Advisories
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
54 items
LMDeploy's PyTorch DistServe control plane deserialized ZeroMQ messages with recv_pyobj(), which uses pickle and can execute arbitrary code during deserialization. An attacker who can reach the POST /distserve/p2p_connect endpoint can point the server at a malicious ZeroMQ peer, and deployments without API-key authentication allow unauthenticated remote code execution with the privileges of the serving process. Affected versions are lmdeploy >= 0.9.2, < 0.16.0, and only when PD-disaggregation/DistServe is enabled.
Fix: Fixed in LMDeploy 0.16.0, which replaces pickle-based ZeroMQ messaging with JSON (send_json()/recv_json()) and validates received objects against the DistServeCacheFreeRequest Pydantic schema. Interim workarounds: prevent untrusted clients from reaching /distserve/* endpoints, restrict the DistServe HTTP and ZeroMQ control planes to trusted cluster networks, configure API-key authentication, and block arbitrary outbound ZeroMQ connections from serving nodes. The source states these workarounds reduce exposure but do not make pickle deserialization safe.
GitHub Advisory DatabaseCVE-2026-85885 is an improper neutralization of special elements used in a command ('command injection') flaw in M365 Copilot. An authorized attacker can exploit it over a network to elevate privileges.
SQLBot, a Text-to-SQL system built on large language models and RAG, is affected prior to version 1.9.0. An authenticated user can submit a crafted sheet["tableName"] value through POST /api/v1/datasource/, which is stored without safe identifier handling. When the datasource is later removed via DELETE /api/v1/datasource/{id}, PostgreSQL executes the stored value in cleanup SQL, allowing COPY TO PROGRAM and arbitrary operating-system commands under the postgres process privileges inside the SQLBot container.
Fixed in version 1.9.0.
LMDeploy versions from 0.9.1 up to but not including 0.10.2 run an RPC server (AsyncRPCServer in zmq_rpc.py) that deserializes incoming messages with pickle.loads() in call_and_response() without any sanitization. This allows remote code execution through the RPC server.
Fix: Version 0.10.2 contains a patch.
NVD/CVE DatabaseCVE-2026-19407 affects the Google Cloud Gemini Enterprise Agent Platform SDK for Python in versions prior to 1.166.1. The flaw is a bucket squatting issue that allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft.
IBM Langflow OSS versions 1.0.0 through 1.10.0 can let attackers run arbitrary Python code with root privileges (UID=0) on the Langflow server. Attackers do this by submitting components that contain socket or urllib imports. The flaw enables AWS credential theft via IMDSv1 SSRF with full IAM role permissions, arbitrary file exfiltration from the container filesystem, and lateral movement to internal services such as PostgreSQL and Redis within the Docker network. The scanner also incorrectly returns "validated": true, which gives a false security signal.
PraisonAI, a multi-agent teams system, has a flaw in its unauthenticated POST /api/v1/runs Jobs API before praisonai 4.6.59 and praisonaiagents 1.6.59. The endpoint accepts attacker-controlled agent_yaml, and its approve field can mark execute_command as YAML-approved before @require_approval checks critical tools. A remote caller can thereby make a configured language model agent run arbitrary operating-system commands without credentials or operator interaction.
Mistral Vibe before 2.25.5 contains a remote code execution flaw in its worktree creation process, which runs git hooks before trust validation. An attacker who supplies a repository with a crafted post-checkout hook can execute arbitrary shell commands with the privileges of the user running Vibe.
Fix: Fixed in 2.25.5. The source does not discuss any other mitigation.
NVD/CVE DatabaseA containerized MCP server running under the default `network` permission profile (`insecure_allow_all: true`) can reach host-local services through `host.docker.internal`, including the ToolHive API, other ToolHive-managed MCP server proxies, and other localhost services. Because the ToolHive API and MCP proxy endpoints are unauthenticated, a compromised or malicious MCP server can move laterally without a container escape. The source rates the severity High.
LMDeploy, through its latest release, passes the quant_dtype value from a model's HuggingFace quantization_config directly into eval(f'torch.{quant_dtype}') at lmdeploy/pytorch/config.py line 620 with no validation. The AWQ branch does not override this value, so a malicious model can run arbitrary Python when loaded with lmdeploy. The advisory describes this as a supply-chain vector affecting any user who loads an untrusted model.
vLLM versions before 0.28.0 do not validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints. An unauthenticated attacker can crash the engine by submitting a negative token ID, which triggers a CUDA device-side assertion that poisons the GPU context and makes all later requests fail until the process restarts.
Fix: Fixed in vLLM 0.28.0. The source does not state an upgrade path or workaround beyond this version.
CVE-2026-85887 is an incorrect permission assignment for a critical resource in M365 Copilot. An authorized attacker can exploit it over a network to disclose information.
vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggregated deployments. Remote attackers can submit requests with max_tokens=0 to exhaust decode-worker memory without bound until the worker restarts.
CVE-2026-78501 is an improper neutralization of special elements used in a command ('command injection') flaw in Microsoft 365 Copilot's Business Chat. An unauthorized attacker can exploit it over a network to disclose information.
Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network. The source gives no affected versions, attack preconditions or further technical detail.
AI Agent Automation, a modular AI agent workflow platform, is affected by CVE-2026-54520 in versions prior to 0.9.1. The executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.path value through path.resolve with process.cwd() and uses the result for reads or writes without confirming it stays inside an approved workflow directory. An authenticated user who can create or modify workflow file steps can use traversal segments to read sensitive files or write and overwrite files the backend process can access, including application-adjacent files when process permissions allow.
AI Agent Automation versions prior to 0.9.1 contain an authorization flaw in backend/src/controllers/memory.controller.js. The listMemories, deleteMemory, and clearAgentMemory functions accept a caller-supplied agentId or memory _id without checking that the related Agent belongs to req.user. An authenticated attacker who knows or obtains another user's identifiers can read that user's AgentMemory content, delete an individual memory, or clear all memory for a victim agent.
SQLBot, a Text-to-SQL system built on large language models and RAG, is affected by CVE-2026-53556 before version 1.9.0. The POST /api/v1/datasource/previewData endpoint places the client-controlled table_name value into generated SQL without safe identifier handling. An authenticated user can use a crafted table_name to call pg_read_file(), pg_read_binary_file() or pg_ls_dir() through a datasource pointed at the internal PostgreSQL service, reading filesystem content such as /etc/hosts and /etc/passwd, and potentially configuration, credentials and source code. In the default tested trusted loopback authentication configuration, the connection runs with PostgreSQL superuser privileges.
CVE-2026-53554 affects SQLBot, a Text-to-SQL system built on large language models and RAG, prior to 1.9.0. The POST /api/v1/datasource/parseExcel endpoint trusts attacker-controlled multipart filenames when choosing storage, and it writes uploaded content before spreadsheet parsing and validation finish. A crafted upload can plant a Python file in /opt/sqlbot/app/alembic/versions/ even when parsing fails and the endpoint returns an error. On the next startup or migration, Alembic imports that file and runs its module-level statements inside the SQLBot runtime.
MCP Documentation Server versions 1.13.0 through 1.13.1 start a Web UI by default on port 3080, and startWebServer in src/web-server.ts calls app.listen(PORT) without a host, binding the unauthenticated document-management API to all interfaces instead of localhost. A network-reachable client can call endpoints such as GET /api/documents, POST /api/documents, DELETE /api/documents/:id and POST /api/search-all without credentials to read, search, insert or delete documents and alter the assistant's knowledge base. The attacker must be able to reach the service over a LAN, VM network, container bridge, VPN or other routed network, and the issue does not grant remote code execution.
Fix: This vulnerability is fixed in praisonai 4.6.59 and praisonaiagents 1.6.59.
NVD/CVE DatabaseFix: Fixed in 0.9.1.
Fix: Fixed in 0.9.1.
NVD/CVE DatabaseFix: This issue is fixed in version 1.9.0.
NVD/CVE DatabaseFix: Fixed in 1.9.0.
Fix: Fixed in 1.13.1.
NVD/CVE Database