AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 763
- Last 90 days
- 325
- Change
- +44%vs 225 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 38 |
159 items
CVE-2025-58374: Roo Code arbitrary code execution through npm install auto-approval
Sep 5, 2025HighVulnerabilitySecurityCVE-2025-58374Roo Code versions 3.25.23 and below ship a default allowlist of commands that run without manual approval when auto-approve is enabled, and that list includes npm install. Because npm install executes lifecycle scripts, a malicious postinstall script in a repository's package.json runs automatically, so opening a malicious repo with auto-approved commands enabled can lead to arbitrary code execution.
Fix: Fixed in version 3.26.0.
NVD/CVE DatabaseCVE-2025-58373: Roo Code .rooignore bypass via symlinks exposes excluded files
Sep 5, 2025MediumVulnerabilitySecurityCVE-2025-58373Roo Code versions 3.25.23 and below contain a flaw where .rooignore exclusions can be bypassed using symlinks. An attacker with write access to the workspace can trick the extension into reading files meant to be excluded, such as .env or configuration files, exposing secrets and other excluded project data.
Fix: Fixed in version 3.26.0.
NVD/CVE DatabaseCVE-2025-58372: Roo Code arbitrary code execution via unprotected .code-workspace files
Sep 5, 2025HighVulnerabilitySecurityCVE-2025-58372Roo Code, an AI-powered autonomous coding agent for editors, versions 3.25.23 and below, does not protect VS Code .code-workspace files the way it protects the .vscode folder. If the agent auto-approves file writes, an attacker who can influence its prompts, for example through prompt injection, can have malicious workspace settings or tasks written. Those tasks run automatically when the workspace is reopened, leading to arbitrary code execution.
Fix: Fixed in version 3.26.0.
NVD/CVE DatabaseCVE-2025-58371: Roo Code GitHub workflow code execution via unsanitized pull request metadata
Sep 5, 2025CriticalVulnerabilitySecurityCVE-2025-58371CVE-2025-58371 affects Roo Code, an AI-powered autonomous coding agent, in versions 3.26.6 and below. A GitHub workflow used unsanitized pull request metadata in a privileged context, so an attacker can craft input that achieves Remote Code Execution on the Actions runner. Because the workflow runs with broad permissions and access to repository secrets, the attacker can run arbitrary commands, modify code, access secrets and create malicious releases or packages, fully compromising the repository and its associated services.
Fix: Fixed in version 3.26.7.
NVD/CVE DatabaseCVE-2025-58370: Roo Code command parsing flaw allows arbitrary command execution via prompts
Sep 5, 2025HighVulnerabilitySecurityCVE-2025-58370CVE-2025-58370 affects Roo Code, an AI-powered autonomous coding agent, in versions below 3.26.0. The command parsing logic mishandles Bash parameter expansion and indirect references, so when the agent is configured to auto-approve certain commands, an attacker who can influence prompts can get additional arbitrary commands executed alongside the intended one. The weakness is classified as CWE-78, OS Command Injection.
Fix: This is fixed in version 3.26.0.
NVD/CVE DatabaseCVE-2025-57771: Roo Code command injection in auto-approved command parsing
Aug 22, 2025HighVulnerabilitySecurityCVE-2025-57771CVE-2025-57771 affects Roo Code, an AI-powered autonomous coding agent, in versions prior to 3.25.5. The command parsing logic does not properly handle process substitution and single ampersand characters for auto-execute commands, so an attacker who can submit crafted prompts may inject arbitrary commands to run alongside an intended command such as ls. Exploitation requires prompt submission access and that the user has enabled auto-approved command execution, which is disabled by default; the source states this could allow arbitrary code execution.
Fix: Fixed in version 3.25.5.
NVD/CVE DatabaseCVE-2025-55284: Claude Code confirmation prompt bypass allows network file exfiltration
Aug 15, 2025HighVulnerabilitySecurityCVE-2025-55284Claude Code versions prior to 1.0.4 contain an overly broad allowlist of safe commands. This lets an attacker bypass confirmation prompts to read a file and send its contents over the network without user approval. Reliable exploitation requires the ability to insert untrusted content into a Claude Code context window.
Fix: Fixed in version 1.0.4. Users on standard auto-update received the fix automatically after release. Versions prior to 1.0.24 are deprecated and have been forced to update, so current users are unaffected.
NVD/CVE DatabaseCVE-2025-55012: Zed Agent Panel allows remote code execution via permissions bypass
Aug 11, 2025HighVulnerabilitySecurityIndustryCVE-2025-55012Prior to version 0.197.3 of Zed, a multiplayer code editor, the Zed Agent Panel let an AI agent bypass user permission checks. By exploiting this, an agent could create or modify a project-specific configuration file and execute arbitrary commands on a victim's machine without the explicit approval normally required, achieving Remote Code Execution (RCE).
Fix: Fixed in version 0.197.3. Workaround: avoid sending prompts to the Agent Panel, or limit the AI Agent's file system access.
NVD/CVE DatabaseCVE-2025-54795: Claude Code command parsing flaw bypasses confirmation prompt
Aug 4, 2025CriticalVulnerabilitySecurityCVE-2025-54795CVE-2025-54795 affects Claude Code versions below 1.0.20. An error in command parsing lets an attacker bypass the Claude Code confirmation prompt and trigger execution of an untrusted command, classified as CWE-78. Exploiting it reliably requires the ability to add untrusted content into a Claude Code context window.
Fix: Fixed in version 1.0.20.
NVD/CVE DatabaseCVE-2025-54794: Claude Code path validation flaw exposes files outside working directory
Aug 4, 2025CriticalVulnerabilitySecurityCVE-2025-54794CVE-2025-54794 affects Claude Code versions below 0.2.111. A path validation flaw compares path prefixes instead of canonical paths, which lets an attacker bypass directory restrictions and access files outside the CWD. Exploitation requires a directory sharing the CWD's prefix that exists or can be created, plus the ability to add untrusted content into a Claude Code context window. GitHub, Inc. rates it CVSS 4.0 7.7 (High).
Fix: Fixed in version 0.2.111.
NVD/CVE DatabaseCVE-2025-54377: Roo Code allow-list bypass via multi-line command injection
Jul 23, 2025HighVulnerabilitySecurityCVE-2025-54377Roo Code, an AI-powered autonomous coding agent for editors, versions 3.23.18 and below, does not validate line breaks (\n) in its command input. This allows a bypass of the allow-list mechanism, since only the first line or token may be considered when commands are evaluated, so additional commands in subsequent lines can run.
Fix: Fixed in version 3.23.19.
NVD/CVE DatabaseCVE-2025-53536: Roo Code code execution via auto-approved Write to VS Code settings
Jul 7, 2025HighVulnerabilitySecurityCVE-2025-53536CVE-2025-53536 affects Roo Code, an AI-powered autonomous coding agent, prior to 3.22.6. When the victim had "Write" auto-approved, an attacker able to submit prompts to the agent could write to VS Code settings files and trigger code execution. One example uses the php.validate.executablePath setting, where the attacker sets an arbitrary command as the PHP path and then creates a PHP file to trigger it.
Fix: Fixed in 3.22.6.
NVD/CVE DatabaseCVE-2025-53098: Roo Code arbitrary command execution via MCP configuration file writes
Jun 27, 2025HighVulnerabilitySecurityCVE-2025-53098Roo Code, an AI-powered autonomous coding agent, stored project-specific MCP configuration in `.roo/mcp.json` within the VS Code workspace. Before version 3.20.3, an attacker who could submit prompts to the agent could have it write a malicious command into that file, leading to arbitrary command execution if the user had enabled auto-approved file writes.
Fix: Fixed in 3.20.3, which adds an additional opt-in configuration layer for auto-approving writes to Roo's configuration files, including all files within the `.roo/` folder.
NVD/CVE DatabaseCVE-2025-53097: Roo Code search_files tool reads files outside VS Code workspace
Jun 27, 2025MediumVulnerabilitySecurityCVE-2025-53097Roo Code, an AI-powered autonomous coding agent, prior to version 3.20.3 had a flaw where the `search_files` tool ignored the setting that disables reads outside the VS Code workspace. An attacker who could inject a prompt into the agent could read a sensitive file and write its contents into a JSON schema, which triggered a network request by default without user confirmation. The issue is rated moderate because the attacker must already be able to submit prompts to the agent.
Fix: Fixed in 3.20.3: `search_files` now respects the setting that limits it to the workspace.
NVD/CVE DatabaseCVE-2025-52882: Claude Code IDE extensions allow unauthorized websocket connections
Jun 24, 2025HighVulnerabilitySecurityCVE-2025-52882CVE-2025-52882 affects Claude Code extensions for VSCode and its forks, such as Cursor, Windsurf, and VSCodium, as well as the JetBrains plugin Claude Code [Beta]. Visiting attacker-controlled webpages lets an attacker make unauthorized websocket connections to the IDE. Exploitation can read arbitrary files, list open files, and obtain selection and diagnostics events, and in VSCode it can also execute code in limited cases involving an open Jupyter Notebook and an accepted malicious prompt.
Fix: Claude released a patch on June 13, 2025. For VSCode and forks, update or uninstall Claude Code for VSCode versions prior to 1.0.24, then restart the IDE. For JetBrains IDEs, update or uninstall Claude Code [Beta] versions prior to 0.1.9, then restart the IDE.
NVD/CVE DatabaseCVE-2025-52552: FastGPT login page LastRoute parameter open redirect and DOM-based XSS
Jun 20, 2025MediumVulnerabilitySecurityCVE-2025-52552CVE-2025-52552 affects FastGPT, an AI Agent building platform, before version 4.9.12. The LastRoute parameter on the login page is vulnerable to open redirect (CWE-601) and DOM-based cross-site scripting (CWE-79). Because the parameter is improperly validated and not sanitized, attackers can run malicious JavaScript or redirect users to attacker-controlled sites.
Fix: Fixed in version 4.9.12.
NVD/CVE DatabaseCVE-2025-48491: Project AI hardcoded API key
May 30, 2025HighVulnerabilitySecurityCVE-2025-48491The source text is NIST NVD navigation material: a disclaimer about external links and a list of GitHub commit and advisory URLs for CVE-2025-48491 in the Project AI platform for creating AI agents. It does not describe the flaw, the affected versions or the impact, beyond the title's note that before the pre-beta version a hardcoded API key was present.
NVD/CVE DatabaseCVE-2024-43396: Khoj stored XSS through Automation feature task instructions
Aug 20, 2024MediumVulnerabilitySecurityCVE-2024-43396CVE-2024-43396 affects Khoj, an application that creates personal AI agents. The Automation feature does not sanitize the q parameter for the /api/automation endpoint when it is rendered on the page, so a user can inject arbitrary HTML and JavaScript, resulting in Stored XSS (CWE-79).
Fix: This vulnerability is fixed in 1.15.0.
NVD/CVE DatabaseCVE-2024-25639: Khoj cross-site scripting via prompt injection from untrusted documents
Jul 8, 2024MediumVulnerabilitySecurityCVE-2024-25639CVE-2024-25639 affects the Khoj Obsidian, Desktop and Web clients, which inadequately sanitize the AI model's response and user inputs. Untrusted documents, whether indexed by the user or read from the internet via the /online command, can trigger Cross Site Scripting (XSS) through Prompt Injection.
Fix: Fixed in 1.13.0.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.