `pickle.loads()` after only NUL bytes are stripped, so a hex-encoded absolute path in a crafted PDF's `/Encoding` name can redirect deserialization to an attacker-writable `.pickle.gz` file, giving arbitrary Python code execution with the privileges of the BabelDOC process.
CVE-2026-59207 is a vulnerability in n8n, an open source workflow automation platform, affecting versions before 2.27.4 and 2.28.1. The AI Agents feature did not enforce the Allowed HTTP Request Domains restriction configured on credentials when an MCP tool was pointed at an arbitrary URL. A member-level user with use-only access to a shared credential could send its secret to an external server they control.
Fix: This issue is fixed in versions 2.27.4 and 2.28.1.
In Phantom 1.3.0 and earlier, the MCP tools accepted arbitrary absolute output paths when PHANTOM_OUTPUT_DIR was unset, the default. Any caller able to send tool calls, such as an AI agent, could write or overwrite files the process user can write, including shell startup files. Separately, the stem-separation and render paths decoded input audio without a size or duration cap, so a small compressed FLAC or OGG file could expand to multi-gigabyte PCM and exhaust memory.
Fix: Fixed in 1.3.1: file writes are confined to PHANTOM_OUTPUT_DIR (default ~/.phantom/output), with symlinks resolved and re-verified on the final path; decode, duration and size guards were added to the separation and render paths, plus ffmpeg -max_alloc/-t/-fs; output creation uses atomic O_CREAT|O_EXCL. Workaround: set PHANTOM_OUTPUT_DIR (and optionally PHANTOM_AUDIO_DIR) to dedicated directories before starting the server.
CVE-2026-54499 affects Stanza, the Stanford NLP Python library, before version 1.12.2. Model loaders such as stanza.models.common.pretrain.Pretrain.load() call torch.load(..., weights_only=True) but fall back to torch.load(..., weights_only=False) when a pickle.UnpicklingError is raised. An attacker-controlled malicious .pt pretrain or model file can therefore execute arbitrary pickle code when a Stanza NLP pipeline loads it.
Fix: Fixed in 1.12.2.
Serena's built-in web dashboard exposes an unauthenticated Flask API on fixed TCP port 24282 (hardcoded as 0x5EDA in constants.py), with no authentication, no CSRF protection and no Host header validation. A DNS rebinding attack lets a malicious webpage write arbitrary content to the agent's persistent memory, which the agent later reads and acts on, reaching execute_shell_command, enabled by default through shell=True, for remote code execution. The source states that any user running Serena with the default configuration is affected, and the chain requires only that the victim visit a malicious webpage while Serena is running.
CVE-2026-59822 affects LiteLLM versions prior to 1.84.0. An unauthenticated attacker could send a fabricated Authorization header to the MCP Streamable HTTP endpoint, triggering an OAuth2 passthrough fallback that replaces failed key validation with an empty UserAPIKeyAuth() object. This lets requests reach MCP tooling without a valid LiteLLM key. The GitHub-assigned CVSS 4.0 base score is 8.8 (HIGH), and CWE-287 and CWE-306 are listed.
LiteLLM, a proxy server (AI Gateway) for calling LLM APIs in OpenAI or native format, prior to 1.83.7-stable does not sufficiently validate file paths during extraction of uploaded Skills ZIP archives. An authenticated user with access to LLM API routes, or a key whose allowed_routes includes /v1/skills, anthropic_routes, or llm_api_routes, can upload a crafted archive with path traversal entries that may be written outside the intended extraction or staging directory.
Fix: Fixed in 1.83.7-stable.
CVE-2026-59806 affects Gradio before 6.20.0. Unvalidated HTTP/HTTPS URLs passed to the file_fetch() function in the /gradio_api/file= endpoint enable an open redirect and server-side request forgery. A crafted FileData response can target internal endpoints such as cloud metadata services to retrieve sensitive credentials, including EC2 IAM role credentials. VulnCheck rates it CVSS 4.0 4.9 (MEDIUM); NVD has not yet provided an assessment.
Fix: Fixed in 6.20.0 (gradio@6.20.0 release, per the referenced GitHub commit and release tag).
GHSA-7w99-5wm4-3g79 affects @better-auth/oauth-provider at versions >= 1.6.0 and < 1.6.11, the embedded plugin in better-auth >= 1.4.8-beta.7 and < 1.6.0, and the legacy oidc-provider and mcp plugins. The POST /oauth2/token authorization_code grant redeems single-use codes through a non-atomic find-then-delete sequence, so two concurrent requests with the same code can both pass verification and each mint access, refresh and id tokens, contrary to RFC 6749 section 4.1.2.
CVE-2026-55574 affects vLLM, an inference and serving engine for LLMs, prior to 0.24.0. The structured_outputs.regex API parameter passes a user-supplied regular expression directly to the xgrammar and outlines grammar compiler backends without a compilation timeout, and the outlines validation performs no complexity analysis. A single request with an adversarial regex containing nested quantifiers can cause exponential state-space expansion, hanging an inference worker indefinitely and denying service.
Fixed in version 0.24.0.
Fix: Fixed in version 3.16.3.
NVD/CVE DatabaseFix: Fixed in 1.84.0.
NVD/CVE DatabaseFix: Fixed in @better-auth/oauth-provider@1.6.11 and better-auth@1.6.11 for the legacy oidc-provider and mcp plugin paths, which switch to an atomic internalAdapter.consumeVerificationValue claim. Upgrade is the recommended path; the source says the listed workarounds (reverse-proxy serialization, database uniqueness constraints, application-layer hooks) do not fully close the bug without a code patch.