AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 763
- Last 90 days
- 325
- Change
- +44%vs 225 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 38 |
159 items
CVE-2026-33075: FastGPT workflow code execution and secret exfiltration by external contributors
Mar 20, 2026HighVulnerabilitySecurityCVE-2026-33075FastGPT versions 4.14.8.3 and below have a flaw in the fastgpt-preview-image.yml workflow. It uses pull_request_target, which runs with access to repository secrets, yet checks out code from the pull request author's fork, so any external contributor can achieve arbitrary code execution and secret exfiltration. The workflow also builds and pushes Docker images from attacker-controlled Dockerfiles, which enables a supply chain attack via the production container registry.
Fix: A patch was not available at the time of publication.
NVD/CVE DatabaseCVE-2026-32128: FastGPT Python Sandbox file write restriction bypass via stdout remapping
Mar 11, 2026MediumVulnerabilitySecurityCVE-2026-32128CVE-2026-32128 affects FastGPT, an AI Agent building platform, in version 4.14.7 and earlier. Its Python Sandbox (fastgpt-sandbox) relies on static detection and seccomp to block file writes, but an attacker can remap stdout (fd 1) to an arbitrary writable file descriptor using fcntl. Because sys.stdout.write() still satisfies the seccomp rule write(fd==1), the attacker can create or overwrite arbitrary files inside the sandbox container.
NVD/CVE DatabaseCVE-2026-30834: PinchTab server-side request forgery in /download endpoint
Mar 7, 2026HighVulnerabilitySecurityCVE-2026-30834PinchTab, a standalone HTTP server that gives AI agents direct control over a Chrome browser, contains a Server-Side Request Forgery (SSRF) flaw in its /download endpoint in versions prior to 0.7.7 (CWE-918). Any user with API access can make the server request arbitrary URLs, including internal network services and local system files, and exfiltrate the full response content.
Fix: This issue has been patched in version 0.7.7.
NVD/CVE DatabaseCVE-2026-29791: Agentgateway input validation flaw in MCP tools/call to OpenAPI conversion
Mar 6, 2026MediumVulnerabilitySecurityCVE-2026-29791CVE-2026-29791 affects Agentgateway, an open source data plane for agentic AI connectivity, prior to version 0.12.0. When converting an MCP tools/call request to an OpenAPI request, input path, query, and header values are not sanitized, which is classified as CWE-20 Improper Input Validation. The NVD assessment has not yet been provided.
Fix: This issue has been patched in version 0.12.0.
NVD/CVE DatabaseCVE-2026-27597: Enclave JavaScript sandbox escape leading to remote code execution
Feb 24, 2026CriticalVulnerabilitySecurityCVE-2026-27597CVE-2026-27597 affects Enclave, a secure JavaScript sandbox for AI agent code execution, in versions prior to 2.11.1. The flaw allows an escape from the security boundaries set by `@enclave-vm/core`, which can be used to achieve remote code execution (RCE). The weakness is classified as CWE-94, Improper Control of Generation of Code ('Code Injection').
Fix: Fixed in version 2.11.1.
NVD/CVE DatabaseCVE-2026-26075: FastGPT server-side request handling in web page and HTTP nodes
Feb 12, 2026MediumVulnerabilitySecurityCVE-2026-26075CVE-2026-26075 affects FastGPT, an AI Agent building platform. Its web page acquisition nodes and HTTP nodes initiate data acquisition requests from the server, which the source describes as a security issue. The fix adds stricter internal network address detection, and the source rates it CVSS 4.0 6.9 MEDIUM (AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N) per GitHub, Inc.; NVD has not yet provided an assessment.
Fix: Fixed in 4.14.7. In addition to implementing internal network isolation in the deployment environment, stricter internal network address detection has been added.
NVD/CVE DatabaseCVE-2026-26003: FastGPT is an AI Agent building platform. From 4.14.0 to 4.14.5, attackers can directly access the plugin system…
Feb 10, 2026MediumVulnerabilitySecurityCVE-2026-26003CVE-2026-26003 affects FastGPT, an AI Agent building platform, in versions 4.14.0 through 4.14.5. Attackers can reach the plugin system directly through FastGPT/api/plugin/xxx without authentication. The source says this may crash the plugin system and cause loss of plugin installation status, but it will not result in key leakage.
Fix: Fixed in 4.14.5-fix.
NVD/CVE DatabaseCVE-2026-25592: Semantic Kernel .NET SDK arbitrary file write in SessionsPythonPlugin
Feb 6, 2026CriticalVulnerabilitySecurityCVE-2026-25592Semantic Kernel's .NET SDK, prior to 1.70.0, contains an Arbitrary File Write vulnerability in the SessionsPythonPlugin. The flaw is fixed in Microsoft.SemanticKernel.Core 1.70.0.
Fix: Fixed in Microsoft.SemanticKernel.Core 1.70.0. As a mitigation, create a Function Invocation Filter that checks the arguments passed to DownloadFileAsync or UploadFileAsync and ensures the provided localFilePath is allow listed.
NVD/CVE DatabaseCVE-2026-25533: Enclave JavaScript sandbox escape through dynamic property access bypass
Feb 6, 2026MediumVulnerabilitySecurityCVE-2026-25533CVE-2026-25533 affects Enclave, a secure JavaScript sandbox for AI agent code execution, in versions prior to 2.10.1. The sandbox's existing protections in enclave-vm can be bypassed in three ways: AST sanitization through dynamic property accesses, incomplete hardening of error objects around the vm module, and the function constructor access prevention through host object references. GitHub rates it CVSS 4.0 6.4 (Medium), with a local attack vector and no privileges or user interaction required.
Fix: Fixed in 2.10.1.
NVD/CVE DatabaseCVE-2026-25580: Pydantic AI server-side request forgery in URL download via message history
Feb 6, 2026HighVulnerabilitySecurityCVE-2026-25580Pydantic AI, a Python agent framework for Generative AI applications, contains a Server-Side Request Forgery (SSRF) flaw in its URL download functionality in versions from 0.0.26 to before 1.56.0. When applications accept message history from untrusted sources, attackers can include malicious URLs that make the server send HTTP requests to internal network resources, potentially reaching internal services or cloud credentials. Only applications that accept message history from external users are affected.
Fix: This vulnerability is fixed in 1.56.0.
NVD/CVE DatabaseCVE-2026-25640: Pydantic AI web UI path traversal via version query parameter
Feb 6, 2026HighVulnerabilitySecurityCVE-2026-25640Pydantic AI versions from 1.34.0 before 1.51.0 contain a path traversal flaw in the web UI. The version query parameter in the CDN URL is not validated, so a crafted URL makes the server fetch and serve attacker-controlled HTML/JavaScript from another location on the same CDN. Only applications using Agent.to_web or clai web are affected, and an attacker who lures a victim into clicking the link or loading it in an iframe can run code in the victim's browser and steal chat history and other client-side data.
Fix: Fixed in 1.51.0.
NVD/CVE DatabaseCVE-2026-25725: Claude Code bubblewrap sandbox escape by creating settings.json
Feb 6, 2026CriticalVulnerabilitySecurityCVE-2026-25725Claude Code, an agentic coding tool, prior to version 2.1.2 had a flaw in its bubblewrap sandboxing mechanism. When .claude/settings.json did not exist at startup, it was left unprotected, even though the parent directory was writable and .claude/settings.local.json was read-only. Code running inside the sandbox could create this file and inject persistent hooks, such as SessionStart commands, that ran with host privileges when Claude Code restarted.
Fix: Patched in version 2.1.2.
NVD/CVE DatabaseCVE-2026-25724: Claude Code deny rules bypassed through symbolic links
Feb 6, 2026HighVulnerabilitySecurityCVE-2026-25724Claude Code, an agentic coding tool, failed to strictly enforce deny rules set in settings.json when accessing files through symbolic links. A user's explicit denial of a file such as /etc/passwd could be bypassed by reading that file through a symlink pointing to it. The issue is tracked as CVE-2026-25724 and affects versions prior to 2.1.7.
Fix: This issue has been patched in version 2.1.7.
NVD/CVE DatabaseCVE-2026-25723: Claude Code file write restriction bypass via piped sed and echo commands
Feb 6, 2026MediumVulnerabilitySecurityCVE-2026-25723Claude Code, an agentic coding tool, failed to properly validate commands that combined piped sed operations with echo, letting attackers bypass file write restrictions. The flaw allowed writes to sensitive locations such as the .claude folder and paths outside the project scope, but exploitation required the ability to run commands through Claude Code with the "accept edits" feature enabled.
Fix: Patched in version 2.0.55.
NVD/CVE DatabaseCVE-2026-25722: Claude Code write protection bypass via cd into protected directories
Feb 6, 2026CriticalVulnerabilitySecurityCVE-2026-25722Claude Code, an agentic coding tool, failed to properly validate directory changes before version 2.0.57. Using the cd command to enter protected directories such as .claude let an attacker bypass write protection and create or modify files without user confirmation. Reliable exploitation required the ability to add untrusted content into the Claude Code context window.
Fix: This issue has been patched in version 2.0.57.
NVD/CVE DatabaseCVE-2026-24887: Claude Code confirmation prompt bypass via find command
Feb 3, 2026HighVulnerabilitySecurityCVE-2026-24887CVE-2026-24887 affects Claude Code, an agentic coding tool, prior to version 2.0.72. A command parsing error let an attacker bypass the confirmation prompt and run untrusted commands through the find command. Exploitation reliably required the ability to add untrusted content into the Claude Code context window.
Fix: Fixed in version 2.0.72.
NVD/CVE DatabaseCVE-2026-24053: Claude Code Bash validation flaw in ZSH clobber syntax allows file writes
Feb 3, 2026MediumVulnerabilitySecurityCVE-2026-24053CVE-2026-24053 affects Claude Code prior to version 2.0.74. A Bash command validation flaw in parsing ZSH clobber syntax let an attacker bypass directory restrictions and write files outside the current working directory without user permission prompts. Exploitation required the user to run ZSH and the ability to add untrusted content into a Claude Code context window.
Fix: Fixed in version 2.0.74.
NVD/CVE DatabaseCVE-2026-24052: Claude Code WebFetch trusted domain check bypass via startsWith validation
Feb 3, 2026HighVulnerabilitySecurityCVE-2026-24052CVE-2026-24052 affects Claude Code before version 1.0.111. Its trusted domain check for WebFetch requests used startsWith(), so a domain such as modelcontextprotocol.io.example.com passed validation as if it were modelcontextprotocol.io. This could let an attacker trigger automatic requests to attacker-controlled domains without user consent, potentially leading to data exfiltration.
Fix: Fixed in version 1.0.111.
NVD/CVE DatabaseCVE-2025-13374: Kalrav AI Agent WordPress plugin arbitrary file upload via kalrav_upload_file
Jan 24, 2026CriticalVulnerabilitySecurityCVE-2025-13374The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to and including 2.3.3. The flaw is missing file type validation in the kalrav_upload_file AJAX action, and unauthenticated attackers can exploit it. The source states this may make remote code execution possible on the affected site's server.
NVD/CVE DatabaseCVE-2026-24399: ChatterMate client-side injection through iframe javascript URI in chat input
Jan 23, 2026CriticalVulnerabilitySecurityCVE-2026-24399ChatterMate, a no-code AI chatbot agent framework, versions 1.0.8 and below, accepts and executes malicious HTML/JavaScript supplied as chat input. An iframe payload containing a javascript: URI runs in the browser context, exposing client-side data such as localStorage tokens and cookies. The flaw is tracked as CVE-2026-24399 under CWE-79.
Fix: Fixed in version 1.0.9.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.