Advisories
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
35 items
Vibe-Trading, a FastAPI-based agent application, exposes its API without authentication when the optional API_AUTH_KEY is unset, which is the shipped default. The Docker image runs the server as root and binds port 8899 on all interfaces. The source reports five findings, the lead one rated Critical (CVSS 3.1 score 9.8): an anonymous client can post to POST /sessions/{id}/messages, and the LLM agent can route the request to BashTool, which runs the command through subprocess.run with shell=True.
GHSA-jqmf-mx4f-hfr6 reports five LLM-callable tools in Vibe-Trading that allow command execution, code injection, and SSRF. The most severe is BashTool, which passes LLM-emitted commands unfiltered to subprocess.run(shell=True) in agent/src/tools/bash_tool.py, rated CVSS v3.1 9.0 (Critical) and mapped to CWE-78. Because the tools are registered unconditionally and the container runs as root, an unauthenticated client reaching port 8899 can trigger execution, and prompt injection in processed documents can also drive the tool calls.
Three issues in Loom for AWS, an AI agent orchestration platform, were addressed. CVE-2026-103956 (CWE-306, CWE-1188) let any network client gain full administrative control of the agent control plane in versions below 1.6.1 when no identity provider was configured, and this was fixed in 1.6.1. CVE-2026-103957 and CVE-2026-103958 (CWE-918, CWE-201) affect versions below 1.7.0 and let an authenticated user with the mcp:write or a2a:write scope exploit OAuth2 discovery handling and tool server or remote agent connections, leading to credential disclosure or access to arbitrary internal network locations.
Fix: Upgrade to the latest version, 1.7.0, and ensure any forked or derivative code is patched to incorporate the new fixes.
GitLab fixed a vulnerability in its AI Gateway component, CVE-2026-90970, affecting versions from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1. Under certain conditions, an authenticated user with Duo Agent Platform access could escape the prompt template sandbox through a specially crafted flow configuration and execute arbitrary commands on the AI Gateway.
Langflow up to version 1.9.3 contains a code injection flaw in the validate-post_validate_code endpoint, implemented in src/backend/base/langflow/api/v1/validate.py. An authenticated attacker can submit Python code to /api/v1/validate/code, which executes it on the server without sandboxing or security controls, enabling arbitrary code execution. The source states the route accepts raw Python source without a visible entitlement guard.
Mounting an attacker-controlled NAND flash image through `lx_nand_flash_open()` triggers an unbounded out-of-bounds heap write in LevelX's NAND flash-translation-layer metadata parser. The write overwrites a driver function pointer in the control block, and a demonstrated control-flow hijack sets RIP to a full 8-byte attacker-chosen value, verified in registers. Two further out-of-bounds reads accompany it, all reproduced under ASan at HEAD `9f1cfdc`. The affected header notes that some portions were generated by Copilot (Sonnet 4.6), and the parser relies on an unchecked on-flash count.
SiYuan's AI Agent tools `http_request` (`util.HTTPRequest`) and `web_fetch` (`util.WebFetch`) check outbound hosts with `CheckHostSSRF`, which resolves DNS once at guard time, while the actual connection resolves DNS again through the default `net.Dialer` with no connect-time private-IP check. An attacker-controlled domain can return a public IP to the guard and a private or metadata address such as `169.254.169.254` to the connection, bypassing the SSRF defense. Affected versions are `<= 3.8.0`, verified on v3.8.0, and the flaw is an incomplete-fix variant of GHSA-rg26-cg95-gq6p.
Fix: Fixed in 3.8.1
GHSA-5rmq-chc7-m22f affects the Vibe-Trading file-read tools. The safe_user_path() check in agent/src/tools/path_utils.py accepts any path under Path.home() or Path.cwd(), which resolve to /root and /app inside the shipped container, so files such as /root/.ssh/id_rsa and /app/agent/.env pass. read_document() performs no sandbox check and returns any file the FastAPI process, running as root, can read, and the advisory reports that unauthenticated clients can reach it on port 8899.
CVE-2026-104019 is an OS command injection flaw in the startup script that runs when a SageMaker Space starts in Amazon SageMaker Unified Studio. The script's network validation against project connections does not sanitize connection details, so under certain conditions arbitrary code can run in another project member's Space. In projects with Trusted Identity Propagation enabled, a user with contributor permissions or higher could obtain another member's temporary execution role credentials and call downstream services on that member's behalf.
Fix: Fixed in all supported SageMaker Distribution versions by sanitizing connection details during startup validation. The fix is deployed globally and applies to Spaces automatically on their next startup. Versions 2.8.x through 2.13.x are affected with no fix, as they are end of support.
A weakness in langflow-ai langflow up to 1.8.4 lets an attacker write or overwrite files outside the intended working directory. The flaw is an absolute path traversal in the knowledge base creation endpoint at src/backend/base/langflow/api/v1/knowledge_bases.py:51, reached over HTTP POST, and it is tracked as CVE-2026-51888.
CVE-2026-51884 affects the /knowledge_base/upload_temp_docs temporary document upload endpoint in Langchain Chatchat 0.3.1. The endpoint is vulnerable to path traversal, and crafted malicious filenames let an attacker write files to arbitrary locations on the server, bypassing the intended restrictions on the temporary directory.
CVE-2026-51883 affects the knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0 and 0.3.1. An attacker can inject path traversal sequences such as `..\` into the `knowledge_base_name` parameter, writing knowledge base content to arbitrary locations outside the configured knowledge base root directory.
CVE-2026-51882 affects the OpenAI-compatible file upload endpoint `/v1/files` in Langchain-Chatchat 0.3.0. The endpoint is vulnerable to path traversal, so an attacker can craft malicious filenames to write files to arbitrary locations outside the `openai_files` directory.
CVE-2026-97662 is an argument injection flaw in the diff scan operation of security-agent-mcp-server, an open-source MCP server published by AWS in the awslabs/mcp repository. Affected versions are 0.1.1 up to but not including 0.2.0. A crafted reference value is parsed as a command-line option instead of a revision, letting a context-dependent actor create, overwrite, or truncate arbitrary files on the host outside the workspace directory and bypass the server's workspace-confinement control.
The AI Engine plugin for WordPress, up to and including 3.8.0, contains a stored cross-site scripting flaw. An unauthenticated attacker can send crafted input to the /mwai-ui/v1/chats/submit REST endpoint, which writes an attacker-controlled string into the PHP error log as a forged line. The plugin's Advisor feature then passes that content into an AI prompt and stores the result unescaped, so the injected script runs when an administrator opens the WordPress dashboard.
Claude Code selected an API key stored on the device, such as one from an earlier `/login` or written into its configuration, over the user's valid Claude Enterprise or Team sign-in when fetching server-managed settings. If the settings endpoint rejected that key, the session ran without the organization's policy, or kept applying a stale cached copy, while still operating as the organization's account. Exploitation required local access to a device holding such a key, and the no-policy case also required that no managed settings had been cached. Endpoint-managed (MDM or file-based) settings were not affected. Claude for Enterprise was affected from version 2.0.68, and Claude for Work (Team) from version 2.1.38.
AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verification in the realtime WebSocket and SSE service when the AISOC_REALTIME_JWT_SECRET environment variable is not set. Unauthenticated attackers can forge subscription tickets with arbitrary tenant identifiers, gaining access to cross-tenant live alerts, cases, agent events and graph updates through the realtime endpoints.
Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization flaw in the experimental agent mode Bash tool approval mechanism, which fails to properly parse shell syntax. An attacker who can influence model output through prompt injection can append control operators such as semicolons or logical operators to an approved command, executing additional shell commands and bypassing the session approval requirement.
CVE-2026-77177 affects Open GenAI Stack (aka ogx-ai) dated 2026-06-11, as used in the Meta AI backend for WhatsApp and other products. Prompt injection that carries Jinja2 template syntax can trigger server-side expression evaluation without sanitization, allowing code execution.
CVE-2026-100308 affects the model loading component in Amazon GluonTS before 0.17.0. Deserialization of untrusted data may allow context-dependent attackers to execute arbitrary operating system commands with the privileges of the loading process, via a crafted serialized model directory.
Fix: Upgrade to version 0.17.0 or later.
NVD/CVE DatabaseFix: Users on standard Claude Code auto-update have already received the fix. Users performing manual updates are advised to update to version 2.1.260 or later.
NVD/CVE Database