Advisories
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
54 items
Xinference used Python's eval() to parse Llama3 tool-call output in the extract_tool_calls() function of xinference/model/llm/tool_parsers/llama3_tool_parser.py. A remote, unauthenticated attacker can use prompts sent to the /v1/chat/completions endpoint to make the model return a Python expression, which the server evaluates. The flaw is rated Critical, CVSS 10.0, and allows remote code execution in the Xinference server process in the tested default deployment.
CVE-2026-62674 affects Omnigent, an open-source AI agent framework and meta-harness, before version 0.3.0. The PUT /sessions/{session_id}/agent endpoint checks LEVEL_EDIT permission but does not reject a bound shared or template agent whose agent.session_id is None. An authenticated user with edit access to a session can replace that shared agent bundle, add a stdio MCP server, and cause later sessions using the shared agent to run an attacker-controlled command with the Omnigent runner's permissions, exposing files, credentials, workspace data, internal services, and runner availability.
CVE-2026-47627 affects NVIDIA Triton Inference Server for Linux and is classified as CWE-22, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'). The source states that an attacker could cause path traversal, and a successful exploit might lead to denial of service. NVD had not yet provided an assessment when the entry was published on 08/18/2026.
Context7 through version 2.1.2 contains a prompt injection flaw in its Custom AI Instructions feature, served through the MCP server. An attacker can inject unsanitized content into those instructions, which connected AI coding agents then execute. The poisoned instructions can exfiltrate credentials from environment files to an attacker-controlled service and delete files on the victim's machine when the agent makes a routine library documentation request.
CodeWhale (codewhale and codewhale-tui) versions 0.8.41 up to but not including 0.8.64 contain an argument injection flaw in the git_show tool. The model-supplied rev parameter reaches the git show argv without an --end-of-options sentinel, so a value starting with --output= is read as a git flag, enabling arbitrary file writes as the invoking user, since the tool is auto-approved and advertised as read-only.
Fix: Fixed in 0.8.64 by adding rev validation.
The unauthenticated webhook test endpoint in the default MLflow Tracking Server (`POST /api/2.0/mlflow/webhooks/{id}/test`) returns the upstream response status and body to the caller. The SSRF guard `_validate_webhook_url`, added in PR #20747 and shipped in 3.10.0, checks only the original hostname, and delivery follows HTTP redirects without re-validation or IP pinning, so an allow-listed HTTPS host can redirect to internal or metadata addresses and the response is reflected back, yielding unauthenticated full-read SSRF on a default server.
MemOS, a memory operating system for LLMs and AI agents, has an authentication bypass when AUTH_ENABLED=true but the INTERNAL_SERVICE_SECRET environment variable is unset. The is_internal_request() check in src/memos/api/middleware/auth.py then compares None to None, which evaluates true, so an unauthenticated remote attacker is treated as an internal principal with scopes ["all"]. This grants access to admin API-key management endpoints (minting, enumerating, revoking keys, and generating a master key) and to all data endpoints.
CVE-2026-64859 affects New API, a large language model (LLM) gateway and asset management system, prior to 1.0.0-rc.7. The admin user list and user lookup APIs, including GET /api/user/, return User.AccessToken as access_token, so an authenticated administrator can obtain the root user's bearer token and access root-only system configuration APIs. The weakness is classified as CWE-200.
Fix: Fixed in version 1.0.0-rc.7.
UpTrain versions 0.7.1 and prior are affected by a remote code execution flaw in the /new_run endpoint, reachable through the checks and metadata parameters. Any user with access to UpTrain and a valid authentication method may be able to run arbitrary code in the context of the host, which in most cases is the docker container suggested by the documentation.
UpTrain versions 0.7.1 and prior have a remote code execution flaw in the `/add_prompts` endpoint, reachable through the `checks` and `metadata` parameters. Any user with UpTrain access and a valid authentication method may execute arbitrary code in the context of the host running UpTrain, which in most cases is the Docker container suggested by the documentation.
UpTrain versions 0.7.1 and prior expose a remote code execution flaw in the /create_project endpoint, reachable through the checks and metadata parameters. Any user with access to UpTrain and a valid authentication method may run arbitrary code in the context of the host running UpTrain, which in most cases is the Docker container suggested by the documentation.
Omnigent, an open-source AI agent framework and meta-harness for orchestrating coding agents, is affected by CVE-2026-62677 in versions prior to 0.3.0. An authenticated user can upload a session-scoped agent bundle with an absolute or traversal-containing os_env.cwd value, which the parser and validator store without constraint. When OMNIGENT_RUNNER_WORKSPACE is unset, the attacker-controlled path becomes the trusted root, letting sys_os_read, write, edit and shell tools reach runner files and environment secrets outside the intended workspace.
Fixed in 0.3.0.
Omnigent, an open-source AI agent framework and meta-harness for orchestrating coding agents, has a flaw in its shared shell-command parser (omnigent/policies/builtins/_shell.py) before version 0.3.0. The parser does not recognize combined interpreter flags, the timeout, nice, setsid, and stdbuf wrappers, command substitutions, or a single background control operator. A gated git push or gh write hidden in these forms yields no parsed operation, so the github.py write_repos and write_branches allowlist and the working_dir.py workspace confinement policies abstain and allow the command. An authenticated or prompt-injected agent can therefore push to an unauthorized repository or branch or escape the intended workspace (CVE-2026-62676).
CVE-2026-62675 affects Omnigent, an open-source AI agent framework and meta-harness, before version 0.3.0. An authenticated user can submit an agent bundle to POST /v1/sessions, and validate_agent_bundle in omnigent/server/bundles.py fails to reject a tools..callable dotted Python path, so the bundle can select subprocess.check_output and run a local command with the runner process permissions. This can expose runner files, environment variables, credentials, workspace data, internal services, and availability without administrator access.
Fixed in 0.3.0.
In ONNX before 1.21.0, the save_external_data function opens the external-data file path for writing without O_NOFOLLOW or O_EXCL, after a non-atomic os.path.isfile() check. A local attacker with write access to the directory where a victim serializes external data can pre-plant a symlink that gets followed, so the victim's write appends to any file the victim can write, such as ~/.ssh/authorized_keys, cron files, or application configs.
Fix: Fixed in 1.21.0.
SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies restrict_to_same_domain only to leaf url entries, not to nested sitemap entries, which are passed directly to self.scrape_all([loc.text], "xml") and fetched with an aiohttp GET. An attacker who controls or influences an ingested sitemap can point a nested entry at an internal address, so the server fetches it even when restrict_to_same_domain is True, and the response is returned in the Documents.
CVE-2026-69855 is a server-side request forgery (SSRF) flaw in Microsoft Copilot in Azure, classified as CWE-918. An authorized attacker can exploit it over a network to disclose information. The source gives no CVSS score, as NVD has not yet provided an assessment.
A NoSQL injection flaw in langgraph-checkpoint-mongodb and langgraph-store-mongodb lets a caller who controls the filter argument embed MongoDB query operators, because keys prefixed with $ are not rejected. The affected methods are MongoDBSaver.list(), MongoDBSaver.alist() and MongoDBStore.search(), and the advisory rates the issue High (CVSS 4.0 base 7.1, CVSS 3.1 base 7.7), with cross-tenant read exposure of checkpoint data.
Upgrade langgraph-checkpoint-mongodb to 0.3.0 or later and langgraph-store-mongodb to 0.4.0 or later. If an upgrade is not possible immediately, remove or escape MongoDB query metacharacters such as "$" from user-controlled input before passing it to the filter parameter.
CVE-2026-15679 is a remote code execution flaw in Hugging Face PyTorch Image Models. The flaw lies in checkpoint parsing, where user-supplied data is not properly validated, leading to deserialization of untrusted data. Remote attackers can execute arbitrary code in the context of the current process, but the target must visit a malicious page or open a malicious file.
CVE-2026-18482 is a command injection vulnerability in the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server in Neo.mjs. The checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled absolutePath values into shell commands, enabling arbitrary OS command execution when an AI agent is induced to invoke these tools.
Fix: Commit 88c77fc fixes these vulnerabilities.
NVD/CVE DatabaseFix: Fixed in version 0.3.0.
Fix: Fixed in version 0.3.0.
NVD/CVE Database