AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 763
- Last 90 days
- 325
- Change
- +44%vs 225 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 38 |
159 items
CVE-2026-65698: Void path traversal in AI agent file-reading tools via injected instructions
Jul 23, 2026MediumVulnerabilitySecurityCVE-2026-65698CVE-2026-65698 affects Void through 1.3.4, where the AI agent file-reading tools (read_file, ls_dir, get_dir_tree, and search_*) lack workspace confinement. A network-adjacent attacker who injects instructions into content the agent processes can supply absolute paths or file:// URIs to read arbitrary host files outside the open workspace. Because these tools bypass the approval gate, sensitive files such as SSH private keys or cloud credentials can be silently exfiltrated through subsequent tool calls.
NVD/CVE DatabaseGHSA-fpg6-x68q-5793: n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows
Jul 22, 2026MediumVulnerabilitySecurityCVE-2026-65590GHSA-fpg6-x68q-5793 affects the shell tool in the @n8n/computer-use package, which applied its sandbox restrictions only on macOS. On Linux and Windows, shell commands ran without filesystem or network restrictions, giving unrestricted access to the host from the computer-use agent process. Only deployments that explicitly install and run @n8n/computer-use are affected, not standard n8n installations.
Fix: The issue is fixed in n8n versions 2.29.8 and 2.30.1; upgrade to one of these or later. The fix adds sandbox enforcement on Linux via bubblewrap and disables the shell tool when a working sandbox cannot be established. The opt-out flag --dangerously-disable-shell-sandbox exists for deployments that require unsandboxed shell access. Temporary workarounds: avoid deploying @n8n/computer-use on Linux or Windows hosts until the fix is applied, and restrict access to the n8n instance and computer-use agent to fully trusted users. The source states these workarounds do not fully remediate the risk.
GitHub Advisory DatabaseGHSA-pf2q-pxhf-hgmw: n8n: Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory
Jul 22, 2026MediumVulnerabilitySecurityThe @n8n/computer-use file-search tool confined searches to a configured base directory. A crafted search pattern could bypass that confinement check and return the names and contents of files anywhere the daemon's OS user can read, whenever an actor could influence the tool's search input.
Fix: Fixed in n8n versions 2.31.5 and 2.32.1; upgrade to one of these or later. If upgrading is not immediately possible, restrict instance access to fully trusted users, disable or remove AI agent workflows that use the computer-use package, and run the n8n process under a dedicated low-privilege user account. These workarounds do not fully remediate the risk and are short-term measures only.
GitHub Advisory DatabaseGHSA-x5vx-c2c8-m3w9: n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool
Jul 22, 2026HighVulnerabilitySecurityCVE-2026-65015A user with the read-only Project Viewer role in n8n's AI Agents feature could escalate privileges by chatting with an agent that has node tools enabled. The run_node_tool path was authorized only by the agent:execute scope, so it ran nodes with project credentials without checking the requesting user's node-execution or credential-access rights. On instances with Execute Command or SSH enabled, this could extend to arbitrary command execution on the n8n host.
Fix: The issue is fixed in n8n versions 2.29.8 and 2.30.1; users should upgrade to one of these or later. If upgrading is not immediately possible, administrators may temporarily remove `agents` from the `N8N_ENABLED_MODULES` environment variable, restrict project membership to fully trusted users, and disable command-execution nodes such as Execute Command and SSH. The source states these workarounds do not fully remediate the risk.
GitHub Advisory DatabaseGHSA-w46p-w7w2-fr9g: Duplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool
Jul 22, 2026HighVulnerabilitySecurityThis advisory is a withdrawn duplicate of GHSA-x5vx-c2c8-m3w9. The original description states that n8n versions before 2.30.1 contain a privilege escalation flaw in the AI Agents feature, where the node-execution tool lacks proper authorization checks. A Project Viewer user can chat with an agent that has node tools enabled, execute arbitrary nodes and access credential secrets without authorization verification.
GitHub Advisory DatabaseCVE-2026-57495: AgenticMail bridge resumes privileged sessions without sender check
Jul 20, 2026HighVulnerabilitySecurityIndustryCVE-2026-57495Two inbound-mail handlers in AgenticMail's @agenticmail/claudecode, @agenticmail/codex, @agenticmail/core and @agenticmail/openclaw packages act on privileged effects without checking that the sender is the operator, unlike a sibling handler that does. The most serious path lets any external email routed to the bridge inbox resume the operator's Claude Code session with `permissionMode: 'bypassPermissions'`, embedding attacker-controlled `from`, `subject` and `preview` fields into the prompt the agent reads.
Fix: Fixed in @agenticmail/claudecode 0.2.39, @agenticmail/codex 0.1.33, @agenticmail/core 0.9.43 and @agenticmail/openclaw 0.5.71.
NVD/CVE DatabaseCVE-2026-57494: AgenticMail cross-agent task access through pending task enumeration
Jul 20, 2026HighVulnerabilitySecurityCVE-2026-57494CVE-2026-57494 affects @agenticmail/api before version 0.9.64. A low-privileged authenticated agent can list another agent's pending and claimed tasks through GET /api/agenticmail/tasks/pending?assignee=<name>, which returns task IDs and payloads. Those IDs can then be used on the /tasks/:id/claim, /result, /complete and /fail endpoints to act on tasks assigned to a different agent, because agent names are discoverable via GET /api/agenticmail/accounts/directory.
Fix: Fixed in 0.9.64.
NVD/CVE DatabaseCVE-2026-47255: AgenticMail API and core flaws in storage SQL validation and SMTP handling
Jul 20, 2026HighVulnerabilitySecurityIndustryCVE-2026-47255CVE-2026-47255 affects @agenticmail/api before 0.9.32 and @agenticmail/core before 0.9.10, which give AI agents real email addresses and phone numbers. The source describes several weaknesses in these packages, including inactive-agent hour filtering, storage SQL identifier validation, metadata-backed ownership checks for raw storage SQL, and SMTP envelope/header control-character validation. It also notes that TLS certificate verification for MailSender was not the default before the fix.
Fix: @agenticmail/api 0.9.32 and @agenticmail/core 0.9.10 are patched.
NVD/CVE DatabaseCVE-2026-58195: Agentic-Flow MCP server tools command execution through shell interpolation
Jul 17, 2026HighVulnerabilitySecurityCVE-2026-58195Agentic-Flow, an AI agent orchestration platform, is affected in versions prior to 2.0.14. Several MCP server tool files interpolate attacker-influenceable parameters such as agent, task, name, language and agentdb directly into shell command strings passed to execSync(). This allows arbitrary OS command execution with the privileges of the MCP server user.
Fix: This issue is fixed in version 2.0.14.
NVD/CVE DatabaseCVE-2026-15737: AWS Bedrock AgentCore Python SDK logs sensitive prompts and responses in spans
Jul 16, 2026MediumVulnerabilitySecurityPrivacyCVE-2026-15737CVE-2026-15737 affects the OpenTelemetry instrumentation in the AWS Bedrock AgentCore Python SDK, versions 1.4.8 and 1.5.0. The SDK wrote raw user prompts and complete agent responses into span attributes on every invocation, without filtering or masking. A local authenticated user with read access to CloudWatch Logs can view that sensitive content in the customer's aws/spans log group.
Fix: Upgrade to version 1.5.1 or later. Users who ran affected versions should also review and purge sensitive content from their aws/spans CloudWatch log groups.
NVD/CVE DatabaseCVE-2026-15746: Strands Agents elasticsearch_memory tool SSRF exposing Elasticsearch API key
Jul 15, 2026MediumVulnerabilitySecurityCVE-2026-15746CVE-2026-15746 is a server-side request forgery (SSRF) issue in the elasticsearch_memory tool of the strands-agents-tools package, which ships with the Strands Agents Python SDK. The tool exposed es_url, cloud_id and api_key as fields the LLM could control through the tool schema. When api_key was omitted, the tool fell back to the operator's ELASTICSEARCH_API_KEY environment variable and sent it to a host the LLM specified, so a crafted prompt could leak that key to an attacker-controlled server in the Authorization header.
Fix: Upgrade strands-agents-tools to version 0.7.0 or later. As a precaution, rotate ELASTICSEARCH_API_KEY, even without evidence that it was exposed.
NVD/CVE DatabaseCVE-2026-13237: Drupal AI Agents incorrect authorization allows forceful browsing
Jul 10, 2026MediumVulnerabilitySecurityCVE-2026-13237CVE-2026-13237 is an Incorrect Authorization flaw (CWE-863) in Drupal AI Agents that allows Forceful Browsing. The issue affects AI Agents versions 0.0.0 to 1.1.4, 1.2.0 to 1.2.5, and 1.3.0 to 1.3.1. NVD has not yet provided an assessment, and the vulnerability was published by Drupal.org on 07/10/2026.
NVD/CVE DatabaseCVE-2026-13236: Drupal AI Agents missing authorization allows forceful browsing
Jul 10, 2026MediumVulnerabilitySecurityCVE-2026-13236CVE-2026-13236 is a Missing Authorization flaw (CWE-862) in Drupal AI Agents that allows Forceful Browsing. It affects versions 0.0.0 through 1.1.4, 1.2.0 through 1.2.5, and 1.3.0 through 1.3.1. NVD has not yet provided an assessment, and the flaw was published 07/10/2026 by Drupal.org.
NVD/CVE DatabaseCVE-2026-59207: n8n AI Agents MCP tool ignores credential HTTP domain restriction
Jul 9, 2026HighVulnerabilitySecurityCVE-2026-59207CVE-2026-59207 is a vulnerability in n8n, an open source workflow automation platform, affecting versions before 2.27.4 and 2.28.1. The AI Agents feature did not enforce the Allowed HTTP Request Domains restriction configured on credentials when an MCP tool was pointed at an arbitrary URL. A member-level user with use-only access to a shared credential could send its secret to an external server they control.
Fix: This issue is fixed in versions 2.27.4 and 2.28.1.
NVD/CVE DatabaseCVE-2026-44934: SUSE Rancher AI Agent information disclosure in DEBUG loglevel logs
Jul 6, 2026HighVulnerabilitySecurityPrivacyCVE-2026-44934CVE-2026-44934 is an information disclosure flaw in SUSE Rancher AI Agent 1.0 before 1.0.2. When the DEBUG loglevel is set, API keys or LLM response text, which may contain sensitive data, are written to log files. A local attacker who can read those logs could misuse the exposed data or credentials. SUSE rates it CVSS 4.0 7.0 (HIGH), and NVD has not yet provided an assessment.
NVD/CVE DatabaseCVE-2026-13437: Devolutions PowerShell Universal leaks App Tokens in AI Agent job API responses
Jun 29, 2026MediumVulnerabilitySecurityCVE-2026-13437CVE-2026-13437 affects the AI Agent job API in Devolutions PowerShell Universal 2026.2.0. An authenticated user with AI Agent read access can obtain App Tokens, which are serialized in plaintext in job API responses, and these tokens are reusable and may carry higher privileges than the user's own. The weakness is classified as CWE-201, Insertion of Sensitive Information Into Sent Data.
NVD/CVE DatabaseCVE-2026-55607: Claude Code worktree handling allows sandbox escape via git directory confusion
Jun 29, 2026HighVulnerabilitySecurityCVE-2026-55607Claude Code versions 2.1.38 through 2.1.163 allowed creation of worktrees named ".git" and navigation to worktrees outside the sandbox context, enabling git directory confusion attacks. Through symlink manipulation and git fsmonitor execution during worktree operations, an attacker could overwrite files such as .zshenv in the user's home directory, leading to code execution outside seatbelt sandbox restrictions. Reliable exploitation required the user to clone a malicious repository containing prompt injection content and run Claude Code against it.
Fix: Fixed in 2.1.163.
NVD/CVE DatabaseGHSA-vcv2-r9jh-99m5: Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSync
Jun 19, 2026HighVulnerabilitySecurityagentic-flow versions <= 2.0.13 interpolated MCP tool parameters such as agent, task, name, language and agentdb arguments directly into shell command strings passed to execSync(). A malicious value can break out of the double-quoted argument and run arbitrary OS commands with the privileges of the user running the MCP server. The HTTP/SSE transports expose the same sinks without authentication or Origin/Host validation.
Fix: Fixed in agentic-flow@2.0.14, which rewrites every affected call site to use execFileSync(file, argv, { shell: false }). Upgrade to agentic-flow >= 2.0.14. There is no in-product configuration that mitigates this without upgrading.
GitHub Advisory DatabaseCVE-2026-50287: AgenticMail MCP server missing authentication on HTTP /mcp endpoint
Jun 12, 2026HighVulnerabilitySecurityCVE-2026-50287CVE-2026-50287 affects @agenticmail/mcp before version 0.9.27 when started with --http or MCP_HTTP=1, which enables a Streamable HTTP transport. The /mcp endpoint accepts requests without any HTTP authentication layer, so a remote client can initialize a session and call tools directly. GitHub, Inc. rates it CVSS-B 8.7 HIGH (CVSS:4.0), with high confidentiality impact and no privileges or user interaction required.
Fix: Fixed in version 0.9.27.
NVD/CVE DatabaseCVE-2026-44287: FastGPT JavaScript sandbox code execution via dynamic import bypass
May 29, 2026MediumVulnerabilitySecurityCVE-2026-44287CVE-2026-44287 affects FastGPT, an AI Agent building platform, before 4.15.0-beta1. The JavaScript sandbox worker at projects/code-sandbox/src/pool/worker.ts:356 blocks dynamic import() with the regex /\bimport\s*\(/.test(code), which misses a block comment placed between import and (, such as import/**/("child_process"). Because import() is not wrapped by the safeRequire Proxy, which only proxies require, an attacker can load child_process and call execSync to run arbitrary commands as uid=100(sandbox) inside the sandbox container.
Fix: Fixed in 4.15.0-beta1.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.