Advisories
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
43 items
CVE-2026-19297 affects IBM Langflow OSS versions 1.0.0 through 1.9.6. A remote attacker could gain unauthorized access to user accounts because the product does not properly restrict excessive authentication attempts (CWE-307). NVD has not yet provided an assessment.
Trigger.dev versions prior to 4.5.6 fail to scope a deployment lookup to the caller's environment. In POST /api/v1/deployments/:deploymentId/background-workers, workerDeployment.findFirst() selects by friendlyId without an environmentId predicate. A caller with a valid API key for one project can submit another project's deployment identifier, link an attacker-owned background worker to it, and move that deployment from BUILDING to DEPLOYING.
Fix: Fixed in 4.5.6.
CVE-2026-73487 affects Flowise before 3.1.3. A regex-based Python code validator in the CSV and Airtable Agent nodes can be bypassed, letting unauthenticated attackers inject malicious code through prompt injection. Attackers can use unblocked pandas functions such as pd.read_json() to exfiltrate datasets, perform SSRF against internal services, or achieve code execution via the unauthenticated prediction API. VulnCheck rates it CVSS-B 9.0 (CRITICAL), while NVD has not yet provided an assessment.
CVE-2026-73485 affects Flowise before 3.1.3, specifically the Airtable Agent node. An unauthenticated attacker can send crafted prompts to a chatflow using that node, bypassing the pythonCodeValidator blocklist through obfuscation to execute arbitrary Python code. The code runs in an unsandboxed pyodide environment with full access to the host operating system. VulnCheck rates it CVSS 4.0 9.0 CRITICAL, and NVD has not yet provided an assessment.
PapersGPT for Zotero 0.6.1 (CVE-2026-73032) passes LLM endpoint output unsanitized to window.eval() in views.ts, letting an attacker run arbitrary JavaScript. Attackers can reach this through prompt injection in PDFs, MITM interception of API requests, or a malicious custom LLM endpoint. The code runs in Zotero's chrome-privileged context, enabling file read and write, process execution, and access to all Zotero data.
The Cortex MCP server (`neuro-cortex-memory`) before version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable, which Claude Code sets to the open project directory, as a trusted Cortex developer checkout. When `open_visualization` runs, `_find_dev_source()` accepts that directory as a source root if `_is_cortex_root()` finds an `mcp_server/` subdirectory and a `ui/unified-viz.html` file. An attacker who places those two marker files in a malicious repository can make Cortex run `mcp_server/server/visualize_bootstrap.py` from it via `subprocess.run`, executing code with the victim's local user privileges.
Trigger.dev versions from 4.4.2 through 4.5.0-rc.5 let a caller with a valid environment API key obtain presigned URLs for another tenant's object-store keys. The flaw arises because user-controlled packet keys are assigned to URL.pathname without rejecting dot segments, and the packets route performs no per-resource ownership validation. WHATWG path normalization collapses .. segments before signing, so an attacker can read or overwrite another tenant's task payloads.
Fix: Fixed in 4.5.0-rc.5.
Trigger.dev versions prior to 4.5.2 contain an account takeover flaw in the Google sign-in flow. The function addGoogleStrategy() in apps/webapp/app/services/googleAuth.server.ts passes a Google profile email to findOrCreateGoogleUser() without checking Google's email_verified assertion. An attacker can use a Google profile with an unverified matching email to attach their Google authIdentifier to an existing email-matched account and log in as that user.
CVE-2026-73654 affects Trigger.dev from 3.3.8 until 4.5.6. The PUT /api/v1/runs/:runId/metadata endpoint passes attacker-controlled operation.key values to new JSONHeroPath(operation.key).set() in packages/core/src/v3/runMetadata/operations.ts without rejecting constructor and prototype path segments. A caller with a normal environment API key can pollute Object.prototype in the shared webapp process, corrupting Prisma queries and Prometheus labels, breaking other tenants' worker authentication, and causing a process-wide denial of service.
Fixed in version 4.5.6.
CVE-2026-72675 is a missing authorization flaw (CWE-862) in Kibana. Part of the Machine Learning functionality did not apply the per-request space filter, so operations issued from one space ran against the machine learning data of every space in the deployment. Kibana Machine Learning performs its Elasticsearch operations with elevated internal permissions, which allows cross-space information disclosure and unauthorized data modification via privilege abuse (CAPEC-122).
CVE-2026-72642 affects the native inference process that Elasticsearch uses to evaluate uploaded machine learning models. A model operation computes a memory address from an offset embedded in the model without checking that it stays within the bounds of the underlying storage. A user with privileges to upload and deploy a trained model can craft one that reads and writes memory outside its allocation, corrupting the heap and crashing the inference process; with enough control over the heap layout, this could enable arbitrary code execution within that process.
vLLM, an inference and serving engine for large language models, contains a flaw from 0.20.2rc0 through 0.26.0 in safe_load_prompt_embeds in vllm/renderers/embed_utils.py. The function toggles the process-global torch.sparse.check_sparse_tensor_invariants setting, and concurrent prompt_embeds parts submitted to POST /v1/chat/completions can race that state, letting an invalid sparse tensor reach tensor.to_dense despite the CVE-2025-62164 guard when enable_prompt_embeds is enabled.
This issue is fixed in version 0.26.0.
Network-AI ClaudeHookBridge before 5.15.1 truncates the target string to 500 characters before evaluating denyPatterns, while Claude Code executes the full untruncated command. An attacker can place dangerous content past byte 500 in a Bash command field, bypassing the operator's hard-deny list and executing arbitrary commands. VulnCheck rates it CVSS 4.0 8.7 HIGH (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N); NVD has not yet provided an assessment.
MCP Atlassian, a Model Context Protocol server for Confluence and Jira, is affected by CVE-2026-73498 in versions prior to 0.22.0. The confluence_upload_attachment tool passes a client-supplied file_path directly to open() without calling validate_safe_path, so an authenticated MCP client can read any file the server process can access and upload it to Confluence as an attachment. If an AI agent is induced through untrusted content to call the tool, the flaw can also expose server environment variables such as CONFLUENCE_API_TOKEN.
Fixed in 0.22.0.
The `ado_package_install` MCP tool in `stata-mcp` interpolates its `package` argument into a Stata command string without validation, and `Controller` sends the result to Stata via `pexpect.sendline()`. Embedded newlines let an attacker inject Stata's `shell` command, giving OS command execution under the account running the Stata-MCP server. The tool is enabled in the default `all` profile, and the base CVSS score is 8.4 (High).
Fujitsu Research's OneCompression library 1.2.0 has an unsafe deserialization flaw, tracked as CVE-2026-73325. QuantizedModelLoader.load_quantized_model_pt() calls torch.load with weights_only=False, which runs Python's pickle machinery on a model.pt checkpoint. An attacker who supplies a crafted checkpoint with a malicious __reduce__ method can execute arbitrary Python code, including system commands, when the library loads it from a caller-selected model directory.
Prowler, a cloud security platform, failed to validate the base_url for its openai_compatible Lighthouse provider before version 5.33.1. An authenticated user with Lighthouse provider configuration access could set this URL through POST /api/v1/lighthouse/providers and POST /api/v1/lighthouse/providers/{id}/connection. When client.models.list ran, the job in api/src/backend/tasks/jobs/lighthouse_providers.py sent requests, including the API key in the Authorization header, to attacker-controlled or internal endpoints.
Claude Code Templates versions before 1.29.4 ship a Claude Code Studio server, started with the --studio option, that binds to all interfaces on port 3444, allows cross-origin requests, and requires no authentication. Request-body fields prompt and agentName reach child_process.spawn() with shell execution enabled, so shell metacharacters are interpreted, letting an attacker who can reach the port, or lure a developer to a malicious website, run arbitrary OS commands with the developer's privileges.
Fixed in 1.29.4.
DSPy 3.3.0b1 has a file exfiltration flaw in its Image and Audio output field adapters. An attacker who can influence language model output can inject a filesystem path into the url field of a parsed Image or Audio typed output, and the JSONAdapter and ChatAdapter then read and base64-encode that local file through encode_image or encode_audio in image.py and audio.py. The file contents are embedded in outgoing prompt messages sent to an attacker-controlled model endpoint.
CVE-2026-73218 affects Cursor IDE for macOS before 3.0.0. An agent running in Auto-Run Sandbox mode can, when Docker Desktop and the Dev Containers CLI are installed, launch a privileged container and mount Docker's virtiofs0. This grants read and write access to the user's home directory and host command execution with the user's privileges, without an additional permission prompt. The CVSS 4.0 base score from GitHub is 7.7 (HIGH).
Fix: Fixed in version 3.0.0.
Fix: Fixed in 3.17.1.
Fix: Fixed in 4.5.2.
NVD/CVE DatabaseFix: Fixed in 5.33.1.
NVD/CVE Database