AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 763
- Last 90 days
- 325
- Change
- +44%vs 225 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 38 |
159 items
CVE-2026-42075: Evolver path traversal in skill download fetch command via --out flag
May 4, 2026HighVulnerabilitySecurityCVE-2026-42075CVE-2026-42075 affects Evolver, a GEP-powered self-evolving engine for AI agents, prior to version 1.69.3. A path traversal flaw (CWE-22) in the skill download (fetch) command accepts unvalidated paths through the --out= flag, allowing attackers to write files to arbitrary filesystem locations. The source says this can overwrite critical system files or create files in sensitive locations.
Fix: This issue has been patched in version 1.69.3.
NVD/CVE DatabaseCareful Adoption of Agentic AI Services
May 1, 2026InfoVulnerabilitySecurityPolicyCISA, with the Australian Signals Directorate's Australian Cyber Security Centre and other international and U.S. partners, released guidance on adopting agentic AI systems. The guide outlines key security challenges and risks of agentic AI and gives actionable steps for designing, deploying, and operating these systems safely, aligning AI risk management with existing cybersecurity frameworks.
CISA Cybersecurity AdvisoriesCVE-2026-41679: Paperclip unauthenticated remote code execution through its API
Apr 22, 2026CriticalVulnerabilitySecurityCVE-2026-41679Paperclip, a Node.js server and React UI for orchestrating AI agents, is affected by CVE-2026-41679 in versions prior to 2026.416.0. An unauthenticated attacker can achieve full remote code execution on any network-accessible instance running in `authenticated` mode with default configuration, using a six-call API chain requiring no credentials or user interaction.
Fix: Version 2026.416.0 patches the issue.
NVD/CVE DatabaseCVE-2026-41208: Paperclip server privilege escalation through adapterConfig endpoint
Apr 22, 2026HighVulnerabilitySecurityCVE-2026-41208Versions of @paperclipai/server prior to 2026.416.0 contain a privilege escalation flaw. Agents can update their own adapterConfig through the /agents/:id endpoint, and the server later executes adapterConfig.workspaceStrategy.provisionCommand during workspace provisioning. An attacker holding an Agent API key can inject shell commands that run on the Paperclip server host, which the source describes as remote code execution.
Fix: @paperclipai/server version 2026.416.0 fixes the issue.
NVD/CVE DatabaseCVE-2026-39861: Claude Code sandbox escape through symlinks outside the workspace
Apr 20, 2026HighVulnerabilitySecurityCVE-2026-39861Claude Code versions before 2.1.64 let sandboxed processes create symlinks pointing outside the workspace. When Claude Code later wrote through such a symlink, its unsandboxed process followed it and wrote to the external target without asking the user for confirmation, enabling a sandbox escape that could potentially lead to code execution outside the sandbox. Exploitation required injecting untrusted content into the Claude Code context window to trigger sandboxed code execution.
Fix: Fixed in version 2.1.64. Users on standard auto-update received the fix automatically; users performing manual updates are advised to update to version 2.1.64 or later.
NVD/CVE DatabaseCVE-2026-40352: FastGPT NoSQL injection in password change endpoint
Apr 17, 2026HighVulnerabilitySecurityCVE-2026-40352FastGPT, an AI Agent building platform, has a NoSQL injection flaw in its password change endpoint in versions prior to 4.14.9.5. An authenticated attacker can inject MongoDB query operators to bypass the "old password" check, changing the password of their own account or others' accounts when combined with ID manipulation, which leads to full account takeover and persistence.
Fix: Fixed in version 4.14.9.5.
NVD/CVE DatabaseCVE-2026-40351: FastGPT NoSQL injection in password-based login endpoint
Apr 17, 2026CriticalVulnerabilitySecurityCVE-2026-40351CVE-2026-40351 affects FastGPT, an AI Agent building platform, in versions prior to 4.14.9.5. The password-based login endpoint uses TypeScript type assertion without runtime validation, so an unauthenticated attacker can submit a MongoDB query operator object such as {"$ne": ""} as the password field. This NoSQL injection bypasses the password check and allows login as any user, including the root administrator.
Fix: This issue has been fixed in version 4.14.9.5.
NVD/CVE DatabaseCVE-2026-40252: FastGPT broken access control lets teams run other teams' applications
Apr 10, 2026MediumVulnerabilitySecurityCVE-2026-40252CVE-2026-40252 is a Broken Access Control flaw (IDOR/BOLA) in FastGPT, an AI Agent building platform, affecting versions prior to 4.14.10.4. Any authenticated team can supply a foreign appId to access and execute another team's applications, because the API validates the team token but does not check that the application belongs to that team. The result is cross-tenant data exposure and unauthorized execution of private AI workflows.
Fix: Fixed in 4.14.10.4.
NVD/CVE DatabaseCVE-2026-40100: FastGPT server-side request forgery in the mcpTools/runTool endpoint
Apr 10, 2026MediumVulnerabilitySecurityCVE-2026-40100CVE-2026-40100 affects FastGPT, an AI Agent building platform, prior to 4.14.10.3. The /api/core/app/mcpTools/runTool endpoint accepts arbitrary URLs without authentication, and the internal IP check in isInternalAddress() blocks private IPs only when CHECK_INTERNAL_IP=true, which is not the default. Unauthenticated attackers can therefore perform SSRF against internal network resources.
Fix: Fixed in 4.14.10.3.
NVD/CVE DatabaseCVE-2026-39981: AGiXT path traversal in safe_join() of essential_abilities extension
Apr 9, 2026HighVulnerabilitySecurityCVE-2026-39981CVE-2026-39981 affects AGiXT, an AI Agent Automation Platform, before version 1.9.2. The safe_join() function in the essential_abilities extension does not check that resolved file paths stay within the designated agent workspace. An authenticated attacker can use directory traversal sequences to read, write, or delete arbitrary files on the server hosting the AGiXT instance.
Fix: Fixed in 1.9.2.
NVD/CVE DatabaseGHSA-v3qc-wrwx-j3pw: OpenClaw: Agentic Consent Bypass — LLM Agent Can Silently Disable Exec Approval via `config.patch`
Apr 2, 2026HighVulnerabilitySecurityOpenClaw's openclaw npm package, versions <=2026.3.24, lets an LLM agent silently disable exec approval through the config.patch function, bypassing user consent for command execution. Maintainers fixed it in commit 76411b2afc4ae721e36c12e0ea24fd23e2fed61e, shipped in v2026.3.28, and rate the issue high severity.
Fix: Fixed in v2026.3.28 (commit 76411b2afc4ae721e36c12e0ea24fd23e2fed61e); upgrade openclaw to >= 2026.3.28.
GitHub Advisory DatabaseCVE-2026-34163: FastGPT MCP tools endpoints server-side request forgery via user-supplied URL
Mar 31, 2026HighVulnerabilitySecurityCVE-2026-34163FastGPT, an AI Agent building platform, has an SSRF flaw in its MCP tools endpoints, /api/core/app/mcpTools/getTools and /api/core/app/mcpTools/runTool, before version 4.14.9.5. These endpoints accept a user-supplied URL and send server-side HTTP requests to it without checking for internal or private network addresses. The application's isInternalAddress() function exists but these endpoints do not call it. An authenticated attacker can scan internal networks, reach cloud metadata services, and interact with internal services such as MongoDB and Redis.
Fix: Fixed in 4.14.9.5.
NVD/CVE DatabaseCVE-2026-34162: FastGPT HTTP tools testing endpoint missing authentication
Mar 31, 2026CriticalVulnerabilitySecurityCVE-2026-34162CVE-2026-34162 affects FastGPT, an AI Agent building platform, prior to version 4.14.9.5. The HTTP tools testing endpoint /api/core/app/httpTools/runTool is exposed without any authentication and acts as a full HTTP proxy, accepting a user-supplied baseUrl, toolPath, method, headers and body, then returning the complete server-side response to the caller. It is classified as CWE-306 (Missing Authentication for Critical Function) and CWE-918 (Server-Side Request Forgery).
Fix: This issue has been patched in version 4.14.9.5.
NVD/CVE DatabaseCVE-2026-33873: Langflow arbitrary Python execution through Agentic Assistant validation
Mar 27, 2026CriticalVulnerabilitySecurityCVE-2026-33873Langflow versions prior to 1.9.0 contain CVE-2026-33873 in the Agentic Assistant feature. Its validation phase executes LLM-generated Python code, reaching dynamic execution sinks and instantiating the generated class server-side. Where an attacker can access the feature and influence model output, this allows arbitrary server-side Python execution.
Fix: Version 1.9.0 fixes the issue.
NVD/CVE DatabaseCVE-2026-33623: PinchTab command injection in Windows Chrome cleanup path
Mar 26, 2026MediumVulnerabilitySecurityCVE-2026-33623PinchTab v0.8.4, a standalone HTTP server that gives AI agents control over Chrome, has a Windows-only command injection flaw in its orphaned Chrome cleanup path. The cleanup routine builds a PowerShell -Command string from a profile-derived needle, and the escaping only neutralizes backslashes, not other PowerShell metacharacters. An attacker with authenticated, administrative-equivalent access to instance lifecycle endpoints who launches an instance with a crafted profile name and triggers cleanup can run arbitrary PowerShell commands as the PinchTab OS user, not unauthenticated and without bypassing host privilege boundaries.
Fix: Fixed in 0.8.5.
NVD/CVE DatabaseCVE-2026-33622: PinchTab arbitrary JavaScript execution through POST /wait fn mode
Mar 26, 2026HighVulnerabilitySecurityCVE-2026-33622PinchTab v0.8.3 through v0.8.5 let a caller with the server token run arbitrary JavaScript in a tab through POST /wait and POST /tabs/{id}/wait when fn mode is used, even with security.allowEvaluate disabled. POST /evaluate enforces that guard, but /wait embedded the user-supplied fn expression into executable JavaScript without checking it. The flaw is a policy bypass rather than an authentication bypass, since authenticated API access is still required.
Fix: The current worktree applies the same policy boundary to fn mode in /wait that already exists on /evaluate, while preserving the non-code wait modes. As of publication, a patched version is not yet available.
NVD/CVE DatabaseCVE-2026-33621: PinchTab rate limiting missing on auth-checkable endpoints
Mar 26, 2026MediumVulnerabilitySecurityCVE-2026-33621PinchTab v0.7.7 through v0.8.4 has incomplete request throttling on auth-checkable endpoints. In v0.7.7 through v0.8.3, RateLimitMiddleware in internal/handlers/middleware.go was never added to the production handler chain, and the pre-v0.8.4 limiter keyed clients by X-Forwarded-For, allowing header spoofing if enabled. v0.8.4 fixed both but still exempted /health and /metrics from rate limiting.
Fix: Fixed in v0.8.5: RateLimitMiddleware is applied in the production handler chain, the client address is derived from the immediate peer IP instead of forwarded headers by default, and the /health and /metrics exemption is removed.
NVD/CVE DatabaseCVE-2026-33620: PinchTab accepts API token in URL query parameter
Mar 26, 2026MediumVulnerabilitySecurityCVE-2026-33620PinchTab, a standalone HTTP server giving AI agents direct control over a Chrome browser, versions v0.7.8 through v0.8.3 accepted the API token from a `token` URL query parameter as well as the `Authorization` header. A valid credential sent in the URL can be exposed through URIs recorded by reverse proxy access logs, browser and shell history, clipboard history, and tracing systems. The issue is an unsafe credential transport pattern rather than an authentication bypass, and it affects only deployments with a configured token where a client uses the query-parameter form.
Fix: Fixed in v0.8.4, which removes query-string token authentication and requires safer header- or session-based authentication flows.
NVD/CVE DatabaseCVE-2026-33619: PinchTab server-side request forgery in scheduler webhook delivery
Mar 26, 2026MediumVulnerabilitySecurityCVE-2026-33619PinchTab v0.8.3 contains a server-side request forgery issue in the optional scheduler's webhook delivery path. When a task submitted to POST /tasks has a user-controlled callbackUrl, the server sends an outbound POST to that URL without rejecting loopback or private destinations, and it follows redirects, enabling blind SSRF toward attacker-chosen targets reachable from the server. The scheduler is off by default, and in token-protected deployments the attacker must already hold the master API token.
Fix: Fixed in v0.8.4, which validates callback targets before dispatch, rejects non-public IP ranges, pins delivery to validated IPs, disables redirect following, and validates callbackUrl during task submission.
NVD/CVE DatabaseCVE-2026-33081: PinchTab blind SSRF through the /download endpoint
Mar 20, 2026MediumVulnerabilitySecurityCVE-2026-33081PinchTab, a standalone HTTP server giving AI agents control of a Chrome browser, versions 0.8.2 and below, has a blind SSRF flaw in its /download endpoint. validateDownloadURL() checks only the initial user-supplied URL, so the embedded Chromium browser can follow attacker-controlled redirects or navigations to internal network addresses after validation. Exploitation requires security.allowDownload=true, which is disabled by default.
Fix: Fixed in 0.8.3.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.