AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 764
- Last 90 days
- 324
- Change
- +43%vs 227 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 39 |
764 items
v5.4.0
Feb 5, 2026MediumResearchIndustrySecurityResearchThe v5.4.0 release of the framework adds four new techniques, including Publish Poisoned AI Agent Tool and User Execution: Poisoned AI Agent Tool, along with Escape to Host and Exploitation for Credential Access. It also updates the Modify AI Agent Configuration technique and adds four case studies covering exposed ClawdBot control interfaces, a poisoned ClawdBot skill supply chain compromise, a 1-click remote code execution in OpenClaw, and command and control via prompt injection in OpenClaw.
MITRE ATLAS ReleasesAgentic AI Site 'Moltbook' Is Riddled With Security Risks
Feb 5, 2026MediumNewsSecurityIndustryA platform called Moltbook, built entirely with AI, exposed all of its data through a publicly accessible API. The article describes this as a predictable and preventable outcome.
Dark ReadingCVE-2026-24887: Claude Code confirmation prompt bypass via find command
Feb 3, 2026HighVulnerabilitySecurityCVE-2026-24887CVE-2026-24887 affects Claude Code, an agentic coding tool, prior to version 2.0.72. A command parsing error let an attacker bypass the confirmation prompt and run untrusted commands through the find command. Exploitation reliably required the ability to add untrusted content into the Claude Code context window.
Fix: Fixed in version 2.0.72.
NVD/CVE DatabaseCVE-2026-24053: Claude Code Bash validation flaw in ZSH clobber syntax allows file writes
Feb 3, 2026MediumVulnerabilitySecurityCVE-2026-24053CVE-2026-24053 affects Claude Code prior to version 2.0.74. A Bash command validation flaw in parsing ZSH clobber syntax let an attacker bypass directory restrictions and write files outside the current working directory without user permission prompts. Exploitation required the user to run ZSH and the ability to add untrusted content into a Claude Code context window.
Fix: Fixed in version 2.0.74.
NVD/CVE DatabaseCVE-2026-24052: Claude Code WebFetch trusted domain check bypass via startsWith validation
Feb 3, 2026HighVulnerabilitySecurityCVE-2026-24052CVE-2026-24052 affects Claude Code before version 1.0.111. Its trusted domain check for WebFetch requests used startsWith(), so a domain such as modelcontextprotocol.io.example.com passed validation as if it were modelcontextprotocol.io. This could let an attacker trigger automatic requests to attacker-controlled domains without user consent, potentially leading to data exfiltration.
Fix: Fixed in version 1.0.111.
NVD/CVE Databasev5.2.0
Jan 30, 2026InfoResearchIndustryResearchSecurityMITRE ATLAS released v5.2.0, which adds new techniques such as AI Service API, Virtualization/Sandbox Evasion, AI Agent Tool Credential Harvesting, AI Agent Tool Data Poisoning, AI Agent Clickbait, Data Destruction via AI Agent Tool Invocation, and Generate Malicious Commands. The release also adds mitigations including Segmentation of AI Agent Components, Input and Output Validation for AI Agent Components, and Deepfake Detection, and adds case studies including SesameOp, Malware Prototype with Embedded Prompt Injection, and LAMEHUG.
Fix: Added mitigations include Segmentation of AI Agent Components, Input and Output Validation for AI Agent Components, and Deepfake Detection. Updated mitigations include Limit Public Release of Information, Model Hardening, Restrict Number of AI Model Queries, Privileged AI Agent Permissions Configuration, AI Agent Tools Permissions Configuration, Human In-the-Loop for AI Agent Actions, and Restrict AI Agent Tool Invocation on Untrusted Data, among others.
MITRE ATLAS Releases2026: The Year Agentic AI Becomes the Attack-Surface Poster Child
Jan 30, 2026InfoNewsSecurityIndustryDark Reading asked its readers which of four security trends would most likely become a reality in 2026. The options were agentic AI attacks, advanced deepfake threats, board recognition of cyber as a top priority, and password-less technology adoption.
Dark ReadingBuilding Trustworthy AI Agents
Jan 30, 2026InfoResearchPeer-reviewedSafetyIndustryThe article argues that personal AI assistants depend on an unfounded assumption that users can trust systems that are not yet trustworthy. It says current assistants fail predictably: they push users against their own interests, cast doubt on what users know, and cannot separate a user's present self from their past. It also states they handle incomplete, inaccurate, and partial context poorly, with no standard way to improve accuracy, correct error sources, or hold them accountable for wrong information.
IEEE Xplore (Security & AI Journals)CVE-2025-13374: Kalrav AI Agent WordPress plugin arbitrary file upload via kalrav_upload_file
Jan 24, 2026CriticalVulnerabilitySecurityCVE-2025-13374The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to and including 2.3.3. The flaw is missing file type validation in the kalrav_upload_file AJAX action, and unauthenticated attackers can exploit it. The source states this may make remote code execution possible on the affected site's server.
NVD/CVE DatabaseCVE-2026-24399: ChatterMate client-side injection through iframe javascript URI in chat input
Jan 23, 2026CriticalVulnerabilitySecurityCVE-2026-24399ChatterMate, a no-code AI chatbot agent framework, versions 1.0.8 and below, accepts and executes malicious HTML/JavaScript supplied as chat input. An iframe payload containing a javascript: URI runs in the browser context, exposing client-side data such as localStorage tokens and cookies. The flaw is tracked as CVE-2026-24399 under CWE-79.
Fix: Fixed in version 1.0.9.
NVD/CVE DatabaseCVE-2026-21852: Claude Code project-load flow leaks API keys before trust prompt
Jan 21, 2026HighVulnerabilitySecurityCVE-2026-21852EPSS: 27.9%Prior to version 2.0.65, Claude Code's project-load flow let a malicious repository exfiltrate data, including Anthropic API keys, before the user confirmed trust. A repository settings file could set ANTHROPIC_BASE_URL to an attacker-controlled endpoint, and Claude Code issued API requests on opening the repository, before the trust prompt appeared.
Fix: Fixed in 2.0.65, which contains a patch. Users on standard auto-update have already received the fix; users performing manual updates should update to version 2.0.65 or the latest version.
NVD/CVE DatabaseCVE-2026-22686: Enclave VM sandbox escape via host Error object prototype chain
Jan 13, 2026CriticalVulnerabilitySecurityCVE-2026-22686CVE-2026-22686 affects enclave-vm, the sandbox component of Enclave, in versions prior to 2.7.0. When a tool invocation fails, enclave-vm passes a host-side Error object into sandboxed code, and that object keeps its host realm prototype chain. Untrusted code can walk that chain to the host Function constructor and run arbitrary JavaScript in the host Node.js runtime, reaching process.env, the filesystem and the network.
Fix: Fixed in 2.7.0.
NVD/CVE DatabaseLack of isolation in agentic browsers resurfaces old vulnerabilities
Jan 13, 2026MediumNewsSecuritySafetyResearchers exploited a lack of isolation in several agentic browsers, which are browsers with embedded AI agents, to carry out attacks such as spreading false information and leaking data across sites. They describe the attacks as similar to cross-site scripting (XSS) and cross-site request forgery (CSRF), and say they resurface old vulnerability patterns. The authors outline a threat model with four trust zones and four violation classes, and they recommend extending the Same-Origin Policy to AI agents.
Fix: For developers of agentic browsers, the key recommendation is to extend the Same-Origin Policy to AI agents. The source also says the authors provide both immediate mitigations and long-term architectural solutions, but the specific mitigation details are not included in the text provided.
Trail of Bits BlogCVE-2026-22813: OpenCode markdown renderer allows HTML injection leading to script execution
Jan 12, 2026MediumVulnerabilitySecurityCVE-2026-22813CVE-2026-22813 affects OpenCode, an open source AI coding agent. The markdown renderer for LLM responses inserts arbitrary HTML into the DOM without DOMPurify sanitization or a CSP on the web interface, so controlling a chat session's LLM response yields JavaScript execution on the http://localhost:4096 origin. GitHub, Inc. assigned a CVSS 4.0 base score of 9.4 (CRITICAL), while NIST has not yet provided an assessment.
Fix: Fixed in 1.1.10
NVD/CVE DatabaseCVE-2026-22812: OpenCode unauthenticated HTTP server allows arbitrary shell command execution
Jan 12, 2026HighVulnerabilitySecurityCVE-2026-22812EPSS: 16.5%CVE-2026-22812 affects OpenCode, an open source AI coding agent, before version 1.0.216. OpenCode automatically starts an unauthenticated HTTP server, which lets any local process, or any website through permissive CORS, run arbitrary shell commands with the user's privileges. The weakness is classified as CWE-306, CWE-749 and CWE-942.
Fix: Fixed in 1.0.216.
NVD/CVE DatabaseAgentic ProbLLMs: Exploiting AI Computer-Use And Coding Agents (39C3 Video + Slides)
Dec 31, 2025InfoNewsSecurityResearchA security researcher presented a 39C3 talk titled "Agentic ProbLLMs: Exploiting AI Computer-Use and Coding Agents" at the Chaos Communication Congress in Hamburg. The talk covers the researcher's security research on vulnerabilities in agentic systems and the Month of AI Bugs, with demonstrations. Recordings are available on media.ccc.de and the Embrace The Red YouTube channel.
Embrace The RedExploring the Agentic Metaverse’s Potential for Transforming Cybersecurity Workforce Development
Dec 12, 2025InfoResearchPeer-reviewedResearchIndustryThis exploratory qualitative study evaluates an AI-driven metaverse prototype designed for cybersecurity training, with feedback from 53 cybersecurity professionals. The authors identify challenges in operationalizing the agentic metaverse, a convergence of immersive metaverse platforms and multi-agent systems, and offer six recommendations with emphasis on implementation and governance.
Fix: The source states six recommendations to guide operationalization of the agentic metaverse, with emphasis on implementation and governance considerations, but does not list their specific content in the provided text.
AIS eLibrary (Journal of AIS, CAIS, etc.)CVE-2025-67510: Neuron MySQLWriteTool executes arbitrary SQL provided by the caller
Dec 10, 2025CriticalVulnerabilitySecurityCVE-2025-67510Neuron, a PHP framework for building and orchestrating AI agents, versions 2.8.11 and below, has a flaw in MySQLWriteTool. The tool runs caller-supplied SQL through PDO::prepare() and execute() with no semantic restrictions. In an agent context, prompt injection or indirect prompt manipulation can make the agent run destructive statements such as DROP TABLE, TRUNCATE, DELETE, ALTER, or privilege-related statements, limited by the database user's permissions. Deployments that expose the tool to untrusted input or run it under a broadly privileged database user are affected.
Fix: This issue is fixed in version 2.8.12.
NVD/CVE DatabaseCVE-2025-67509: Neuron MySQLSelectTool read-only bypass allows file writes via INTO OUTFILE
Dec 10, 2025HighVulnerabilitySecurityCVE-2025-67509Neuron, a PHP framework for building AI agents, has a read-only bypass in MySQLSelectTool in versions 2.8.11 and below. The tool validates queries by checking the first keyword and a forbidden-keyword list, which does not block file-writing constructs such as INTO OUTFILE and INTO DUMPFILE. An attacker who can influence the tool input, for example through prompt injection on a public agent endpoint, can write arbitrary files to the database server if the MySQL or MariaDB account has the FILE privilege and the server configuration permits writes to a useful location, such as a web-accessible directory.
Fix: Fixed in 2.8.12.
NVD/CVE DatabaseOWASP Top 10 for Agentic Applications – The Benchmark for Agentic Security in the Age of Autonomous AI
Dec 10, 2025InfoResearchIndustryResearchSecurityOWASP has released the Top 10 for Agentic AI Applications, a community framework for securing autonomous, tool-using AI systems. The source says it is informed by real incidents and has already been adopted across industry.
OWASP GenAI Security
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.