Advisories
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
81 items
The AI Copilot – Content Generator WordPress plugin, in all versions up to and including 1.5.6, fails to verify user authorization. Unauthenticated attackers can save and run a malicious workflow containing a wp_create_user action node with role=administrator, creating an administrator account and taking over the site. The waic-nonce value is emitted into public JavaScript (WAIC_DATA.waicNonce) on pages where the [aiwu-form] shortcode or public chatbot is rendered, so the nonce check provides no real barrier. Any site rendering those components on a frontend page is exposed.
CVE-2026-67622 affects Flowise through 3.1.4 in its OpenAI Assistants integration. An authenticated attacker can supply an arbitrary credential UUID to Assistants endpoints, and because the credential lookup lacks a workspace ownership check, the attacker can reach credentials in other workspaces. The flaw also lets the attacker enumerate cross-workspace assistant metadata, retrieve file and vector store listings, and upload files into victim workspaces.
FrontMCP, a TypeScript framework for the Model Context Protocol, is affected by CVE-2026-67531 in versions prior to 1.5.7. The sandboxed codecall:execute tool exposes live host Zod schema instances through getTool(), and because Zod v4 defines _zod as non-configurable and non-writable, the Proxy invariants return the raw host object, letting a script reach the host Function constructor and run arbitrary code in the server process. A single tools/call is enough, and the attacker gains the server user's privileges, including OAuth client secrets, JWT_SECRET, session keys, database credentials, and cloud instance metadata. Because DEFAULT_AUTH_OPTIONS defaults to public mode, unconfigured servers expose this to unauthenticated callers, and on authenticated servers an indirect prompt injection in tool output or fetched content can trigger it without a human attacker.
PraisonAI versions prior to 4.6.40 ship a Claude GitHub Actions workflow that embeds an attacker-controlled pull request branch name into a Bash run: block without quoting or validation. Any @claude comment can trigger the job, so an outside contributor can open a fork PR with shell metacharacters in the branch name and execute arbitrary shell code on the runner. Because the job holds a GitHub App token with write permissions, OIDC access and gh/git access, the injection can chain through $GITHUB_PATH to repository writes, pull request and issue manipulation, or OIDC-token abuse.
Flowise's OAuth2 token refresh endpoint, POST /api/v1/oauth2-credential/refresh/:credentialId, is listed in WHITELIST_URLS and so requires no authentication. It decrypts the stored credential, sends a refresh request to the configured OAuth provider, and returns the new access_token in the response body. An attacker who obtains a credential ID can use this to steal access tokens for the victim's connected services, such as Google or Microsoft accounts.
Suggested fix: remove the refresh endpoint from WHITELIST_URLS in constants.ts and add an authentication check in the route handler.
Flowise version 3.1.1 (tested on Ubuntu 25.10) contains a flaw in the run method of the CSV_Agents class, used by the CSV Agent node. Untrusted input is placed into an LLM prompt without adequate sanitization, so a prompt injection can make the LLM return a malicious Python script. That script passes a regex blocklist validator in packages/components/src/pythonCodeValidator.ts, which can be bypassed, and then runs in pyodide, which is not sandboxed from the host OS, giving code execution as the server's service account. Authentication is not required to exploit it.
Flowise's CSVAgent node interpolates an unvalidated base64 segment from the csvFile data URI directly into a Python template run by Pyodide. Because Pyodide's default js bridge exposes eval and dynamic import() on Node.js, an injected payload can break out of the string literal and execute code in the host Node.js process, not the WASM sandbox. A workspace user with chatflows:create can plant the crafted node, and any unauthenticated request to the public POST /api/v1/prediction/:id endpoint then triggers the RCE.
The validatePythonCodeForDataFrame blacklist in Flowise's packages/components/src/pythonCodeValidator.ts can be bypassed with Unicode homoglyph identifiers, letting arbitrary Python run inside Pyodide and full OS command execution on the Flowise host through Pyodide's js module interop. The validator gates pyodide.runPythonAsync calls in the CSV Agent and Airtable Agent, and the source says this reopens the paths patched as GHSA-3hjv-c53m-58jj and GHSA-v38x-c887-992f. The source states the original patches are effectively reintroduced in 3.1.2.
The SQLite Record Manager node in FlowiseAI/Flowise 3.1.2 lets users control the database path through the additionalConfig input. Because the spread of additionalConfiguration follows the database setting, a user-supplied value overrides the intended path, so an attacker can write an SQLite database to an arbitrary filepath, including system directories, since the flowiseai/flowise:3.1.2 Docker image runs as root. The advisory notes the executed SQL query is not user controllable and tableName is validated against /^[a-zA-Z0-9_]+$/.
Flowise's CSVAgent node runs user-supplied Python through pyodide, intended for pandas CSV processing. A denylist blocks dangerous constructs, but the user-controlled customReadCSVFunc input can call pandas.read_pickle(), which deserializes a pickled payload and allows code execution without matching any denied pattern.
A report on GHSA-vmv7-4m6c-3cg5 describes a remote code execution flaw in Flowise, verified as root on version 3.1.2. Unsanitized base64 data from a CSV data URI is interpolated into Python code run by Pyodide in CSVAgent.ts (line 161), letting an attacker reach the host Node.js process through the js bridge and run OS commands as root in the container. The report also lists credential exposure via FLOWISE_PASSWORD and an arbitrary file read, with a CVSS v3.1 score of 9.9.
Option 1 (Best): Use pyodide.globals.set('base64_string', base64String) instead of string interpolation. Option 2: Validate base64 before interpolation, rejecting input that does not match /^[A-Za-z0-9+/=]*$/. Option 3: Escape special characters (", \n, \r, \\) before interpolation.
Flowise's executeJavaScriptCode() function merges caller-supplied nodeVMOptions into its NodeVM sandbox defaults using the JavaScript spread operator, so caller values override the secure settings. An authenticated user can set require.builtin to ["*"] and re-enable child_process and fs, running arbitrary system commands as root on the Flowise server. The flaw is reached through the route in packages/server/src/routes/node-custom-functions/index.ts and the executeCustomNodeFunction() service in packages/server/src/utils/executeCustomNodeFunction.ts.
The Flowise platform's custom JavaScript sandbox, which uses the vm2 package by default, can be escaped to reach remote code execution in FlowiseAI/Flowise 3.1.1 and FlowiseAI/nodevm 3.9.25. Flowise permits custom code to import the moment, axios and node-fetch modules, and the moment dependency carries a previously reported path traversal flaw (CVE-2022-24785) that can lead to RCE when user input reaches the locale function. The advisory states that the issue still affects commit dddfb3c90eec900d747790a439bd362a764039cd and that patching vm2 alone would not resolve it.
Flowise 3.1.2 lets users set arbitrary options for the TypeORM `DataSource` class through the `additionalConfig` input on several nodes, including the MySQL, Postgres and SQLite Record Managers and the AgentMemory nodes. Because TypeORM `DataSource` options can load local files as JavaScript code, this enables remote code execution. The advisory includes a reproduction that begins by logging into a Flowise instance via `POST /api/v1/auth/login`.
CVE-2026-12261 affects `nltk.downloader` in nltk/nltk versions <= 3.9.4. The downloader extracts package archives into shared namespaces such as `corpora/` and `taggers/` rather than package-isolated roots, and checks package integrity only after extraction. One package can therefore overwrite another package's trusted resources, and the changes take effect through ordinary NLTK APIs and persist across interpreter restarts, affecting downstream machine learning pipelines.
CVE-2026-19111 is an insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools of the strands-agents-tools package for Strands Agents. Each tool uses a namespace field as its only tenant-isolation key, and the LLM could control that field through the tool schema, so a crafted prompt could forge it. A remote authenticated user could then read, modify, or delete other tenants' memories or inject false memories, and the standalone mongodb_memory and elasticsearch_memory functions could be redirected to an actor-specified cluster through exposed connection parameters. Impacted versions are below 0.8.3.
Fixed in 0.8.3. The source states no other mitigation, so upgrade strands-agents-tools to version 0.8.3 or later.
CVE-2026-18954 is an incorrect authorization issue in the aggregation pipeline tool of the Amazon DocumentDB MCP Server, an open-source Model Context Protocol server for AI assistants. Write-capable pipeline stages ($out, $merge) bypass the read-only mode enforcement, potentially letting an authenticated MCP client perform write operations on the connected database. Impacted versions are below 1.0.12.
Fix: Fixed in 1.0.12 or later. The source otherwise directs readers to the linked AWS Security Bulletin article for complete information.
AWS Security BulletinsCVE-2026-18953 is an improper limitation of a pathname to a restricted directory in the get_resource tool of awslabs.aws-transform-mcp-server, a locally run MCP server, in versions 0.1.0 through 0.1.4. A context-dependent actor can use the savePath parameter to write arbitrary files outside the intended working directory, which could lead to local code execution.
Fix: Fixed in 0.1.5 (the source states the flaw is present before 0.1.5).
AWS Security BulletinsCVE-2026-69111 affects Milvus through 2.6.22 and 3.0.0. An unauthenticated remote attacker can send a crafted HTTP GET request to the management server on port 9091, reaching the unprotected /management/stop endpoint, which bypasses REST API authentication middleware. By supplying a 'role' parameter, the attacker can shut down the proxy, datanode, or querynode components, causing denial of service. The weakness is classified as CWE-306, and VulnCheck rates it CVSS 4.0 8.7 (HIGH), while NVD has not yet provided an assessment.
CVE-2026-9205 affects IBM Langflow OSS and concerns a weak cryptographic key derivation flaw in the ensure_fernet_key() function. The weakness is classified as CWE-338, use of a cryptographically weak pseudo-random number generator. NVD published the entry on 08/05/2026 and last modified it on 08/06/2026, and NVD has not yet provided its own assessment.
Fix: Fixed in version 1.5.7.
NVD/CVE DatabaseFix: This issue has been fixed in version 4.6.40.