AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 764
- Last 90 days
- 324
- Change
- +43%vs 227 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 39 |
764 items
OWASP GenAI Security Project Releases Top 10 Risks and Mitigations for Agentic AI Security
Dec 10, 2025InfoResearchIndustrySecurityIndustryThe OWASP GenAI Security Project released a Top 10 list of risks and mitigations for agentic AI security on December 10, 2025. The release is described as the culmination of input from over 100 industry leaders and extensive published resources.
OWASP GenAI SecurityCVE-2025-12189: The Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents plugin for…
Dec 5, 2025MediumVulnerabilitySecurityIndustryCVE-2025-12189The Bread & Butter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 7.10.1321. Missing or incorrect nonce validation in the uploadImage() function lets unauthenticated attackers upload arbitrary files, which can enable remote code execution if they trick a site administrator into clicking a link.
NVD/CVE DatabaseCVE-2025-66032: Claude Code command injection via shell parsing of $IFS and short flags
Dec 3, 2025CriticalVulnerabilitySecurityCVE-2025-66032CVE-2025-66032 affects Claude Code, an agentic coding tool, before version 1.0.93. Errors in parsing shell commands related to $IFS and short CLI flags let an attacker bypass the read-only validation and trigger arbitrary code execution. Exploiting it reliably requires the ability to add untrusted content into the Claude Code context window.
Fix: Fixed in 1.0.93.
NVD/CVE DatabaseCVE-2025-65946: Roo Code auto-executes commands outside its allow list prefixes
Nov 21, 2025HighVulnerabilitySecurityCVE-2025-65946CVE-2025-65946 affects Roo Code, an AI-powered autonomous coding agent that runs in users' editors, in versions prior to 3.26.7. A validation error let Roo automatically execute commands that did not match the allow list prefixes. The issue is classified as CWE-77 (Command Injection) and CWE-20 (Improper Input Validation).
Fix: This issue has been patched in version 3.26.7.
NVD/CVE DatabaseCVE-2025-64755: Claude Code read-only validation bypass via sed command parsing
Nov 20, 2025CriticalVulnerabilitySecurityCVE-2025-64755CVE-2025-64755 affects Claude Code, an agentic coding tool, before version 2.0.31. An error in sed command parsing let an attacker bypass the read-only validation and write to arbitrary files on the host system. GitHub, Inc. assigned a CVSS 4.0 base score of 8.7 (High) and classified the weakness as CWE-78 (OS Command Injection).
Fix: Fixed in version 2.0.31.
NVD/CVE DatabaseCVE-2025-65099: Claude Code code execution via Yarn plugins in untrusted directories
Nov 19, 2025CriticalVulnerabilitySecurityCVE-2025-65099CVE-2025-65099 affects Claude Code before version 1.0.39 when it runs on a machine with Yarn 3.0 or above. A project's yarn plugins could execute code before the user accepted the startup trust dialog, provided the user started Claude Code in an untrusted directory.
Fix: This issue has been patched in version 1.0.39.
NVD/CVE DatabaseCVE-2025-62612: FastGPT SSRF in workflow file reading node via unverified network links
Oct 22, 2025MediumVulnerabilitySecurityCVE-2025-62612CVE-2025-62612 affects FastGPT, an AI Agent building platform, prior to version 4.11.1. The workflow file reading node does not verify network links for security, which exposes the platform to server-side request forgery (SSRF, CWE-918). The source rates the issue MEDIUM under CVSS 4.0 (GitHub, Inc., base score 6.9).
Fix: This issue has been patched in version 4.11.1.
NVD/CVE DatabasePrompt injection to RCE in AI agents
Oct 22, 2025MediumNewsSecuritySafetyModern AI agents run system commands such as find, grep, rg and git without human approval for efficiency, and the researchers describe bypassing human approval through argument injection against these pre-approved commands. They achieved remote code execution with a single prompt against three unnamed production agent platforms, which the authors say remain under coordinated disclosure.
Fix: The source states that the impact can be limited through improved command execution design, such as sandboxing and argument separation, and that the authors provide actionable recommendations for developers, users and security engineers. The specific recommendations are not included in the provided text.
Trail of Bits Blogv5.0.0
Oct 15, 2025InfoResearchIndustrySecurityResearchMITRE released ATLAS Data v5.0.0, which adds a "Technique Maturity" field to the distributed ATLAS.yaml file. The field grades evidence behind each technique as Feasible, Demonstrated, or Realized. The release also adds several new AI agent techniques, including AI Agent Context Poisoning, RAG Credential Harvesting, and Exfiltration via AI Agent Tool Invocation, plus one new case study.
MITRE ATLAS ReleasesCVE-2025-61685: Mastra directory traversal disclosing directory listings
Oct 3, 2025MediumVulnerabilitySecurityCVE-2025-61685Mastra, a TypeScript framework for building AI agents and assistants, is vulnerable in versions 0.13.8 through 0.13.20-alpha.0 to directory traversal. A path traversal check that protects reading file contents is bypassed by later logic that generates directory suggestions, letting an attacker list arbitrary directories on the user's filesystem, including the home directory, and expose details of the file system's structure.
Fix: This issue is fixed in version 0.13.20.
NVD/CVE DatabaseCVE-2025-59829: Claude Code permission deny rules bypassed via symlinks
Oct 3, 2025MediumVulnerabilitySecurityCVE-2025-59829Claude Code versions below 1.0.120 did not account for symlinks when checking permission deny rules. If a user denied Claude Code access to a file, but Claude Code could reach a symlink pointing to that file, Claude Code could still access the file.
Fix: Fixed in version 1.0.120. Standard auto-update installs the fix automatically; users performing manual updates are advised to update to the latest version.
NVD/CVE DatabaseCVE-2025-59536: Claude Code code injection through startup trust dialog
Oct 3, 2025HighVulnerabilitySecurityIndustryCVE-2025-59536EPSS: 27.2%Claude Code versions before 1.0.111 were vulnerable to Code Injection because of a bug in the startup trust dialog. The tool could be tricked into executing code contained in a project before the user accepted the dialog. Exploitation requires a user to start Claude Code in an untrusted directory.
Fix: Fixed in version 1.0.111. Users on standard auto-update received the fix automatically; users performing manual updates are advised to update to the latest version.
NVD/CVE DatabaseCVE-2025-59828: Claude Code trust dialog bypass through Yarn plugin auto-execution
Sep 24, 2025CriticalVulnerabilitySecurityCVE-2025-59828CVE-2025-59828 affects Claude Code before version 1.0.39 when used with Yarn 2.0+. Yarn plugins execute automatically when yarn --version runs, which can bypass the directory trust dialog because plugins run before the user accepts the risks of an untrusted directory. Users of Yarn Classic were not affected.
Fix: This issue has been fixed in version 1.0.39. Users on standard Claude Code auto-update received the fix automatically. Users performing manual updates are advised to update to the latest version.
NVD/CVE DatabaseCross-Agent Privilege Escalation: When Agents Free Each Other
Sep 24, 2025MediumNewsSecurityResearchJohann Rehberger describes a design flaw in agentic systems that lets one coding agent rewrite another agent's configuration, freeing it from its sandbox. In his demo, a prompt-injected GitHub Copilot writes a malicious MCP server into Claude Code's config, which then runs arbitrary code. The post notes that Claude can reciprocate by modifying Copilot's configuration.
Fix: Mitigations and Recommendations: the source states that vendors should adopt secure defaults and that users should be aware of several points, including isolating the agent's configuration so it is less accessible to others and not automatically overwriting or creating files. The remainder of the mitigation text is cut off in the source.
Embrace The RedCVE-2025-59532: Codex CLI sandbox bypass allowing arbitrary file writes and command execution
Sep 22, 2025HighVulnerabilitySecurityCVE-2025-59532CVE-2025-59532 affects Codex CLI, OpenAI's locally run coding agent, in versions 0.2.0 to 0.38.0. A bug in the sandbox configuration logic let Codex CLI treat a model-generated cwd as the sandbox's writable root, even for paths outside the folder where the session started. This bypassed the workspace boundary and enabled arbitrary file writes and command execution with the permissions of the Codex process, though the network-disabled sandbox restriction was not affected.
Fix: Fixed in Codex CLI 0.39.0, which canonicalizes and validates the sandbox policy boundary against where the user started the session rather than the model-generated path. Users on 0.38.0 or earlier should update immediately via their package manager or by reinstalling the latest Codex CLI. Users of the Codex IDE extension should update to 0.4.12.
NVD/CVE DatabaseCVE-2025-55319: Ai command injection in Agentic AI and Visual Studio Code over network
Sep 11, 2025HighVulnerabilitySecurityCVE-2025-55319CVE-2025-55319 is an AI command injection flaw in Agentic AI and Visual Studio Code. An unauthorized attacker can exploit it over a network to execute code. NIST has not yet provided an NVD assessment, and the entry was published 09/11/2025 and last modified 09/24/2025.
NVD/CVE DatabaseCVE-2025-59041: Claude Code code execution via malicious git user email before workspace trust
Sep 10, 2025CriticalVulnerabilitySecurityCVE-2025-59041CVE-2025-59041 affects Claude Code, an agentic coding tool. At startup, Claude Code executed a command templated in with `git config user.email`, so a maliciously configured user email in git could trigger arbitrary code execution before the user accepted the workspace trust dialog in versions prior to 1.0.105.
Fix: Fixed in version 1.0.105. Users on standard Claude Code auto-update received the fix automatically; users performing manual updates are advised to update to version 1.0.105 or the latest version.
NVD/CVE DatabaseCVE-2025-58764: Claude Code confirmation prompt bypass through command parsing error
Sep 10, 2025CriticalVulnerabilitySecurityCVE-2025-58764CVE-2025-58764 affects Claude Code versions prior to 1.0.105. A command parsing error allows the confirmation prompt to be bypassed, triggering execution of an untrusted command. Exploitation reliably requires the ability to add untrusted content into a Claude Code context window.
Fix: Users on standard Claude Code auto-update received the fix automatically. Users performing manual updates are advised to update to version 1.0.105 or the latest version.
NVD/CVE DatabaseCVE-2025-58374: Roo Code arbitrary code execution through npm install auto-approval
Sep 5, 2025HighVulnerabilitySecurityCVE-2025-58374Roo Code versions 3.25.23 and below ship a default allowlist of commands that run without manual approval when auto-approve is enabled, and that list includes npm install. Because npm install executes lifecycle scripts, a malicious postinstall script in a repository's package.json runs automatically, so opening a malicious repo with auto-approved commands enabled can lead to arbitrary code execution.
Fix: Fixed in version 3.26.0.
NVD/CVE DatabaseCVE-2025-58373: Roo Code .rooignore bypass via symlinks exposes excluded files
Sep 5, 2025MediumVulnerabilitySecurityCVE-2025-58373Roo Code versions 3.25.23 and below contain a flaw where .rooignore exclusions can be bypassed using symlinks. An attacker with write access to the workspace can trick the extension into reading files meant to be excluded, such as .env or configuration files, exposing secrets and other excluded project data.
Fix: Fixed in version 3.26.0.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.