AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 763
- Last 90 days
- 325
- Change
- +44%vs 225 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 38 |
159 items
CVE-2026-21852: Claude Code project-load flow leaks API keys before trust prompt
Jan 21, 2026HighVulnerabilitySecurityCVE-2026-21852EPSS: 27.9%Prior to version 2.0.65, Claude Code's project-load flow let a malicious repository exfiltrate data, including Anthropic API keys, before the user confirmed trust. A repository settings file could set ANTHROPIC_BASE_URL to an attacker-controlled endpoint, and Claude Code issued API requests on opening the repository, before the trust prompt appeared.
Fix: Fixed in 2.0.65, which contains a patch. Users on standard auto-update have already received the fix; users performing manual updates should update to version 2.0.65 or the latest version.
NVD/CVE DatabaseCVE-2026-22686: Enclave VM sandbox escape via host Error object prototype chain
Jan 13, 2026CriticalVulnerabilitySecurityCVE-2026-22686CVE-2026-22686 affects enclave-vm, the sandbox component of Enclave, in versions prior to 2.7.0. When a tool invocation fails, enclave-vm passes a host-side Error object into sandboxed code, and that object keeps its host realm prototype chain. Untrusted code can walk that chain to the host Function constructor and run arbitrary JavaScript in the host Node.js runtime, reaching process.env, the filesystem and the network.
Fix: Fixed in 2.7.0.
NVD/CVE DatabaseCVE-2026-22813: OpenCode markdown renderer allows HTML injection leading to script execution
Jan 12, 2026MediumVulnerabilitySecurityCVE-2026-22813CVE-2026-22813 affects OpenCode, an open source AI coding agent. The markdown renderer for LLM responses inserts arbitrary HTML into the DOM without DOMPurify sanitization or a CSP on the web interface, so controlling a chat session's LLM response yields JavaScript execution on the http://localhost:4096 origin. GitHub, Inc. assigned a CVSS 4.0 base score of 9.4 (CRITICAL), while NIST has not yet provided an assessment.
Fix: Fixed in 1.1.10
NVD/CVE DatabaseCVE-2026-22812: OpenCode unauthenticated HTTP server allows arbitrary shell command execution
Jan 12, 2026HighVulnerabilitySecurityCVE-2026-22812EPSS: 16.5%CVE-2026-22812 affects OpenCode, an open source AI coding agent, before version 1.0.216. OpenCode automatically starts an unauthenticated HTTP server, which lets any local process, or any website through permissive CORS, run arbitrary shell commands with the user's privileges. The weakness is classified as CWE-306, CWE-749 and CWE-942.
Fix: Fixed in 1.0.216.
NVD/CVE DatabaseCVE-2025-67510: Neuron MySQLWriteTool executes arbitrary SQL provided by the caller
Dec 10, 2025CriticalVulnerabilitySecurityCVE-2025-67510Neuron, a PHP framework for building and orchestrating AI agents, versions 2.8.11 and below, has a flaw in MySQLWriteTool. The tool runs caller-supplied SQL through PDO::prepare() and execute() with no semantic restrictions. In an agent context, prompt injection or indirect prompt manipulation can make the agent run destructive statements such as DROP TABLE, TRUNCATE, DELETE, ALTER, or privilege-related statements, limited by the database user's permissions. Deployments that expose the tool to untrusted input or run it under a broadly privileged database user are affected.
Fix: This issue is fixed in version 2.8.12.
NVD/CVE DatabaseCVE-2025-67509: Neuron MySQLSelectTool read-only bypass allows file writes via INTO OUTFILE
Dec 10, 2025HighVulnerabilitySecurityCVE-2025-67509Neuron, a PHP framework for building AI agents, has a read-only bypass in MySQLSelectTool in versions 2.8.11 and below. The tool validates queries by checking the first keyword and a forbidden-keyword list, which does not block file-writing constructs such as INTO OUTFILE and INTO DUMPFILE. An attacker who can influence the tool input, for example through prompt injection on a public agent endpoint, can write arbitrary files to the database server if the MySQL or MariaDB account has the FILE privilege and the server configuration permits writes to a useful location, such as a web-accessible directory.
Fix: Fixed in 2.8.12.
NVD/CVE DatabaseCVE-2025-12189: The Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents plugin for…
Dec 5, 2025MediumVulnerabilitySecurityIndustryCVE-2025-12189The Bread & Butter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 7.10.1321. Missing or incorrect nonce validation in the uploadImage() function lets unauthenticated attackers upload arbitrary files, which can enable remote code execution if they trick a site administrator into clicking a link.
NVD/CVE DatabaseCVE-2025-66032: Claude Code command injection via shell parsing of $IFS and short flags
Dec 3, 2025CriticalVulnerabilitySecurityCVE-2025-66032CVE-2025-66032 affects Claude Code, an agentic coding tool, before version 1.0.93. Errors in parsing shell commands related to $IFS and short CLI flags let an attacker bypass the read-only validation and trigger arbitrary code execution. Exploiting it reliably requires the ability to add untrusted content into the Claude Code context window.
Fix: Fixed in 1.0.93.
NVD/CVE DatabaseCVE-2025-65946: Roo Code auto-executes commands outside its allow list prefixes
Nov 21, 2025HighVulnerabilitySecurityCVE-2025-65946CVE-2025-65946 affects Roo Code, an AI-powered autonomous coding agent that runs in users' editors, in versions prior to 3.26.7. A validation error let Roo automatically execute commands that did not match the allow list prefixes. The issue is classified as CWE-77 (Command Injection) and CWE-20 (Improper Input Validation).
Fix: This issue has been patched in version 3.26.7.
NVD/CVE DatabaseCVE-2025-64755: Claude Code read-only validation bypass via sed command parsing
Nov 20, 2025CriticalVulnerabilitySecurityCVE-2025-64755CVE-2025-64755 affects Claude Code, an agentic coding tool, before version 2.0.31. An error in sed command parsing let an attacker bypass the read-only validation and write to arbitrary files on the host system. GitHub, Inc. assigned a CVSS 4.0 base score of 8.7 (High) and classified the weakness as CWE-78 (OS Command Injection).
Fix: Fixed in version 2.0.31.
NVD/CVE DatabaseCVE-2025-65099: Claude Code code execution via Yarn plugins in untrusted directories
Nov 19, 2025CriticalVulnerabilitySecurityCVE-2025-65099CVE-2025-65099 affects Claude Code before version 1.0.39 when it runs on a machine with Yarn 3.0 or above. A project's yarn plugins could execute code before the user accepted the startup trust dialog, provided the user started Claude Code in an untrusted directory.
Fix: This issue has been patched in version 1.0.39.
NVD/CVE DatabaseCVE-2025-62612: FastGPT SSRF in workflow file reading node via unverified network links
Oct 22, 2025MediumVulnerabilitySecurityCVE-2025-62612CVE-2025-62612 affects FastGPT, an AI Agent building platform, prior to version 4.11.1. The workflow file reading node does not verify network links for security, which exposes the platform to server-side request forgery (SSRF, CWE-918). The source rates the issue MEDIUM under CVSS 4.0 (GitHub, Inc., base score 6.9).
Fix: This issue has been patched in version 4.11.1.
NVD/CVE DatabaseCVE-2025-61685: Mastra directory traversal disclosing directory listings
Oct 3, 2025MediumVulnerabilitySecurityCVE-2025-61685Mastra, a TypeScript framework for building AI agents and assistants, is vulnerable in versions 0.13.8 through 0.13.20-alpha.0 to directory traversal. A path traversal check that protects reading file contents is bypassed by later logic that generates directory suggestions, letting an attacker list arbitrary directories on the user's filesystem, including the home directory, and expose details of the file system's structure.
Fix: This issue is fixed in version 0.13.20.
NVD/CVE DatabaseCVE-2025-59829: Claude Code permission deny rules bypassed via symlinks
Oct 3, 2025MediumVulnerabilitySecurityCVE-2025-59829Claude Code versions below 1.0.120 did not account for symlinks when checking permission deny rules. If a user denied Claude Code access to a file, but Claude Code could reach a symlink pointing to that file, Claude Code could still access the file.
Fix: Fixed in version 1.0.120. Standard auto-update installs the fix automatically; users performing manual updates are advised to update to the latest version.
NVD/CVE DatabaseCVE-2025-59536: Claude Code code injection through startup trust dialog
Oct 3, 2025HighVulnerabilitySecurityIndustryCVE-2025-59536EPSS: 27.2%Claude Code versions before 1.0.111 were vulnerable to Code Injection because of a bug in the startup trust dialog. The tool could be tricked into executing code contained in a project before the user accepted the dialog. Exploitation requires a user to start Claude Code in an untrusted directory.
Fix: Fixed in version 1.0.111. Users on standard auto-update received the fix automatically; users performing manual updates are advised to update to the latest version.
NVD/CVE DatabaseCVE-2025-59828: Claude Code trust dialog bypass through Yarn plugin auto-execution
Sep 24, 2025CriticalVulnerabilitySecurityCVE-2025-59828CVE-2025-59828 affects Claude Code before version 1.0.39 when used with Yarn 2.0+. Yarn plugins execute automatically when yarn --version runs, which can bypass the directory trust dialog because plugins run before the user accepts the risks of an untrusted directory. Users of Yarn Classic were not affected.
Fix: This issue has been fixed in version 1.0.39. Users on standard Claude Code auto-update received the fix automatically. Users performing manual updates are advised to update to the latest version.
NVD/CVE DatabaseCVE-2025-59532: Codex CLI sandbox bypass allowing arbitrary file writes and command execution
Sep 22, 2025HighVulnerabilitySecurityCVE-2025-59532CVE-2025-59532 affects Codex CLI, OpenAI's locally run coding agent, in versions 0.2.0 to 0.38.0. A bug in the sandbox configuration logic let Codex CLI treat a model-generated cwd as the sandbox's writable root, even for paths outside the folder where the session started. This bypassed the workspace boundary and enabled arbitrary file writes and command execution with the permissions of the Codex process, though the network-disabled sandbox restriction was not affected.
Fix: Fixed in Codex CLI 0.39.0, which canonicalizes and validates the sandbox policy boundary against where the user started the session rather than the model-generated path. Users on 0.38.0 or earlier should update immediately via their package manager or by reinstalling the latest Codex CLI. Users of the Codex IDE extension should update to 0.4.12.
NVD/CVE DatabaseCVE-2025-55319: Ai command injection in Agentic AI and Visual Studio Code over network
Sep 11, 2025HighVulnerabilitySecurityCVE-2025-55319CVE-2025-55319 is an AI command injection flaw in Agentic AI and Visual Studio Code. An unauthorized attacker can exploit it over a network to execute code. NIST has not yet provided an NVD assessment, and the entry was published 09/11/2025 and last modified 09/24/2025.
NVD/CVE DatabaseCVE-2025-59041: Claude Code code execution via malicious git user email before workspace trust
Sep 10, 2025CriticalVulnerabilitySecurityCVE-2025-59041CVE-2025-59041 affects Claude Code, an agentic coding tool. At startup, Claude Code executed a command templated in with `git config user.email`, so a maliciously configured user email in git could trigger arbitrary code execution before the user accepted the workspace trust dialog in versions prior to 1.0.105.
Fix: Fixed in version 1.0.105. Users on standard Claude Code auto-update received the fix automatically; users performing manual updates are advised to update to version 1.0.105 or the latest version.
NVD/CVE DatabaseCVE-2025-58764: Claude Code confirmation prompt bypass through command parsing error
Sep 10, 2025CriticalVulnerabilitySecurityCVE-2025-58764CVE-2025-58764 affects Claude Code versions prior to 1.0.105. A command parsing error allows the confirmation prompt to be bypassed, triggering execution of an untrusted command. Exploitation reliably requires the ability to add untrusted content into a Claude Code context window.
Fix: Users on standard Claude Code auto-update received the fix automatically. Users performing manual updates are advised to update to version 1.0.105 or the latest version.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.