AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 762
- Last 90 days
- 324
- Change
- +44%vs 225 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 37 |
159 items
CVE-2026-108263: Astron Agent code-node execution as root through workflow run endpoints
Oct 9, 2026CriticalVulnerabilitySecurityCVE-2026-108263Astron Agent, an agentic workflow platform, prior to 1.1.2 defaults its workflow code-node path (/console-api/workflow/code/run and /workflow/v1/run) to LocalExecutor in core/workflow/engine/nodes/code/code_node.py unless CODE_EXEC_TYPE is changed. LocalExecutor exposes full Python builtins to dynamic code without the documented sandbox restrictions. An authenticated low-privilege tenant can run code as root in the core-workflow container and use shared credentials to bypass tenant checks, read or modify other tenants' data, and disrupt shared services.
Fix: This issue is fixed in version 1.1.2.
NVD/CVE DatabaseCVE-2026-107288: Pydantic AI web fetch bypasses blocked_domains via hostname variants
Oct 8, 2026LowVulnerabilitySecurityCVE-2026-107288Pydantic AI versions from 1.77.0 up to 1.107.6, and 2.44.0, compare blocked_domains entries against URL hostnames before normalization in the local web_fetch_tool and WebFetch fallback. An attacker-influenced model can use an equivalent spelling, such as an IDNA form, non-ASCII label separator, case variation, or trailing root label, that resolves to a blocked host but fails the string match, so the application fetches that host with its own privileges. allowed_domains fails closed on unmatched spellings, and private-IP and cloud-metadata protections remain effective.
Fix: This issue is fixed in versions 1.107.6 and 2.44.0.
NVD/CVE DatabaseCVE-2026-107286: Pydantic AI streamed requests leak concurrency slots, causing denial of service
Oct 8, 2026HighVulnerabilitySecurityCVE-2026-107286Pydantic AI versions 2.10.0 through 2.53.0 have a flaw in streamed requests made through ConcurrencyLimitedModel or limit_model_concurrency. Because anyio.CapacityLimiter ties an acquired slot to the borrowing task while streaming cleanup can run in a different task, early termination, cancellation, consumer exceptions, or complete stream_text() consumption with debounce_by=0.1 can leave shared concurrency slots occupied. Later requests on the long-lived limiter can then be blocked, causing a denial of service. Agent-level max_concurrency and non-streaming model requests are not affected.
Fix: Fixed in version 2.53.0.
NVD/CVE DatabaseCVE-2026-82627: Uncanny Automator WordPress plugin PHP object injection via deserialization
Oct 7, 2026HighVulnerabilitySecurityIndustryCVE-2026-82627CVE-2026-82627 affects The Uncanny Automator AI + Automation plugin for WordPress in all versions up to and including 7.6.1.1. The flaw is PHP Object Injection via deserialization of untrusted input, which lets an authenticated user with Subscriber-level access or higher inject a PHP object when a third-party integration plugin such as PeepSo, MailPoet or WPForms is installed and a recipe stores attacker-controlled data as trigger meta. A POP chain within Uncanny Automator allows the attacker to delete arbitrary files on the server.
NVD/CVE DatabaseCVE-2026-55157: Token Optimizer MCP OS command injection through smart_user username argument
Sep 28, 2026HighVulnerabilitySecurityCVE-2026-55157Prior to version 5.1.0, token-optimizer-mcp is vulnerable to OS command injection in the smart_user tool. Any MCP client that can call smart_user can run arbitrary shell commands through the username argument of the get-user-info operation, with the privileges of the user running the server.
Fix: This issue has been patched in version 5.1.0.
NVD/CVE DatabaseCVE-2026-55156: Token Optimizer MCP dashboard path traversal via sessionId in session endpoints
Sep 28, 2026MediumVulnerabilitySecurityCVE-2026-55156Token Optimizer MCP versions before 5.1.0 run a dashboard HTTP server whose /api/session-summary and /api/session-events endpoints have no authentication middleware. Both handlers join the caller-supplied sessionId query parameter into a filesystem path with path.join, and Node.js normalizes .. segments, so an unauthenticated network client can read any .jsonl file the server can access.
Fix: This issue has been patched in version 5.1.0.
NVD/CVE DatabaseCVE-2026-101065: Obot Docker quickstart exposes admin access without authentication
Sep 27, 2026CriticalVulnerabilitySecurityCVE-2026-101065Obot, an open-source AI agent and MCP platform, documents a Docker quickstart that starts the container on 0.0.0.0:8080 with authentication disabled by default in all versions up to and including commit d7e6970 (CVE-2026-101065). Unauthenticated users who can reach the port receive a synthetic "nobody" user holding the Owner and Admin roles, which grants full control of the Obot API and UI, including registering and launching attacker-controlled MCP servers. The quickstart also mounts /var/run/docker.sock, giving the MCP runtime backend access to the host's Docker control surface.
Fix: The fix is documentation-only: the quickstart now enables authentication. Operators who followed the previous instructions should set OBOT_SERVER_ENABLE_AUTHENTICATION=true before exposing the host to any untrusted network.
NVD/CVE DatabaseCVE-2026-84462: Zammad security filter bypass in AI Agent configuration fields
Sep 25, 2026HighVulnerabilitySecuritySafetyCVE-2026-84462Zammad, a web-based open source helpdesk and customer support system, has a flaw before version 7.1.2. A security filter protecting its AI Agent configuration can be bypassed by entering specially crafted text into an AI Agent field. An administrator with permission to create or edit AI Agents could run arbitrary commands on the host server, potentially reading, modifying, or destroying all stored data. No action from other users is required, since the malicious code executes the next time the affected AI Agent processes a ticket.
Fix: Fixed in version 7.1.2.
NVD/CVE DatabaseCVE-2026-95985 - Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces
Sep 24, 2026HighVulnerabilitySecurityIndustryCVE-2026-95985 affects the file write tool in Kiro IDE, an agentic desktop IDE, before version 1.0.242. The flaw may let remote unauthenticated actors execute arbitrary commands and inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository opened as an untrusted workspace, sending any message can cause the agent to modify auto-loaded global configuration paths.
Fix: Fixed in 1.0.242 or later. Impacted versions: < 1.0.242.
AWS Security BulletinsCVE-2026-93529: Contributor Broken Access Control in WSP MCP – AI Agents Connector <= 2.7.0 versions.
Sep 23, 2026MediumVulnerabilitySecurityCVE-2026-93529CVE-2026-93529 is a Contributor Broken Access Control flaw in WSP MCP – AI Agents Connector, affecting versions up to and including 2.7.0. The source text provides no further detail on how the flaw is reached or what an attacker gains.
NVD/CVE DatabaseCVE-2026-88978: Hatchet cross-tenant data exposure through WorkerStatus gRPC polling
Sep 21, 2026MediumVulnerabilitySecurityCVE-2026-88978Hatchet, a platform for orchestrating background tasks, AI agents, and durable workflows, has a flaw in versions before 0.106.1. The WorkerStatus gRPC polling path in pkg/repository/durable_events.go passes caller-supplied durable task, node, and branch identifiers to ListSatisfiedEntries without a tenant filter. An authenticated tenant worker that knows another tenant's durable-task UUID can retrieve matching durable event-log records. The source notes that the UUIDv4 requirement makes exploitation unlikely and that single-tenant deployments are unaffected in practice.
Fix: This issue is fixed in version 0.106.1.
NVD/CVE DatabaseCVE-2026-84298: Hatchet durable task stream leaks callback results across tenants
Sep 21, 2026LowVulnerabilitySecurityCVE-2026-84298CVE-2026-84298 affects Hatchet versions before 0.95.3. The V1 DurableTask stream handler stores worker-supplied task_external_id values in the durableInvocations routing map before verifying tenant ownership, and callback delivery looks up that map by task UUID without tenant identity. An authenticated tenant worker that knows another tenant's durable task UUID, and keeps a stream open on the same dispatcher process, can receive that task's durable callback result payload. UUIDv4 values are not enumerable, and single-tenant deployments are unaffected in practice.
Fix: This issue is fixed in version 0.95.3.
NVD/CVE DatabaseCVE-2026-63342: Hatchet durable task event log readable across tenants by UUID
Sep 21, 2026MediumVulnerabilitySecurityCVE-2026-63342Hatchet, a platform for orchestrating background tasks, AI agents and durable workflows, has a flaw prior to 0.91.1. The GET /api/v1/stable/durable-tasks/{durable-task} endpoint, implemented by listDurableEventLog, does not require the target tenant as a parent resource. An authenticated user who obtains another tenant's durable task UUID can read that task's event log, which can expose task display names, workflow identifiers, user messages, wait conditions, branching logic and timing information.
Fix: Fixed in 0.91.1.
NVD/CVE DatabaseCVE-2026-61687: Hatchet OAuth state validation flaw allows session binding to attacker identity
Sep 21, 2026HighVulnerabilitySecurityCVE-2026-61687CVE-2026-61687 affects Hatchet, a platform for orchestrating background tasks, AI agents, and durable workflows, in versions prior to 0.91.1. ValidateOAuthState clears the oauth_state_ session value to an empty string after a successful OAuth callback, then accepts an empty state parameter as equal, letting an unauthenticated attacker bind a victim's session to an attacker-controlled OAuth identity. Exploitation requires the victim to have completed an OAuth flow in the current session and auth.google.enabled, auth.github.enabled, or the Slack integration to be enabled.
Fix: Fixed in version 0.91.1.
NVD/CVE DatabaseCVE-2026-61681: Hatchet SNS subscription handler server-side request forgery via UnsubscribeURL
Sep 21, 2026MediumVulnerabilitySecurityCVE-2026-61681Hatchet, a platform for orchestrating background tasks, AI agents and durable workflows, prior to 0.91.1 has a flaw in the SNS UnsubscribeConfirmation handler in internal/integrations/ingestors/sns/sns.go. The handler calls http.Get() on payload.UnsubscribeURL after VerifyPayload(), but BuildSignature() excludes that field, so an authenticated tenant can replace it with an internal URL in an otherwise valid AWS-signed message. The resulting server-side request can reach the EC2 Instance Metadata Service, internal services and internal HTTP APIs, potentially exposing IAM credentials or network-accessible data and functionality.
Fix: Fixed in 0.91.1
NVD/CVE DatabaseCVE-2026-54520: AI Agent Automation path traversal in executeStep file steps
Sep 17, 2026HighVulnerabilitySecurityCVE-2026-54520AI Agent Automation, a modular AI agent workflow platform, is affected by CVE-2026-54520 in versions prior to 0.9.1. The executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.path value through path.resolve with process.cwd() and uses the result for reads or writes without confirming it stays inside an approved workflow directory. An authenticated user who can create or modify workflow file steps can use traversal segments to read sensitive files or write and overwrite files the backend process can access, including application-adjacent files when process permissions allow.
Fix: Fixed in 0.9.1.
NVD/CVE DatabaseCVE-2026-54519: AI Agent Automation memory controller lacks ownership checks
Sep 17, 2026HighVulnerabilitySecurityPrivacyCVE-2026-54519AI Agent Automation versions prior to 0.9.1 contain an authorization flaw in backend/src/controllers/memory.controller.js. The listMemories, deleteMemory, and clearAgentMemory functions accept a caller-supplied agentId or memory _id without checking that the related Agent belongs to req.user. An authenticated attacker who knows or obtains another user's identifiers can read that user's AgentMemory content, delete an individual memory, or clear all memory for a victim agent.
Fix: Fixed in 0.9.1.
NVD/CVE DatabaseCVE-2026-54504: MCP Documentation Server Web UI exposes unauthenticated document API
Sep 17, 2026HighVulnerabilitySecurityCVE-2026-54504MCP Documentation Server versions 1.13.0 through 1.13.1 start a Web UI by default on port 3080, and startWebServer in src/web-server.ts calls app.listen(PORT) without a host, binding the unauthenticated document-management API to all interfaces instead of localhost. A network-reachable client can call endpoints such as GET /api/documents, POST /api/documents, DELETE /api/documents/:id and POST /api/search-all without credentials to read, search, insert or delete documents and alter the assistant's knowledge base. The attacker must be able to reach the service over a LAN, VM network, container bridge, VPN or other routed network, and the issue does not grant remote code execution.
Fix: Fixed in 1.13.1.
NVD/CVE DatabaseCVE-2026-57586: CodeRAG sync runs repository gradlew wrapper, enabling code execution
Sep 15, 2026HighVulnerabilitySecurityCVE-2026-57586CodeRAG versions prior to 1.3.1 execute repository-controlled code during the default agent-coderag sync flow. When build.gradle or build.gradle.kts is present, _sync_gradle runs a repository-supplied gradlew or gradlew.bat via asyncio.create_subprocess_exec, and validate_path checks only the directory, not the executable's content or integrity. Indexing an attacker-controlled Gradle repository therefore runs attacker code with the victim's operating-system privileges, enabling disclosure, modification, persistence, or denial of service.
Fix: Fixed in 1.3.1.
NVD/CVE DatabaseCVE-2026-19136: Tianxi AI Agent PC Application command injection via crafted link
Sep 10, 2026HighVulnerabilitySecurityCVE-2026-19136A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, which is distributed exclusively in the Chinese market. A local user who opens a specially crafted link handled by the application could allow operating system commands to be executed.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.