Advisories
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
60 items
CVE-2026-31020 affects DocsGPT 0.15.0 and below. Its custom prompt feature renders user-supplied prompt content through Jinja templates without input sanitization or sandboxing. An unauthenticated attacker can inject malicious template expressions, causing server-side template injection that can lead to full remote code execution.
FastChat contains an authentication bypass in the /register_worker endpoint that lets unauthenticated attackers register arbitrary worker addresses and perform server-side request forgery. Attackers can register malicious workers under victim model names to intercept user prompts, images, and responses, or probe internal network ports across the worker mesh.
CVE-2026-80098 is an improper verification of cryptographic signature flaw in Copilot Studio. An unauthorized attacker can exploit it over a network to elevate privileges.
Kestra OSS contains an OS command injection vulnerability (CVE-2026-49869) that allows an unauthenticated remote attacker to create and execute arbitrary workflows without credentials. The item is listed as actively exploited in the wild (CISA KEV).
NLTK's Stanford Java wrapper classes (GenericStanfordParser, StanfordTagger, StanfordTokenizer, StanfordSegmenter) pass user-supplied java_options through the per-call options parameter of nltk/internals.py java(), which calls subprocess.Popen without _validate_java_options(). This bypasses the validation added for CVE-2026-12841, which blocks flags such as -agentpath, -javaagent, -agentlib and @argfile when set through config_java(). An attacker who controls java_options can inject these JVM flags, which the source says can achieve arbitrary code execution, and the issue is incomplete fix of CVE-2026-12841.
CVE-2026-77956 is a code injection flaw in ash-project ash_ai, versions from 0.1.0 before 1.0.0. AshAi.Actions.Prompt passes prompt content through EEx.eval_string/2, so when a prompt action builds its text from request data, attacker-controlled input is compiled and run as Elixir. A remote, unauthenticated client can thus execute arbitrary Elixir code on the server, before any model request is made.
Fix: The fix stops evaluating function-supplied prompt content as EEx; only statically configured templates are evaluated.
CVE-2026-85787 is an incomplete list of disallowed inputs in the SQL validation component of Amazon awslabs postgres-mcp-server before version 1.1.7. Crafted SQL placed in content submitted by an authenticated user could let an unauthenticated actor modify data beyond the read-only scope. Impacted versions are any PyPI package version below 1.1.7.
Fix: Fixed in 1.1.7. Upgrade to version 1.1.7 or later.
AWS Security BulletinsCVE-2026-85654 is a code injection flaw in the CDK generator component of Amazon awslabs.dynamodb-mcp-server, an open-source MCP server for DynamoDB. Improper neutralization of special elements in a template engine lets a context-dependent actor run arbitrary code on the host that deploys the generated application, using crafted table, index, or attribute names in a data model file. Impacted versions are >= 2.0.10 AND <= 2.1.5.
CodeWhale's project config merge copies `allow_shell` from a repository's `.codewhale/config.toml` or `.deepseek/config.toml` without the tightening guard applied to `approval_policy` and `sandbox_mode`. A malicious config committed to a repository can silently set `allow_shell = true` for anyone who clones and opens it, exposing the model's `exec_shell` tool and allowing arbitrary shell command execution on the victim's machine without explicit opt-in. The merge at `crates/tui/src/main.rs:5181-5182` (v0.8.50) is applied automatically unless the user passes `--no-project-config`.
The `git_blame` tool in DeepSeek-TUI passes the model-supplied `rev` parameter unvalidated into the argv of `git blame`. A `rev` value of `--contents=/path/to/secret` makes the tool echo the targeted file's contents into the tool result, which returns to the model and appears in the chat transcript, enabling arbitrary file read at the invoking user's privilege. The tool is registered with `ApprovalRequirement::Auto`, so no approval is requested.
Fixed in 0.8.64 (commit 9a34b5034d29f05d1f28fa61b04719ca6a741020). Users should upgrade to 0.8.64 or later.
The js_execution tool in CodeWhale spawns Node with tokio::process::Command::new without calling env_clear or the child_env scrubber that exec_shell, the Python REPL and the MCP launcher use. Model-provided JavaScript can therefore read process.env, and its output returns to the next model turn, exposing API keys, cloud credentials and forge tokens. With auto_approve enabled (YOLO mode), the JS runs without any prompt, so a prompt injection from a README, web page or MCP output can drain the environment.
CodeWhale's exec_shell_interact tool is marked ApprovalRequirement::Auto, so model-supplied input written to an already-approved interactive shell (such as a python3 -i REPL, mysql, ssh or sudo -i) runs without an approval prompt. Any untrusted content the agent reads can steer that input, giving command execution at the privilege level of the approved process.
Fix: Fixed in 0.8.64 (commit 57f3c89471e27ac4032d9791f6885e5d4408c381). Users should upgrade to 0.8.64 or later.
CodeWhale's project config merge copies the `instructions` array from a repository's `.codewhale/config.toml` or `.deepseek/config.toml` into the session without path validation. The listed paths are expanded via `expand_path`, read from disk with no workspace boundary check, and injected into the AI system prompt, so a malicious cloned repository can expose files such as `~/.ssh/id_rsa` through the conversation. The advisory notes that the 100KB cap, the `DENY_AT_PROJECT_SCOPE` list and the lack of a tightening guard do not prevent this.
IBM Langflow OSS versions 1.0.0 through 1.11.2 let an authenticated attacker read arbitrary files from the server filesystem. The attacker supplies absolute paths or traversal sequences in the files parameter of a build request, and the file contents are embedded in the language model prompt and sent to the configured model endpoint. The LANGFLOW_RESTRICT_LOCAL_FILE_ACCESS=true setting was not enforced in the Chat Input to Message attachment pipeline, though it applied to other file-reading components.
IBM Langflow OSS versions 1.0.0 through 1.11.2 contain a server-side request forgery flaw, tracked as CVE-2026-19305. A remote attacker can exploit it to obtain sensitive information.
IBM Langflow OSS versions 1.0.0 through 1.11.2 contain CVE-2026-19304. A remote authenticated attacker can exploit a URL parser discrepancy to obtain sensitive information from internal services.
IBM Langflow OSS versions 1.0.0 through 1.11.2 contain a flaw caused by improper limitation of a pathname to a restricted directory. A remote authenticated attacker can exploit it to delete arbitrary local files or directories.
IBM Langflow OSS versions 1.0.0 through 1.11.2 are affected by CVE-2026-19300. Incomplete scrubbing of sensitive credential fields could allow a remote attacker to obtain sensitive information.
IBM Langflow OSS versions 1.0.0 through 1.11.2 contain CVE-2026-19298. A remote authenticated attacker can exploit an authorization bypass in the flow build process to execute arbitrary code.
LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object, which evaluates untrusted language model output derived from web page content. Attackers can use indirect prompt injection through web pages to inject malicious Python code that runs on the operator's host without review.
Fix: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 Prioritizing Security Updates Based on Risk and CISA's Forensics Triage Requirements. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due date: 2026-09-05.
CISA Known Exploited VulnerabilitiesFix: Fixed in 0.8.64 (commit 43563356b98c6b993085554da82e77370160a31c). Users should upgrade to 0.8.64 or later.
Fix: Fixed in 0.8.64 (commit 26de44a8bd5051f8f944ea60b2c37ae1d2b7d25e). Users should upgrade to 0.8.64 or later.
GitHub Advisory DatabaseFix: Fixed in 0.8.64 (commit 43563356b98c6b993085554da82e77370160a31c). Users should upgrade to 0.8.64 or later.