AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 764
- Last 90 days
- 324
- Change
- +43%vs 227 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 39 |
764 items
CVE-2025-58372: Roo Code arbitrary code execution via unprotected .code-workspace files
Sep 5, 2025HighVulnerabilitySecurityCVE-2025-58372Roo Code, an AI-powered autonomous coding agent for editors, versions 3.25.23 and below, does not protect VS Code .code-workspace files the way it protects the .vscode folder. If the agent auto-approves file writes, an attacker who can influence its prompts, for example through prompt injection, can have malicious workspace settings or tasks written. Those tasks run automatically when the workspace is reopened, leading to arbitrary code execution.
Fix: Fixed in version 3.26.0.
NVD/CVE DatabaseCVE-2025-58371: Roo Code GitHub workflow code execution via unsanitized pull request metadata
Sep 5, 2025CriticalVulnerabilitySecurityCVE-2025-58371CVE-2025-58371 affects Roo Code, an AI-powered autonomous coding agent, in versions 3.26.6 and below. A GitHub workflow used unsanitized pull request metadata in a privileged context, so an attacker can craft input that achieves Remote Code Execution on the Actions runner. Because the workflow runs with broad permissions and access to repository secrets, the attacker can run arbitrary commands, modify code, access secrets and create malicious releases or packages, fully compromising the repository and its associated services.
Fix: Fixed in version 3.26.7.
NVD/CVE DatabaseCVE-2025-58370: Roo Code command parsing flaw allows arbitrary command execution via prompts
Sep 5, 2025HighVulnerabilitySecurityCVE-2025-58370CVE-2025-58370 affects Roo Code, an AI-powered autonomous coding agent, in versions below 3.26.0. The command parsing logic mishandles Bash parameter expansion and indirect references, so when the agent is configured to auto-approve certain commands, an attacker who can influence prompts can get additional arbitrary commands executed alongside the intended one. The weakness is classified as CWE-78, OS Command Injection.
Fix: This is fixed in version 3.26.0.
NVD/CVE DatabaseCVE-2025-57771: Roo Code command injection in auto-approved command parsing
Aug 22, 2025HighVulnerabilitySecurityCVE-2025-57771CVE-2025-57771 affects Roo Code, an AI-powered autonomous coding agent, in versions prior to 3.25.5. The command parsing logic does not properly handle process substitution and single ampersand characters for auto-execute commands, so an attacker who can submit crafted prompts may inject arbitrary commands to run alongside an intended command such as ls. Exploitation requires prompt submission access and that the user has enabled auto-approved command execution, which is disabled by default; the source states this could allow arbitrary code execution.
Fix: Fixed in version 3.25.5.
NVD/CVE DatabaseCVE-2025-55284: Claude Code confirmation prompt bypass allows network file exfiltration
Aug 15, 2025HighVulnerabilitySecurityCVE-2025-55284Claude Code versions prior to 1.0.4 contain an overly broad allowlist of safe commands. This lets an attacker bypass confirmation prompts to read a file and send its contents over the network without user approval. Reliable exploitation requires the ability to insert untrusted content into a Claude Code context window.
Fix: Fixed in version 1.0.4. Users on standard auto-update received the fix automatically after release. Versions prior to 1.0.24 are deprecated and have been forced to update, so current users are unaffected.
NVD/CVE DatabaseCVE-2025-55012: Zed Agent Panel allows remote code execution via permissions bypass
Aug 11, 2025HighVulnerabilitySecurityIndustryCVE-2025-55012Prior to version 0.197.3 of Zed, a multiplayer code editor, the Zed Agent Panel let an AI agent bypass user permission checks. By exploiting this, an agent could create or modify a project-specific configuration file and execute arbitrary commands on a victim's machine without the explicit approval normally required, achieving Remote Code Execution (RCE).
Fix: Fixed in version 0.197.3. Workaround: avoid sending prompts to the Agent Panel, or limit the AI Agent's file system access.
NVD/CVE DatabaseCVE-2025-54795: Claude Code command parsing flaw bypasses confirmation prompt
Aug 4, 2025CriticalVulnerabilitySecurityCVE-2025-54795CVE-2025-54795 affects Claude Code versions below 1.0.20. An error in command parsing lets an attacker bypass the Claude Code confirmation prompt and trigger execution of an untrusted command, classified as CWE-78. Exploiting it reliably requires the ability to add untrusted content into a Claude Code context window.
Fix: Fixed in version 1.0.20.
NVD/CVE DatabaseCVE-2025-54794: Claude Code path validation flaw exposes files outside working directory
Aug 4, 2025CriticalVulnerabilitySecurityCVE-2025-54794CVE-2025-54794 affects Claude Code versions below 0.2.111. A path validation flaw compares path prefixes instead of canonical paths, which lets an attacker bypass directory restrictions and access files outside the CWD. Exploitation requires a directory sharing the CWD's prefix that exists or can be created, plus the ability to add untrusted content into a Claude Code context window. GitHub, Inc. rates it CVSS 4.0 7.7 (High).
Fix: Fixed in version 0.2.111.
NVD/CVE DatabaseThe Month of AI Bugs 2025
Jul 28, 2025InfoNewsSecurityResearchThe author announces the Month of AI Bugs 2025, a series of more than 20 blog posts in August that will disclose vulnerabilities in agentic AI systems, mainly coding agents such as ChatGPT Codex, Anthropic Claude Code, GitHub Copilot Agent Mode and Cursor. Every reviewed coding agent had vulnerabilities that were reported to its vendor, and vendor responses varied from fixes within days to months of silence. The initiative aims to raise awareness of prompt injection and related risks before deployment.
Embrace The RedCVE-2025-54377: Roo Code allow-list bypass via multi-line command injection
Jul 23, 2025HighVulnerabilitySecurityCVE-2025-54377Roo Code, an AI-powered autonomous coding agent for editors, versions 3.23.18 and below, does not validate line breaks (\n) in its command input. This allows a bypass of the allow-list mechanism, since only the first line or token may be considered when commands are evaluated, so additional commands in subsequent lines can run.
Fix: Fixed in version 3.23.19.
NVD/CVE DatabaseOWASP Agentic AI Taxonomy in Action: From Theory to Tools
Jul 22, 2025InfoResearchIndustrySecurityIndustryOWASP's Agentic Security Initiative (ASI) has a taxonomy called Agentic AI – Threats and Mitigations. Three developer tools, PENSAR, SPLX.AI Agentic Radar, and AI&ME, now adopt it to help teams test, defend, and build agentic systems. The ecosystem is also informing the forthcoming OWASP Top 10 for Agentic AI.
OWASP GenAI SecurityCVE-2025-53536: Roo Code code execution via auto-approved Write to VS Code settings
Jul 7, 2025HighVulnerabilitySecurityCVE-2025-53536CVE-2025-53536 affects Roo Code, an AI-powered autonomous coding agent, prior to 3.22.6. When the victim had "Write" auto-approved, an attacker able to submit prompts to the agent could write to VS Code settings files and trigger code execution. One example uses the php.validate.executablePath setting, where the attacker sets an arbitrary command as the PHP path and then creates a PHP file to trigger it.
Fix: Fixed in 3.22.6.
NVD/CVE DatabaseCVE-2025-53098: Roo Code arbitrary command execution via MCP configuration file writes
Jun 27, 2025HighVulnerabilitySecurityCVE-2025-53098Roo Code, an AI-powered autonomous coding agent, stored project-specific MCP configuration in `.roo/mcp.json` within the VS Code workspace. Before version 3.20.3, an attacker who could submit prompts to the agent could have it write a malicious command into that file, leading to arbitrary command execution if the user had enabled auto-approved file writes.
Fix: Fixed in 3.20.3, which adds an additional opt-in configuration layer for auto-approving writes to Roo's configuration files, including all files within the `.roo/` folder.
NVD/CVE DatabaseCVE-2025-53097: Roo Code search_files tool reads files outside VS Code workspace
Jun 27, 2025MediumVulnerabilitySecurityCVE-2025-53097Roo Code, an AI-powered autonomous coding agent, prior to version 3.20.3 had a flaw where the `search_files` tool ignored the setting that disables reads outside the VS Code workspace. An attacker who could inject a prompt into the agent could read a sensitive file and write its contents into a JSON schema, which triggered a network request by default without user confirmation. The issue is rated moderate because the attacker must already be able to submit prompts to the agent.
Fix: Fixed in 3.20.3: `search_files` now respects the setting that limits it to the workspace.
NVD/CVE DatabaseCVE-2025-52882: Claude Code IDE extensions allow unauthorized websocket connections
Jun 24, 2025HighVulnerabilitySecurityCVE-2025-52882CVE-2025-52882 affects Claude Code extensions for VSCode and its forks, such as Cursor, Windsurf, and VSCodium, as well as the JetBrains plugin Claude Code [Beta]. Visiting attacker-controlled webpages lets an attacker make unauthorized websocket connections to the IDE. Exploitation can read arbitrary files, list open files, and obtain selection and diagnostics events, and in VSCode it can also execute code in limited cases involving an open Jupyter Notebook and an accepted malicious prompt.
Fix: Claude released a patch on June 13, 2025. For VSCode and forks, update or uninstall Claude Code for VSCode versions prior to 1.0.24, then restart the IDE. For JetBrains IDEs, update or uninstall Claude Code [Beta] versions prior to 0.1.9, then restart the IDE.
NVD/CVE DatabaseCVE-2025-52552: FastGPT login page LastRoute parameter open redirect and DOM-based XSS
Jun 20, 2025MediumVulnerabilitySecurityCVE-2025-52552CVE-2025-52552 affects FastGPT, an AI Agent building platform, before version 4.9.12. The LastRoute parameter on the login page is vulnerable to open redirect (CWE-601) and DOM-based cross-site scripting (CWE-79). Because the parameter is improperly validated and not sanitized, attackers can run malicious JavaScript or redirect users to attacker-controlled sites.
Fix: Fixed in version 4.9.12.
NVD/CVE DatabaseCVE-2025-48491: Project AI hardcoded API key
May 30, 2025HighVulnerabilitySecurityCVE-2025-48491The source text is NIST NVD navigation material: a disclaimer about external links and a list of GitHub commit and advisory URLs for CVE-2025-48491 in the Project AI platform for creating AI agents. It does not describe the flaw, the affected versions or the impact, beyond the title's note that before the pre-beta version a hardcoded API key was present.
NVD/CVE DatabaseSecurity Spotlight: Securing Cloud & AI Products with Guardrails
May 28, 2025InfoNewsSecurityIndustryPalo Alto Networks published a blog post titled "Beyond Jailbreaks: Why Agentic AI Needs Contextual Red Teaming" on March 9, 2026, by Sailesh Mishra and Ankita Kumari. The source text argues that generic jailbreak testing misses the real risks in agentic AI and says contextual red teaming can expose tool misuse, data exfiltration, and operational vulnerabilities. The rest of the text is navigation and listings of other posts.
Protect AI BlogAI ClickFix: Hijacking Computer-Use Agents Using ClickFix
May 24, 2025MediumNewsSecurityResearchJohann Rehberger presented a demo at the SAGAI Workshop on May 15, 2025 in San Francisco, showing how ClickFix attacks apply to computer-use AI systems. ClickFix is a social engineering technique in which adversaries tell users that something is broken or needs validation, prompting them to click a button, open a terminal and run commands.
Embrace The RedRecap from OWASP Gen AI Security Project’s – NYC Insecure Agents Hackathon
Apr 25, 2025InfoResearchIndustrySecurityResearchThe OWASP Gen AI Security Project held a hackathon in NYC to build insecure AI agents. The source recaps the event and the most common security findings from the submissions, and notes that AI agents are prone to threats outlined in the Agentic AI – Threats and Mitigations guide released in February.
OWASP GenAI Security
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.