Advisories
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
83 items
Astron Agent, an agentic workflow platform, prior to 1.1.2 defaults its workflow code-node path (/console-api/workflow/code/run and /workflow/v1/run) to LocalExecutor in core/workflow/engine/nodes/code/code_node.py unless CODE_EXEC_TYPE is changed. LocalExecutor exposes full Python builtins to dynamic code without the documented sandbox restrictions. An authenticated low-privilege tenant can run code as root in the core-workflow container and use shared credentials to bypass tenant checks, read or modify other tenants' data, and disrupt shared services.
Fix: This issue is fixed in version 1.1.2.
NVD/CVE DatabaseThe AICoder UI component in PraisonAI exposes write_to_file and execute_command tools to the LLM without path validation or command sanitization. Through prompt injection in the chat interface, an attacker can write to arbitrary filesystem locations, such as /root/.ssh/authorized_keys or /etc/crontab, and execute arbitrary shell commands. Docker containers run as root, which increases the impact.
Ollama's /api/pull endpoint is vulnerable to path traversal because the digestToPath function does not sufficiently validate layer digests. An unauthenticated remote attacker can supply a traversal sequence as a layer digest to write a malicious binary outside the model store. Where the server process can write to /usr/lib/ollama, the file is loaded and executed on the next restart, giving remote code execution as root.
Fixed in version 0.35.0.
Flowise versions 3.1.2 and earlier (packages flowise and flowise-components) contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An authenticated user with access to the /api/v1/node-custom-function endpoint can supply attacker-controlled executablePath and args to puppeteer.launch(), which invokes child_process.spawn() outside the sandbox, enabling arbitrary OS command execution as the Flowise process user (root in the official Docker image) and arbitrary host file disclosure via Chromium's file:// handling. Versions 3.0.8 to 3.1.2 require ALLOW_BUILTIN_DEP=true for exploitation; earlier versions are exploitable by default.
IBM Langflow OSS versions 1.0.0 through 1.12.2 contain a flaw, tracked as CVE-2026-93674, caused by improper neutralization of special elements used in an OS command. A remote attacker could exploit it to execute arbitrary code.
IBM Langflow OSS versions 1.0.0 through 1.12.2 contain a flaw, tracked as CVE-2026-104334, caused by improper control of code generation. A remote attacker could exploit it to execute arbitrary code.
Langflow's PythonREPLComponent and legacy PythonREPLToolComponent executed user- or model-supplied Python without effective sandboxing, so any authenticated user who could run a flow could gain code execution with the service's privileges and escalate to superuser by flipping is_superuser in the database. The root cause is CWE-94/CWE-95, with unrestricted builtins exposed even under the default allow_custom_components=True setting. Affected versions are below 1.10.1.
Upgrade langflow to 1.10.1 or later, preferably 1.12.3 or later. The fix adds restricted builtins via safe_builtins(), AST validation in validate_code_safety(), and a server-policy gate in ensure_code_execution_enabled() that refuses execution when allow_custom_components=False or block_code_interpreter_components=True.
CVE-2026-105740 affects Langflow versions prior to 1.9.0. Any authenticated user can add an MCP server with the "Stdio" transport, and the user-supplied command field is passed directly to bash -c "exec {command}" with no validation, allowlisting, or sandboxing, so the command runs on the server as soon as the server list is fetched. The env field also permits arbitrary environment variable injection, such as LD_PRELOAD or a PATH override.
Fixed in 1.9.0.
CVE-2026-105697 affects Langflow before 1.10.3, where the MCP stdio transport ran whatever command and args a user placed in an MCP server configuration, with no allowlist and, before 1.10.3, wrapped in bash -c "exec {command} ...". Any user who can reach the MCP server settings (POST/PATCH /api/v2/mcp/servers/{server_name}) or build a flow with the MCP Tools component can run an arbitrary OS command on the Langflow host as the Langflow process user, when Langflow connects to the server, even if the UI then reports a startup failure. With the default LANGFLOW_AUTO_LOGIN=true, GET /api/v1/auto_login issues a token without credentials, so the flaw is reachable without an account on an exposed default instance; with AUTO_LOGIN disabled, any authenticated non-admin user can exploit it.
The AgentOS server in the praisonai TypeScript/npm package ships with defaults that bind 0.0.0.0, leave the API key empty, and use wildcard CORS with credentials. Because the auth middleware is only registered when an apiKey is set, the documented quickstart exposes GET /api/agents, which returns agent names, roles and instructions, and POST /api/chat, which invokes agents, to any network peer without authentication. The advisory is rated High and was confirmed at runtime.
PraisonAI's shell command hardening, shipped in npm 1.7.2 and Python 4.6.58 to fix GHSA-5jv7-2mjm-h6qj and GHSA-vjv9-7m7j-h833, can be bypassed through find's built-in -exec action. The fix blocks shell metacharacters and uses spawn() with shell: false, but find stays in the safe command allowlist, and the batch terminator + replaces the blocked ; so commands run without metacharacters. The same gap exists in four implementations, including the TS shell() tool and the Python safe_shell module, and a find -execdir payload reads /etc/passwd while evading the SandboxExecutor path check.
PraisonAI 4.6.63's MCP HTTP-stream server applies authentication only when an API key is set, and the CLI defaults `--api-key` to `None`, so `praisonai mcp serve --transport http-stream` exposes the full MCP surface without authentication. An unauthenticated client can call `initialize` and `tools/list` (about 50 tools), and the dispatcher in `mcp_server/server.py` forwards tool-call arguments to handlers without validating them against the advertised `inputSchema`. The source states this is not an RCE or file read in 4.6.63, because `workflow.run` and `workflow.run_file` fail at runtime.
PraisonAI's Async Jobs API enables API-key middleware only when PRAISONAI_JOBS_API_KEY is set, so all endpoints are unauthenticated by default. An unauthenticated POST /api/v1/runs accepts an attacker-controlled webhook_url, and the server POSTs job payloads to it via httpx, with a DNS-rebinding bypass of the request-time SSRF check that reaches internal services as a blind SSRF.
Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read returned data together with an error, affected handlers forwarded unmasked bytes. Code inside an authorized sandbox could use this to recover host-managed OAuth access and refresh tokens, or a derived Anthropic API key, that were meant to stay outside the sandbox.
The Pydantic AI development web chat UI (`Agent.to_web()`, `clai web`) did not check the content type of requests to its chat endpoint. A website visited by a developer could submit a request to the chat UI on that developer's machine, causing the served agent to run and execute its tools with the privileges and credentials of the local process, including tools marked `requires_approval=True`, because the endpoint trusts approval decisions relayed by the client.
PraisonAI's SkillTools.run_skill_script() accepts a script_path parameter and executes it via subprocess.run() with no path containment validation, unlike FileTools._validate_path(). An LLM-directed call can therefore run arbitrary scripts from any filesystem location, and the @require_approval decorator can be bypassed via YAML approve: for high-risk tools. Chaining with write_file lets an attacker plant and then execute a script, and because PraisonAI Docker containers run as root, an executed script gains root privileges.
Pydantic AI versions 2.10.0 through 2.53.0 have a flaw in streamed requests made through ConcurrencyLimitedModel or limit_model_concurrency. Because anyio.CapacityLimiter ties an acquired slot to the borrowing task while streaming cleanup can run in a different task, early termination, cancellation, consumer exceptions, or complete stream_text() consumption with debounce_by=0.1 can leave shared concurrency slots occupied. Later requests on the long-lived limiter can then be blocked, causing a denial of service. Agent-level max_concurrency and non-streaming model requests are not affected.
CVE-2026-82627 affects The Uncanny Automator AI + Automation plugin for WordPress in all versions up to and including 7.6.1.1. The flaw is PHP Object Injection via deserialization of untrusted input, which lets an authenticated user with Subscriber-level access or higher inject a PHP object when a third-party integration plugin such as PeepSo, MailPoet or WPForms is installed and a recipe stores attacker-controlled data as trigger meta. A POP chain within Uncanny Automator allows the attacker to delete arbitrary files on the server.
Claude Code checked that a target file path was inside the project working directory at permission-check time, but re-resolved the path at write time without repeating the check. An attacker with write access to the shared workspace who could win a race condition could atomically replace a project file with a symlink, redirecting Claude Code's output to an arbitrary file outside the project sandbox. The flaw let a lower-privileged attacker redirect benign edits to sensitive files, such as shell configuration, in a higher-privileged session.
IBM Langflow OSS versions 1.0.0 through 1.12.2 contain a flaw that allows a remote, authenticated attacker to execute arbitrary OS commands. The flaw stems from improper neutralization of special elements used in an OS command, classified as 'Code Injection' and described as improper control of code generation.
Fix: Fixed in 3.1.3.
GitHub Advisory DatabaseFix: Fixed in Langflow 1.10.3, langflow-base 0.10.3, and lfx 1.10.3.
NVD/CVE DatabaseFix: Upgrade to a patched version. The chat endpoint now requires `Content-Type: application/json` and rejects other requests before the request body is parsed and before the agent runs. Scripts and other non-browser clients calling the endpoint directly may need to send this header. If you cannot upgrade, don't run the web UI while browsing untrusted sites, stop it when not in use, and don't serve an agent with side-effecting tools through it.
Fix: Fixed in version 2.53.0.
Fix: Users on standard Claude Code auto-update have already received the fix. Users performing manual updates are advised to update to the latest version.