AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 763
- Last 90 days
- 325
- Change
- +44%vs 225 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 38 |
159 items
CVE-2026-44285: FastGPT server-side request forgery in dataset preview endpoint
May 29, 2026HighVulnerabilitySecurityCVE-2026-44285CVE-2026-44285 is a Server-Side Request Forgery (SSRF) flaw in FastGPT, an AI Agent building platform, prior to 4.15.0-beta1. An authenticated attacker can bypass the global isInternalAddress network protection and make arbitrary HTTP GET requests to internal network services. The flaw is reached through an incomplete fix in the dataset preview endpoint /api/core/dataset/file/getPreviewChunks when the externalFile data import type is used.
Fix: Fixed in 4.15.0-beta1.
NVD/CVE DatabaseCVE-2026-45046: Gryph logs sensitive file writes to local sqlite database by default
May 27, 2026MediumVulnerabilitySecurityPrivacyCVE-2026-45046CVE-2026-45046 affects Gryph, a security layer for AI coding agents, in versions prior to 0.7.0. At the default standard logging level and at full, sensitive file-write content is stored in the local sqlite database as ContentPreview, OldString, or NewString, bypassing the sensitive file filter and log level contracts. The README wrongly states the default log level is minimal when it is standard.
Fix: Fixed in 0.7.0.
NVD/CVE DatabaseCVE-2026-44895: GitLab MCP Server HTTP transport accepts unauthenticated requests
May 26, 2026CriticalVulnerabilitySecurityCVE-2026-44895CVE-2026-44895 affects the GitLab MCP Server before 0.6.0. Its HTTP transport in src/transport.ts has no authentication and sends a wildcard Access-Control-Allow-Origin: * header, while exposing a mutation-capable RPC endpoint backed by GITLAB_PERSONAL_ACCESS_TOKEN. Because httpServer.listen(port) at line 97 passes no host, the server binds to 0.0.0.0 and exposes this surface on every interface.
Fix: Fixed in 0.6.0.
NVD/CVE DatabaseCVE-2026-46383: Microsoft APM archive extraction flaw in legacy-bundle probe on Windows
May 15, 2026MediumVulnerabilitySecurityCVE-2026-46383Microsoft APM, an open-source dependency manager for AI agents, is affected by CVE-2026-46383 in versions prior to 0.13.0. On supported Python 3.10 and 3.11 runtimes on Windows, the legacy-bundle probe used by apm install <bundle> calls raw tar.extractall() on untrusted tar members without rejecting Windows absolute member names such as D:/.... The flaw is reached when a local .tar.gz that is not a plugin-format bundle is passed to apm install.
Fix: Fixed in 0.13.0.
NVD/CVE DatabaseCVE-2026-45539: Microsoft APM symlink following during prompt and agent file integration
May 15, 2026HighVulnerabilitySecurityCVE-2026-45539From 0.5.4 to 0.12.4, two primitive integrators in apm-cli enumerate package files with Path.glob() and Path.rglob() and read matches with Path.read_text(), following symbolic links transparently. A symlink committed inside a remote APM dependency under .apm/prompts/ or .apm/agents/ is preserved into apm_modules/ on clone, then dereferenced during integration, and the resolved content is written as a regular file into the project's deploy directories. The package content_hash, the pre-deploy SecurityGate scan, and apm audit do not flag this.
Fix: Fixed in 0.13.0.
NVD/CVE DatabaseCVE-2026-44641: Microsoft APM path traversal in plugin manifest copies arbitrary host files
May 15, 2026HighVulnerabilitySecurityIndustryCVE-2026-44641Microsoft APM, an open-source dependency manager for AI agents, is affected prior to 0.8.12. When it normalizes marketplace plugins, it copies components referenced in plugin.json into .apm/ without checking that the attacker-controlled agents, skills, commands, and hooks paths stay inside the plugin directory. A malicious plugin can use absolute or ../ traversal paths to copy arbitrary readable files or directories from the installer's machine during apm install.
Fix: Fixed in 0.8.12.
NVD/CVE DatabaseCVE-2026-42572: Hatchet cross-tenant task metadata access through GET /api/v1/stable/dags/tasks
May 14, 2026MediumVulnerabilitySecurityCVE-2026-42572CVE-2026-42572 affects Hatchet, a platform for orchestrating background tasks, AI agents, and durable workflows, prior to 0.83.39. A missing authorization directive on the GET /api/v1/stable/dags/tasks endpoint skipped the tenant-membership check, so a user authenticated to any tenant on the same instance could supply another tenant's UUID and a DAG UUID from that tenant and receive that DAG's task metadata.
Fix: Fixed in 0.83.39.
NVD/CVE DatabaseCVE-2026-43993: JunoClaw WAVS bridge server-side request forgery in computeDataVerify
May 12, 2026HighVulnerabilitySecurityCVE-2026-43993CVE-2026-43993 affects JunoClaw, an agentic AI platform built on Juno Network, before 0.x.y-security-1. The WAVS bridge's computeDataVerify called fetch() on agent-supplied URLs without validating scheme, port, or resolved IP, which is a server-side request forgery (CWE-918). NIST has not yet provided an NVD assessment.
Fix: Fixed in 0.x.y-security-1.
NVD/CVE DatabaseCVE-2026-43992: JunoClaw MCP write tools expose BIP-39 mnemonic in LLM tool-call parameters
May 12, 2026CriticalVulnerabilitySecurityPrivacyCVE-2026-43992CVE-2026-43992 affects JunoClaw, an agentic AI platform built on Juno Network, prior to 0.x.y-security-1. Every MCP write tool, including send_tokens, execute_contract, instantiate_contract, upload_wasm and ibc_transfer, accepted 'mnemonic: string' as an explicit tool-call parameter. As a result, the BIP-39 seed was embedded in the LLM tool-call JSON and exposed to any transport, log or telemetry surface between the LLM provider and the MCP process.
Fix: This vulnerability is fixed in 0.x.y-security-1.
NVD/CVE DatabaseCVE-2026-43991: JunoClaw plugin-shell safety check bypass enables host command execution
May 12, 2026HighVulnerabilitySecurityCVE-2026-43991CVE-2026-43991 affects JunoClaw, an agentic AI platform built on Juno Network, before 0.x.y-security-1. A substring-based blocklist in the plugin-shell command-safety check, applied to the raw command string rather than the parsed first token, can be bypassed by adversarial argument constructions. When combined with the companion advisory, this allows unauthorized command execution on the host.
Fix: This vulnerability is fixed in 0.x.y-security-1.
NVD/CVE DatabaseCVE-2026-43990: JunoClaw plugin-shell command injection through run_command arguments
May 12, 2026HighVulnerabilitySecurityCVE-2026-43990CVE-2026-43990 affects JunoClaw, an agentic AI platform built on Juno Network, prior to 0.x.y-security-1. The plugin-shell run_command function wrapped every agent-supplied command in 'sh -c' / 'cmd /C' and passed the full argument string to the shell parser, so shell metacharacters in agent-supplied arguments were interpreted as command syntax. The issue is classified as CWE-77 and CWE-78, and NVD published it on 05/12/2026.
Fix: This vulnerability is fixed in 0.x.y-security-1.
NVD/CVE DatabaseCVE-2026-43989: JunoClaw upload_wasm MCP tool accepts unvalidated filesystem paths
May 12, 2026HighVulnerabilitySecurityCVE-2026-43989CVE-2026-43989 affects JunoClaw, an agentic AI platform built on Juno Network, prior to 0.x.y-security-1. The upload_wasm MCP tool accepted a filesystem path from the agent and uploaded whatever bytes that path resolved to, without validating location, symlink target, file size, or file format. The flaw is classified as CWE-20, CWE-22, CWE-59 and CWE-73.
Fix: Fixed in 0.x.y-security-1.
NVD/CVE DatabaseCVE-2026-44286: FastGPT unauthenticated SSRF through lafModule fetchData in workflow node
May 8, 2026HighVulnerabilitySecurityCVE-2026-44286CVE-2026-44286 affects FastGPT, an AI Agent building platform, prior to version 4.14.17. An unauthenticated attacker, or an authenticated user with App editing privileges, can make the fetchData function in the lafModule workflow node send arbitrary HTTP requests to internal or private network addresses. The function uses axios on user-controlled URLs without checking them against the isInternalAddress blocklist guard.
Fix: Fixed in 4.14.17.
NVD/CVE DatabaseCVE-2026-44284: FastGPT SSRF through stored internal MCP tool server URLs
May 8, 2026MediumVulnerabilitySecurityCVE-2026-44284FastGPT, an AI Agent building platform, prior to version 4.14.17, let authenticated users who can create or manage MCP toolsets save an internal MCP server URL, such as http://localhost:3000/mcp, through the MCP tool create and update endpoints. The direct MCP preview and run endpoints already rejected internal or private network URLs, so the protection was inconsistent. Later workflow execution used the stored URL without revalidating the destination, letting the FastGPT backend workflow runner connect to that internal destination.
Fix: Fixed in 4.14.17.
NVD/CVE DatabaseCVE-2026-42345: FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in…
May 8, 2026HighVulnerabilitySecurityCVE-2026-42345FastGPT versions 4.14.11 and prior are affected by CVE-2026-42345. The isInternalAddress() function in packages/service/common/system/utils.ts blocks cloud metadata endpoints with a fullUrl.startsWith() check against a hardcoded list, which at least 7 URL encoding techniques bypass to reach the same metadata service. The broader private IP check is disabled by default because CHECK_INTERNAL_IP defaults to false.
NVD/CVE DatabaseCVE-2026-42344: FastGPT DNS rebinding in isInternalAddress() allows internal address bypass
May 8, 2026MediumVulnerabilitySecurityCVE-2026-42344CVE-2026-42344 affects FastGPT, an AI Agent building platform, in versions 4.14.11 and prior. The isInternalAddress() function in packages/service/common/system/utils.ts is vulnerable to DNS rebinding, a time-of-check to time-of-use flaw: it resolves the hostname with dns.resolve4()/dns.resolve6() and checks the IPs against private ranges, but the HTTP request runs as a separate call with a new DNS resolution, so the record can change between validation and fetch.
NVD/CVE DatabaseCVE-2026-42343: FastGPT code-sandbox denial of service through unrestricted resource consumption
May 8, 2026MediumVulnerabilitySecurityCVE-2026-42343CVE-2026-42343 affects FastGPT, an AI Agent building platform, in versions 4.14.13 and prior. Its code-sandbox component relies only on an application-level soft limit, a 500ms polling interval, for memory management and lacks OS-level constraints such as cgroups or kernel-level namespaces. Attackers can bypass memory checks through time-window attacks or exhaust the JavaScript worker pool with concurrent CPU-intensive requests, causing a complete Denial of Service for legitimate users.
NVD/CVE DatabaseCVE-2026-42302: FastGPT agent-sandbox unauthenticated remote code execution via code-server
May 8, 2026CriticalVulnerabilitySecurityCVE-2026-42302FastGPT, an AI Agent building platform, has an unauthenticated Remote Code Execution flaw in its agent-sandbox component from version 4.14.10 to before 4.14.13. The startup script entrypoint.sh runs code-server with the --auth none flag and binds it to 0.0.0.0:8080, so any user with network access to that port can bypass authentication and gain full control of the sandbox environment.
Fix: Fixed in 4.14.13.
NVD/CVE DatabaseCVE-2026-42077: Evolver prototype pollution in mailbox store update functions
May 4, 2026MediumVulnerabilitySecurityCVE-2026-42077CVE-2026-42077 affects Evolver, a GEP-powered self-evolving engine for AI agents, before version 1.69.3. A prototype pollution flaw in the mailbox store module lets attackers inject malicious properties into Object.prototype, altering the behavior of all JavaScript objects. The flaw sits in the _applyUpdate() and _updateRecord() functions, which merge user-controlled data with Object.assign() without filtering keys such as __proto__, constructor, or prototype.
Fix: Fixed in 1.69.3.
NVD/CVE DatabaseCVE-2026-42076: Evolver command injection in _extractLLM() via corpus parameter
May 4, 2026CriticalVulnerabilitySecurityCVE-2026-42076CVE-2026-42076 affects Evolver, a GEP-powered self-evolving engine for AI agents, prior to version 1.69.3. A command injection flaw in the _extractLLM() function builds a curl command by string concatenation and passes it to execSync() without sanitization. When the corpus parameter contains shell metacharacters, an attacker can execute arbitrary shell commands on the server, classified as CWE-78.
Fix: This issue has been patched in version 1.69.3.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.