Advisories
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
68 items
IBM Langflow OSS 1.0.0 through 1.11.1 contains a flaw that lets an authenticated attacker run arbitrary operating system commands in the server process. The attacker saves a flow with a crafted type field value, then triggers a build of a wrapper flow that references it. This escalates privileges from authenticated flow user to OS-level command execution under the server process identity, bypassing the LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false policy control.
IBM Langflow OSS versions 1.0.0 through 1.11.1 are affected by CVE-2026-19286. Improper enforcement of security restrictions on the A2A public endpoint could allow a remote attacker to execute arbitrary code.
Kubeflow Pipelines versions before 2.17.0 have an unauthenticated server-side request forgery flaw in the frontend /_proxy/ route, implemented in frontend/server/proxy-middleware.ts. The _routePathWithReferer() function forwards requests to any attacker-chosen HTTP or HTTPS target without a host allowlist or filtering of loopback, link-local, RFC1918, or cluster-local addresses. The route bypasses authorization middleware when ENABLE_AUTHZ=true and can be reached through crafted Referer headers, letting an unauthenticated attacker read or modify internal services, including cloud metadata credentials and Kubernetes APIs.
BerriAI litellm versions up to and including 1.82.4 are vulnerable to Server-Side Template Injection (CVE-2026-37004). Unauthenticated remote attackers can execute arbitrary OS commands by sending a crafted dotprompt_content parameter to the /prompts/test endpoint, because the code uses an unsandboxed jinja2.Environment.
Agno up to and including 2.5.8 contains CVE-2026-37003, a remote code execution flaw reached through prompt injection. The PythonTools and ShellTools components pass unsanitized, LLM-generated arguments directly to exec(), runpy.run_path() and subprocess.run(). An unauthenticated attacker can embed malicious instructions in content the agent processes, such as web pages or documents, and gain arbitrary code and OS command execution on the host server.
Chainlit versions from 2.4.0rc0 up to but not including 2.12.0 are affected when features.mcp.enabled is set to true in .chainlit/config.toml, tracked as CVE-2026-45018. The POST /mcp endpoint for stdio transport accepts a user-controlled fullCommand string, and validate_mcp_command() checks only the executable name against allowed_executables without restricting its arguments, so an unauthenticated attacker can pass npx -y -c with a payload to run arbitrary shell commands with the privileges of the Chainlit process. Since v2.7.0, MCP is disabled by default.
CVE-2026-55640 affects the Nextcloud MCP Server before 0.117.2. The POST /webhooks/nextcloud endpoint in nextcloud_mcp_server/vector/webhook_receiver.py accepts unauthenticated requests when WEBHOOK_SECRET is unset, which is the default, because startup validation does not require it. The payload["user"]["uid"] field from webhook_parser.py is attacker-controlled and used for Qdrant operations without an authenticated-session cross-check, so a network attacker can delete or trigger re-indexing of vector embeddings for any user and destroy the semantic search index with forged deletion events.
qwed-mcp v0.2.0 passes attacker-controlled strings to SymPy's parse_expr() in src/qwed_mcp/engines/math_engine.py without restricting global_dict or validating the expression's AST. Because parse_expr() calls eval() and Python injects __builtins__ by default, an attacker can embed expressions such as __import__('os').system(...) to run OS commands in the running process. The source reports confirmed root-level execution in a Docker container, requiring no authentication or special configuration.
NLTK before 3.10.0 (affected versions <=3.9.4) has an unsafe pickle deserialization flaw in TransitionParser.parse() (nltk/parse/transitionparser.py). The method calls pickle_load() with restricted=False, routing loads through WarningUnpickler, which does not override find_class(), so arbitrary class resolution is allowed. When an application loads an attacker-crafted model file, embedded pickle gadget chains execute arbitrary Python code with the privileges of the user running the application.
Fixed in 3.10.0.
NextChat versions 2.15.8 through 2.16.1 contain an improper URL validation flaw in the proxy endpoint. The x-base-url header is checked with substring matching rather than hostname parsing, so any URL containing 'api.openai.com' passes validation and receives the server's credentials in the Authorization header, allowing an attacker to obtain the server's OpenAI API key.
IBM Langflow OSS versions 1.0.0 through 1.11.1 contain a namespace collision between user identifiers. A remote attacker can exploit this to obtain sensitive information and inject unauthorized messages.
IBM Langflow OSS versions 1.0.0 through 1.11.1 contain a path traversal flaw (CVE-2026-18899). A remote attacker can exploit it to read arbitrary files.
IBM Langflow OSS versions 1.0.0 through 1.11.1 contain a flaw tracked as CVE-2026-18891. Due to improper authentication, a remote attacker could execute arbitrary flows and access sensitive information.
IBM Langflow OSS versions 1.0.0 through 1.11.1 contain a flaw tracked as CVE-2026-18729. A remote authenticated attacker can exploit improper control of code generation to execute arbitrary code.
Stable Diffusion WebUI through 1.10.1 exposes credentials through its /sdapi/v1/cmd-flags endpoint. The endpoint returns parsed command-line arguments, including gradio_auth and api_auth values, in cleartext. An unauthenticated attacker can query it to retrieve configured usernames and passwords, then use them to log in and access the application.
Qwen-Agent through 0.0.34 contains a path traversal flaw in its document parser, which fails to restrict file access to intended directories. An attacker can supply absolute file paths to the unauthenticated Gradio interface and read arbitrary files that the server process can access.
Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in its document parsing path. The path treats caller-supplied paths as URLs without scheme restriction or host validation. An attacker can reach the unauthenticated Gradio interface to make the server issue HTTP requests to arbitrary internal addresses, including metadata services, and read retrieved content through the parsed document output.
9router's request guard treats a request as local, and so exempt from API-key auth on the `/v1` LLM proxy, based on the client-controlled `Host` header in `isLocalRequest` (`src/dashboardGuard.js`). Because the default `DEFAULT_HOST` is `0.0.0.0` and `requireApiKey` is absent from `DEFAULT_SETTINGS`, a remote unauthenticated attacker sending `Host: localhost` gets an open AI relay using the victim's stored API keys, plus unauthenticated SSRF through `/v1/search` via `provider_options.baseUrl` with the `searxng` provider. Affected: 9router <= 0.4.80.
9router exposes an OpenAI/Anthropic-compatible LLM proxy that is meant to require an API key through Next.js middleware. The middleware checks the original request path before a rewrite maps `/codex/*` to `/api/v1/responses`, and `/codex` is missing from the protected prefix list, so requests to `/codex/*` skip the key check. Tested on v0.4.80 (commit 23da7b1fe3bb8edd2bdbdb63fbbb15a476b02c56, Next.js 16.2.9), an unauthenticated remote request to `/codex/x` returned 200 OK where `/api/v1/responses` returned 401, letting attackers trigger upstream provider calls with operator-stored credentials.
ServiceNow has remediated CVE-2026-74820, a SQL injection vulnerability in the ServiceNow AI platform. In certain circumstances, an unauthenticated user could execute arbitrary SQL statements against the instance's underlying database and access or modify instance data beyond what was intended. ServiceNow is not currently aware of malicious exploitation.
Fix: ServiceNow deployed a security update to hosted instances and provided it to partners and self-hosted customers. Customers are recommended to promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
Fix: Fixed in 2.17.0.
NVD/CVE DatabaseFix: Fixed in 2.12.0. The fix removes fullCommand from the client request; stdio MCP servers are declared by the developer in .chainlit/config.toml under [[features.mcp.servers]] and selected by name, and per-server environment variables are set via an env mapping on the server entry. The source's Workarounds section is empty, so no interim workaround is stated.
Fix: Fixed in 0.117.2.