Advisories
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
62 items
IBM Langflow OSS versions 1.0.0 through 1.11.5 contain a code injection flaw during graph construction. A remote attacker can exploit it to execute arbitrary code.
IBM Langflow OSS versions 1.0.0 through 1.11.5 contain a flaw, tracked as CVE-2026-79724, caused by improper neutralization of special elements used in an OS command. A remote attacker could exploit it to execute arbitrary OS commands.
CVE-2026-85025 affects IBM Langflow OSS versions 1.0.0 through 1.11.5. Improper enforcement of public-flow security restrictions and session isolation controls lets an unauthenticated attacker execute arbitrary code through publicly shared MCP project endpoints. The attacker can also access or modify chat sessions.
OmniRoute, an open-source AI gateway, is affected in version 3.8.49 and earlier. The POST /api/acp/agents endpoint passes attacker-controlled binary and versionCommand values to execFileSync, and the tokenizer's filter still permits interpreter evaluation arguments. With requireLogin set to false, or during a fresh-instance bootstrap window, an anonymous remote request can execute arbitrary code in the server container. With requireLogin enabled and a management password configured, exploitation requires a management session or a management-scoped API key.
CrewAI versions before fb2323b rely on a Python blocklist that blocks modules at import time. This approach works at the wrong level of abstraction and does not stop access to Python's full object graph, so a different flaw from CVE-2026-2275 remains. The source gives ctypes.CDLL(None) as an example: it loads the C library without any import statement.
ESPnet versions before 202609 deserialize pretrained model checkpoints with torch.load using weights_only=False. A crafted checkpoint file can execute attacker-chosen code when it is loaded through the initialization or fine-tuning path.
vLLM before 0.28.0 contains a remote code execution flaw in the LlavaOnevision2 processor loader. The loader ignores the trust_remote_code parameter when it loads remote processor classes, so an attacker who crafts a malicious model with arbitrary code in processing_llava_onevision2.py can run that code with vLLM process authority, even when trust_remote_code is set to False.
CVE-2026-89332 affects Kiro IDE versions before 0.8.135. The Kiro agent could write a workspace settings file in an untrusted workspace, pointing the Powers registry URL at an external endpoint. Opening the Powers panel before answering the approval prompt sent potentially sensitive workspace data to that endpoint, because the file was already written to disk.
Fix: Fixed in 0.8.135 (Kiro IDE versions before 0.8.135 are impacted).
AWS Security BulletinsAn arbitrary file access vulnerability in Mistral Vibe lets an attacker bypass workspace restrictions through commands classified as unconditionally allowed. Missing path validation for these commands allows access to files outside the active workspace without user approval.
CVE-2026-87987 is an arbitrary code execution vulnerability in Mistral Vibe that lets an attacker bypass command permission checks. Environment variable assignments placed before allowlisted commands are excluded from inspection, so attacker-controlled variables can trigger code execution without user approval.
CVE-2026-87986 is an arbitrary code execution vulnerability in Mistral Vibe. Attackers can bypass its command permission checks by using shell constructs the parser cannot interpret. Because the unparsed portions are omitted from inspection, embedded commands run on the user's system without approval.
An arbitrary code execution vulnerability in Mistral Vibe lets an attacker bypass command permission checks by using ANSI-C quoted arguments. These arguments are not properly inspected, so a crafted allowlisted command can run arbitrary code on the user's system without approval.
An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, lets an attacker create or overwrite files outside the active workspace without user approval. Shell redirection destinations are left out of permission checks, so otherwise allowlisted commands can write to any path the Vibe process can access.
An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, lets an attacker bypass workspace restrictions with quoted absolute paths in allowlisted shell commands. Improper handling of quotation marks during path validation allows files outside the active workspace to be read without user approval.
Headroom, a tool that compresses data before it reaches a large language model, fails to validate the `Origin` header on incoming WebSocket requests before the Headroom WebSocket server forwards them upstream. A malicious WebSocket client running in a browser that can reach the Headroom proxy can make arbitrary LLM requests without authentication, which exposes the OpenAI API key stored in the `OPENAI_API_KEY` environment variable. The flaw affects versions prior to 0.35.0.
Fixed in 0.35.0.
A Server-Side Request Forgery (SSRF) flaw in Google Cloud Gemini Enterprise Agent Platform App Builder, in versions prior to 2026-06-01 on Google Cloud Platform, lets an unauthenticated attacker leak the Compute Engine default service account access token. The vulnerability was identified as CVE-2026-19486.
Fix: This vulnerability was patched on 01 June 2026. Users will need to redeploy their previously deployed apps.
IBM Langflow OSS versions 1.0.0 through 1.10.3 contain a flaw tracked as CVE-2026-84889. The flaw stems from improper limitation of a pathname to a restricted directory, and a remote authenticated attacker can exploit it to execute arbitrary code.
IBM Langflow OSS versions 1.0.0 through 1.11.5 contain CVE-2026-81941. An authenticated non-administrative user can build a flow with an MCP Tools component set to a local stdio subprocess transport and run arbitrary operating system commands at the privilege level of the application process. This bypasses the LANGFLOW_CUSTOM_COMPONENT_ADMIN_ONLY and LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS server-side controls. Successful exploitation could expose credentials from the process environment, modify the file system, and reach other services on the server.
IBM Langflow OSS versions 1.0.0 through 1.11.5 contain a flaw tracked as CVE-2026-81940. The flaw stems from improper neutralization of special characters in flow display names, and a remote authenticated attacker can exploit it to execute arbitrary code.
IBM Langflow OSS versions 1.0.0 through 1.11.5 are affected by CVE-2026-81268. A remote authenticated attacker can execute flows and obtain sensitive information because API key sessions do not expire properly after a user is deactivated.