Advisories
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
52 items
Obot, an open-source AI agent and MCP platform, documents a Docker quickstart that starts the container on 0.0.0.0:8080 with authentication disabled by default in all versions up to and including commit d7e6970 (CVE-2026-101065). Unauthenticated users who can reach the port receive a synthetic "nobody" user holding the Owner and Admin roles, which grants full control of the Obot API and UI, including registering and launching attacker-controlled MCP servers. The quickstart also mounts /var/run/docker.sock, giving the MCP runtime backend access to the host's Docker control surface.
Fix: The fix is documentation-only: the quickstart now enables authentication. Operators who followed the previous instructions should set OBOT_SERVER_ENABLE_AUTHENTICATION=true before exposing the host to any untrusted network.
NVD/CVE DatabaseDBHub 0.21.2 exposes an unauthenticated HTTP MCP endpoint at /mcp when run with --transport http. Its origin check only compares Origin and Host hostnames for equality, so a DNS rebinding attack lets a malicious website invoke DBHub MCP tools from a victim's browser without prompt injection or model involvement. With a real configured database, this can read, enumerate, and potentially write database contents depending on configured tool permissions and credentials.
Suggested remediation: bind HTTP transport to 127.0.0.1 by default and require explicit opt-in for 0.0.0.0 or non-loopback hosts. Add an explicit allowed-hosts policy instead of accepting arbitrary hosts (the source text is truncated at this point).
Decepticon composes web crawl output into LLM messages without neutralizing ChatML special-token literals, so a string planted in a target web page can forge a new operator turn that the model treats as authoritative. Under a BYOK OpenAI-compatible backend whose tokenizer preserves special-token IDs (confirmed with vLLM, SGLang and TGI), this bypasses agent guardrails and enables arbitrary command execution in the Kali Linux sandbox. Confirmed in v1.1.4 across all 16 specialist agents.
OpenClaw (npm package `openclaw`) before 2026.7.1 does not enforce the owner-only authorization requirement for Claude Code permission prompts delivered through the MCP channel bridge. An authorized non-owner channel sender with channel command access can approve or deny a pending permission request meant for the owner, so the requested action can proceed without owner consent. The practical impact depends on the pending action and the host capabilities requested by the Claude Code run.
Fixed in version 2026.7.1.
Zammad, a web-based open source helpdesk and customer support system, has a flaw before version 7.1.2. A security filter protecting its AI Agent configuration can be bypassed by entering specially crafted text into an AI Agent field. An administrator with permission to create or edit AI Agents could run arbitrary commands on the host server, potentially reading, modifying, or destroying all stored data. No action from other users is required, since the malicious code executes the next time the affected AI Agent processes a ticket.
BerriAI LiteLLM versions before 1.101.0-rc.1 contain a tenant isolation bypass in the semantic cache layer, tracked as CVE-2026-89032. A metadata key mismatch between _get_semantic_cache_tenant_scope() and _get_metadata_variable_name() lets an authenticated user with a valid virtual key submit semantically similar prompts on routes such as /v1/responses and /bedrock/* and retrieve other tenants' cached responses, including personally identifiable information, financial data or source code. Attackers can also cause agentic front-ends to auto-execute attacker-supplied tool calls under victim credentials.
The Cline Hub dashboard server (`@cline/cline-hub`), launched with the `cline dashboard` CLI command, accepts WebSocket connections on `/browser` without validating the HTTP `Origin` header. When `ROOM_SECRET` is unset, which is the default for `127.0.0.1` binds, `isAuthorizedBrowserRequest()` returns `true`, so any website a developer visits can open a cross-origin WebSocket to `ws://127.0.0.1:8787/browser`. Dashboard sessions default to `autoApprove: true` for all tools, and the source reports that an injected `upsert_mcp_server` frame wrote a malicious `stdio` MCP server entry into the victim's Cline settings file.
@bytebase/dbhub's `readonly = true` setting on the `execute_sql` tool does not make connections read-only. The PostgreSQL and SQLite connectors only apply database-level read-only mode when `config.readonly` is set, but `source.readonly` can never be populated, so that path never runs. Enforcement falls to a classifier that checks only each statement's leading keyword, so a `SELECT` calling functions such as `setval`, `lo_export`, `pg_read_file` or `dblink_exec` can write data, read or write server files, or execute commands. The HTTP transport is unauthenticated and binds to `0.0.0.0` by default.
langchain-nvidia-ai-endpoints versions before 1.4.2 accepted local filesystem paths as image inputs for Vision Language Model requests. An attacker who controls image input passed to ChatNVIDIA or VLM reranking APIs can read files the application process can access and send them to the configured NVIDIA/NIM model endpoint.
Fix: Upgrade to langchain-nvidia-ai-endpoints >= 1.4.2, which rejects raw local filesystem paths for VLM image inputs. If upgrading is not immediately possible, reject local filesystem paths in user-controlled VLM image inputs, allow only trusted remote URLs, data URIs, or known safe asset/file IDs, and run the application with least-privilege filesystem access.
Missing symlink validation in Language Servers for AWS (aws/language-servers) may allow an arbitrary file write outside the workspace trust boundary. Impacted versions are Language Servers for AWS <1.69.0. The agent may follow a symlink inside a trusted workspace to an external location and write there without prompting the user for approval.
Language Servers for AWS, the runtime behind Amazon Q Developer's IDE plugins, contains an improper trust boundary enforcement flaw in versions <1.65.0. When a local user opens a maliciously crafted workspace and trusts it, commands defined in project-level configuration files may execute automatically, giving arbitrary code execution on the user's host.
CVE-2026-95985 affects the file write tool in Kiro IDE, an agentic desktop IDE, before version 1.0.242. The flaw may let remote unauthenticated actors execute arbitrary commands and inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository opened as an untrusted workspace, sending any message can cause the agent to modify auto-loaded global configuration paths.
MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control entirely in _load_model(). A remote attacker can execute arbitrary code by supplying a crafted MLmodel artifact.
MLflow's dspy flavor, versions 2.0 and later, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False control only when model_path ends in .pkl. A remote attacker can use a crafted MLmodel artifact to execute arbitrary code.
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is affected by CVE-2026-18875, a RAG poisoning flaw (CWE-74) caused by an unauthenticated runbook upsert in the FTM AI agent server at api.vectordb.runbooks.js:51. An unauthenticated attacker can insert malicious runbook content into the agent's vector database. This can steer AI-driven MCP tool calls, potentially triggering unauthorized payment actions or exfiltrating payment data.
The upload_attachment method in confluence/attachments.py of mcp-atlassian reads and uploads arbitrary local files to Confluence without calling validate_safe_path(), although the download methods do call it. An MCP-connected AI agent, or an attacker influencing it through prompt injection, can read any file the server process can access, such as SSH keys, AWS credentials or .env files, and exfiltrate it as a Confluence page attachment. The issue was reproduced with mcp-atlassian 0.21.1 on Python 3.11.
Add validate_safe_path(file_path) before the os.path.exists() check in upload_attachment, matching the existing pattern in the download methods. The function is already imported in that file.
The Jira and Confluence attachment upload tools in MCP Atlassian accept caller-controlled file_path parameters and read those paths from the MCP server's local filesystem before uploading them as Atlassian attachments. In local stdio deployments this exposes files readable by the user's MCP process, while in HTTP/SSE or streamable-http deployments any MCP client permitted to invoke upload tools can make the server read a server-local file and upload it to Jira or Confluence. The flaw is deterministic and does not depend on prompt injection or model behavior.
The mcp-atlassian server's confluence_upload_attachment MCP tool passes its file_path argument straight to open(file_path, "rb") with no path validation, so a caller can read arbitrary files the server process can read and upload them to an attacker-controlled Confluence host. With the default streamable-http transport binding 0.0.0.0 without authentication, this is remotely exploitable without credentials. It is the read-side counterpart of GHSA-xjgw-4wvw-rgm4 / CVE-2026-27825, whose fix in v0.17.0 covered only the download path.
9router decides whether a request is local by trusting the client-supplied X-9r-Real-Ip header in isLocalRequest() within src/dashboardGuard.js. When the app runs without custom-server.js, which normally strips and regenerates that header, an unauthenticated remote attacker can send X-9r-Real-Ip: 127.0.0.1 to reach /api/v1/* without an API key. The reported impact includes unauthorized use of the owner's configured LLM provider connections and consumption of paid API credits. The issue was verified on 9router-app 0.5.4 (Next.js 16.2.9) using GET /api/v1/models.
The vault_batch MCP tool and the POST /batch-to-vault HTTP endpoint in @roomi-fields/notebooklm-mcp passed a caller-supplied vault_dir directly to path.resolve() and fs.mkdir() with no containment check, and slug_prefix was concatenated into filenames without sanitization. Affected versions run from v1.6.0 through v2.0.2, and an attacker, or a prompt-injected LLM driving the MCP, could write .md and .json files to any location the server process can write, such as autostart folders or shell startup files.
Fix: Fixed in version 7.1.2.
NVD/CVE DatabaseFix: Fixed in AWS Language Servers version 1.69.0. Upgrade to the latest version and ensure any forked or derivative code is patched with the new fixes. No workarounds are available.
GitHub Advisory DatabaseFix: Fixed in Language Servers for AWS version 1.65.0. Upgrade to the latest version and ensure any forked or derivative code incorporates the fix. No workarounds are available.
GitHub Advisory DatabaseFix: Fixed in 1.0.242 or later. Impacted versions: < 1.0.242.
AWS Security BulletinsFix: Server-local file uploads should be denied by default in HTTP/SSE or multi-user deployments, or uploads should be constrained to an explicit allowlisted upload directory after realpath resolution, and dangerous path forms such as remote UNC paths and file:// URLs should be rejected before filesystem checks.
Fix: Do not trust X-9r-Real-Ip (or any X-9r-* header) received directly from clients. Derive the client address for authorization from a trusted transport-level source, such as req.socket.remoteAddress. If custom-server.js is required for the security model, fail closed when its trusted marker is absent and strip or reject inbound client-supplied X-9r-* headers at the edge. Document supported secure startup modes so the header cannot be attacker-controlled.
Fix: Fixed in v2.0.3: set the NOTEBOOKLM_VAULT_ROOT environment variable to a directory that bounds all vault writes, which enables realpath-based containment, since it is unset by default and the legacy unrestricted behaviour remains when it is unset. slug_prefix is now always sanitized regardless of that variable. Users who cannot upgrade should run the server under a dedicated unprivileged user with write access only to the intended vault directory, keep the HTTP endpoint off non-localhost interfaces, and validate vault_dir arguments before forwarding them.