AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 763
- Last 90 days
- 325
- Change
- +44%vs 225 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 38 |
159 items
CVE-2026-84779: Agentimus AI SEO, llms.txt & MCP for AI Agents broken access control
Sep 3, 2026HighVulnerabilitySecurityCVE-2026-84779CVE-2026-84779 is a Subscriber Broken Access Control flaw in Agentimus – AI SEO, llms.txt & MCP for AI Agents, affecting versions up to and including 1.51.0. The source text provides no further detail on how the flaw is reached or what an attacker gains.
NVD/CVE DatabaseCVE-2026-54746: Hatchet Dispatcher gRPC allows cross-tenant worker label overwrite
Aug 28, 2026MediumVulnerabilitySecurityCVE-2026-54746CVE-2026-54746 affects Hatchet from 0.40.0 through 0.91.1. The Dispatcher gRPC service fails to check that a worker ID in Dispatcher/UpsertWorkerLabels and Dispatcher/Unsubscribe belongs to the tenant in the bearer-token context. An authenticated tenant owner who guesses another tenant's worker UUID can overwrite that worker's affinity labels or disconnect it, causing cross-tenant integrity impact and denial of service on multi-tenant or shared deployments. Single-tenant deployments are not practically affected.
Fix: Fixed in 0.91.1.
NVD/CVE DatabaseCVE-2026-62677: Omnigent path traversal through session agent bundle os_env.cwd value
Aug 21, 2026HighVulnerabilitySecurityCVE-2026-62677Omnigent, an open-source AI agent framework and meta-harness for orchestrating coding agents, is affected by CVE-2026-62677 in versions prior to 0.3.0. An authenticated user can upload a session-scoped agent bundle with an absolute or traversal-containing os_env.cwd value, which the parser and validator store without constraint. When OMNIGENT_RUNNER_WORKSPACE is unset, the attacker-controlled path becomes the trusted root, letting sys_os_read, write, edit and shell tools reach runner files and environment secrets outside the intended workspace.
Fix: Fixed in 0.3.0.
NVD/CVE DatabaseCVE-2026-62676: Omnigent shell parser bypass lets agents evade git push and workspace policies
Aug 21, 2026HighVulnerabilitySecurityCVE-2026-62676Omnigent, an open-source AI agent framework and meta-harness for orchestrating coding agents, has a flaw in its shared shell-command parser (omnigent/policies/builtins/_shell.py) before version 0.3.0. The parser does not recognize combined interpreter flags, the timeout, nice, setsid, and stdbuf wrappers, command substitutions, or a single background control operator. A gated git push or gh write hidden in these forms yields no parsed operation, so the github.py write_repos and write_branches allowlist and the working_dir.py workspace confinement policies abstain and allow the command. An authenticated or prompt-injected agent can therefore push to an unauthorized repository or branch or escape the intended workspace (CVE-2026-62676).
Fix: Fixed in version 0.3.0.
NVD/CVE DatabaseCVE-2026-62675: Omnigent arbitrary command execution through agent bundle tools callable
Aug 21, 2026HighVulnerabilitySecurityCVE-2026-62675CVE-2026-62675 affects Omnigent, an open-source AI agent framework and meta-harness, before version 0.3.0. An authenticated user can submit an agent bundle to POST /v1/sessions, and validate_agent_bundle in omnigent/server/bundles.py fails to reject a tools..callable dotted Python path, so the bundle can select subprocess.check_output and run a local command with the runner process permissions. This can expose runner files, environment variables, credentials, workspace data, internal services, and availability without administrator access.
Fix: Fixed in 0.3.0.
NVD/CVE DatabaseCVE-2026-62674: Omnigent shared agent replacement enables command execution via MCP
Aug 21, 2026CriticalVulnerabilitySecurityCVE-2026-62674CVE-2026-62674 affects Omnigent, an open-source AI agent framework and meta-harness, before version 0.3.0. The PUT /sessions/{session_id}/agent endpoint checks LEVEL_EDIT permission but does not reject a bound shared or template agent whose agent.session_id is None. An authenticated user with edit access to a session can replace that shared agent bundle, add a stdio MCP server, and cause later sessions using the shared agent to run an attacker-controlled command with the Omnigent runner's permissions, exposing files, credentials, workspace data, internal services, and runner availability.
Fix: Fixed in version 0.3.0.
NVD/CVE DatabaseCVE-2026-17153: AI Agent by SiteGround WordPress plugin authorization bypass in image uploads
Aug 20, 2026MediumVulnerabilitySecurityCVE-2026-17153The AI Agent by SiteGround plugin for WordPress contains an authorization bypass in all versions up to and including 1.2.7. The plugin does not verify that a user is authorized to perform an action, so unauthenticated attackers can upload images to the WordPress media library. This bypasses the upload_files capability that normally restricts Contributors. The sg_ai_studio_gutenberg_nonce required by the endpoint is issued to any user with block editor access, so the missing upload_files check is the only remaining barrier.
NVD/CVE DatabaseCVE-2026-50143: Apify MCP server token exposure through Actor MCP server URL redirect
Aug 18, 2026HighVulnerabilitySecurityCVE-2026-50143The Apify MCP server, prior to version 0.10.11, builds the Actor MCP server URL in getActorMCPServerURL (src/mcp/actors.ts) by concatenating the trusted Actor standby URL with the attacker-controlled webServerMcpPath from an Actor definition, without checking the resulting origin. A malicious Actor publisher can use a userinfo-style authority value to redirect connectMCPClient to a third-party host. The call-actor, fetch-actor-details, and actor-mcp paths then send the victim's Authorization bearer token, exposing the Apify API token and granting access to Actors, stored data, and billable compute. Exploitation requires that a victim invoke or inspect the attacker-controlled Actor.
Fix: Fixed in 0.10.11.
NVD/CVE DatabaseCVE-2026-75110: MemOS authentication bypass via unset internal service secret
Aug 17, 2026CriticalVulnerabilitySecurityCVE-2026-75110MemOS, a memory operating system for LLMs and AI agents, has an authentication bypass when AUTH_ENABLED=true but the INTERNAL_SERVICE_SECRET environment variable is unset. The is_internal_request() check in src/memos/api/middleware/auth.py then compares None to None, which evaluates true, so an unauthenticated remote attacker is treated as an internal principal with scopes ["all"]. This grants access to admin API-key management endpoints (minting, enumerating, revoking keys, and generating a master key) and to all data endpoints.
NVD/CVE DatabaseCVE-2026-73658: Trigger.dev object store presigned URL path traversal via packet API
Aug 13, 2026HighVulnerabilitySecurityCVE-2026-73658Trigger.dev versions from 4.4.2 through 4.5.0-rc.5 let a caller with a valid environment API key obtain presigned URLs for another tenant's object-store keys. The flaw arises because user-controlled packet keys are assigned to URL.pathname without rejecting dot segments, and the packets route performs no per-resource ownership validation. WHATWG path normalization collapses .. segments before signing, so an attacker can read or overwrite another tenant's task payloads.
Fix: Fixed in 4.5.0-rc.5.
NVD/CVE DatabaseCVE-2026-73657: Trigger.dev run replay lets any environment key replay other tenants' runs
Aug 13, 2026MediumVulnerabilitySecurityIndustryCVE-2026-73657Trigger.dev versions from 4.4.2 until 4.5.0-rc.4 contain a flaw in `POST /api/v1/runs/:runParam/replay`. The route looks up runs by friendlyId without a runtimeEnvironmentId filter, so any valid environment API key can replay another tenant's run. This consumes victim resources and repeats side effects. When `payloadType: "application/store"` is used, `overrideExistingPayloadPacket()` imports payload bytes without an integrity check, which can make bytes altered through a separate object-store path-traversal flaw into attacker-controlled input for the victim task.
Fix: Fixed in version 4.5.0-rc.4.
NVD/CVE DatabaseCVE-2026-73656: Trigger.dev deployment lookup without environment check via workers API
Aug 13, 2026CriticalVulnerabilitySecurityCVE-2026-73656Trigger.dev versions prior to 4.5.6 fail to scope a deployment lookup to the caller's environment. In POST /api/v1/deployments/:deploymentId/background-workers, workerDeployment.findFirst() selects by friendlyId without an environmentId predicate. A caller with a valid API key for one project can submit another project's deployment identifier, link an attacker-owned background worker to it, and move that deployment from BUILDING to DEPLOYING.
Fix: Fixed in 4.5.6.
NVD/CVE DatabaseCVE-2026-73655: Trigger.dev Google sign-in account takeover via unverified email
Aug 13, 2026HighVulnerabilitySecurityIndustryCVE-2026-73655Trigger.dev versions prior to 4.5.2 contain an account takeover flaw in the Google sign-in flow. The function addGoogleStrategy() in apps/webapp/app/services/googleAuth.server.ts passes a Google profile email to findOrCreateGoogleUser() without checking Google's email_verified assertion. An attacker can use a Google profile with an unverified matching email to attach their Google authIdentifier to an existing email-matched account and log in as that user.
Fix: Fixed in 4.5.2.
NVD/CVE DatabaseCVE-2026-73654: Trigger.dev prototype pollution in run metadata endpoint
Aug 13, 2026HighVulnerabilitySecurityCVE-2026-73654CVE-2026-73654 affects Trigger.dev from 3.3.8 until 4.5.6. The PUT /api/v1/runs/:runId/metadata endpoint passes attacker-controlled operation.key values to new JSONHeroPath(operation.key).set() in packages/core/src/v3/runMetadata/operations.ts without rejecting constructor and prototype path segments. A caller with a normal environment API key can pollute Object.prototype in the shared webapp process, corrupting Prisma queries and Prometheus labels, breaking other tenants' worker authentication, and causing a process-wide denial of service.
Fix: Fixed in version 4.5.6.
NVD/CVE DatabaseCVE-2026-49856: @jshookmcp/jshook SSRF policy bypass through ICMP probe and traceroute tools
Aug 13, 2026MediumVulnerabilitySecurityCVE-2026-49856@jshookmcp/jshook, an MCP server giving AI agents JavaScript analysis tools, has a flaw in version 0.3.1 where the ICMP probe and traceroute tools bypass the central SSRF authorization policy that the raw HTTP, TCP and TLS RTT tools enforce. An MCP client with access to an active network domain can make the server probe internal addresses, even when local SSRF access is disabled, exposing internal reachability and route mapping from the server's network position.
Fix: Fixed in 0.3.2.
NVD/CVE DatabaseCVE-2026-72718: goose review command execution through malicious repository git config
Aug 10, 2026HighVulnerabilitySecurityCVE-2026-72718goose versions before 1.44.0 run the system git executable in the `goose review` command to gather diffs without stripping attacker-controlled Git configuration. A malicious repository whose .git/config sets core fsmonitor to a command causes Git to execute that command on the host during `git diff HEAD`, before any model call or trust prompt, with the privileges of the user running goose. The affected invocations are built by git_command() in crates/goose-cli/src/commands/review/handler.rs.
Fix: Fixed in 1.44.0.
NVD/CVE DatabaseCVE-2026-9196: IBM Langflow OSS code execution during Agentic Assistant validation
Aug 5, 2026HighVulnerabilitySecurityCVE-2026-9196CVE-2026-9196 affects IBM Langflow OSS 1.0.0 through 1.10.3. An authenticated attacker can execute unintended code during Agentic Assistant validation, because the application runs model-generated Python code in the backend before user approval. The source says this may allow side effects such as outbound network access, file system interaction, or data exfiltration with the privileges of the Langflow backend process. The weakness is classified as CWE-94, Improper Control of Generation of Code ('Code Injection').
NVD/CVE DatabaseCVE-2026-66065: Ouroboros arbitrary command execution through untrusted project .env keys
Aug 3, 2026HighVulnerabilitySecurityCVE-2026-66065Versions of Ouroboros, a local-first runtime for AI coding agents, prior to 0.42.1 ship an incomplete denylist of untrusted .env keys. A malicious cloned repository can include a .env file that is auto-loaded at import with no review step, letting an attacker reach arbitrary command execution. The earlier CVE-2026-47211 fix added _UNTRUSTED_ENV_DENYLIST for project-directory .env files but missed several keys. Other variables let attackers redirect the backend config-home and MCP/plugin roots past the approval gate, re-enable blocked local transports, replace sub-agent prompts, and lower tool approval classes.
Fix: Fixed in 0.42.1.
NVD/CVE DatabaseCVE-2026-65975: Pydantic AI UI adapters execute unresolved tool calls from client history
Jul 29, 2026MediumVulnerabilitySecurityCVE-2026-65975Pydantic AI versions 1.88.0 up to 1.107.1 and 2.0.0b1 up to 2.5.0 have a flaw in the UI adapters (AG-UI via Agent.to_ag_ui()/AGUIAdapter, and VercelAIAdapter). When a trailing client message sanitizes to empty and is dropped, as with a client system message under manage_system_prompt='server', an assistant response with an unresolved tool call is dispatched without inspection. A remote client can thereby run a registered, non-approval server tool with client-supplied arguments. Applications that gate tools in before_model_request or after_model_request are most affected, since forged calls skip that guardrail; requires_approval=True tools are not auto-executed by this path.
Fix: Fixed in 1.107.1 and 2.5.0.
NVD/CVE DatabaseCVE-2026-54249: Pydantic AI UI adapters forward unvalidated UploadedFile references
Jul 29, 2026MediumVulnerabilitySecurityCVE-2026-54249Pydantic AI versions 1.65.0 through 1.105.0, and 2.0.0b1 through 2.0.0b5, do not validate UploadedFile references in message history submitted to UI adapters such as the Vercel AI adapter. A client can supply a provider file ID or cloud-storage URI (for example s3:// or gs://), and the provider resolves it with the server's own identity, letting an attacker read objects the server can access, including other tenants' objects. Exploitation requires a valid file identifier, which may be guessable depending on how the application names objects.
Fix: Fixed in 1.106.0 and 2.0.0b6.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.