Prompt injection and jailbreaks
Inputs that override a model's instructions, directly or through content it reads, and attempts to bypass its safeguards.
- All items
- 194
- Last 90 days
- 43
- Change
- -17%vs 52 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 0 |
| Jul 2025 | 3 |
| Aug 2025 | 24 |
| Sep 2025 | 0 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 1 |
| Jan 2026 | 2 |
| Feb 2026 | 7 |
| Mar 2026 | 10 |
| Apr 2026 | 19 |
| May 2026 | 7 |
| Jun 2026 | 15 |
| Jul 2026 | 26 |
| Aug 2026 | 18 |
| Sep 2026 | 7 |
| Oct 2026 | 8 |
56 items
CVE-2026-41318: AnythingLLM stored XSS through chart captions in chat history
Apr 24, 2026MediumVulnerabilitySecurityCVE-2026-41318AnythingLLM versions prior to 1.12.1 contain a stored DOM-level XSS flaw, tracked as CVE-2026-41318. The in-chat markdown renderer interpolates image `alt` text into an HTML attribute without encoding, and the `Chartable` component renders chart captions with no DOMPurify sanitization. An attacker who can influence LLM output, through indirect prompt injection in a shared workspace document or by creating a chart record in a multi-user workspace, can run script in other users' browsers when they open that conversation.
Fix: Patched in version 1.12.1.
NVD/CVE DatabaseGHSA-2r2p-4cgf-hv7h: engram: HTTP server CORS wildcard + auth-off-by-default enables CSRF graph exfiltration and persistent indirect prompt injection
Apr 22, 2026HighVulnerabilitySecuritySafetyThe local HTTP server started by `engram server` (default `127.0.0.1:7337`) accepted requests from any browser origin with no authentication unless `ENGRAM_API_TOKEN` was set. Combined with `Access-Control-Allow-Origin: *` and a body parser that did not require `Content-Type: application/json`, a malicious web page could read the knowledge graph via `GET /query` and `GET /stats`, and write persistent prompt-injection payloads via `POST /learn`, which were later surfaced to the user's AI coding agent. Affected versions are `engramx` >= 1.0.0 and < 2.0.2.
Fix: Fixed in `engramx@2.0.2`. Remediation in 2.0.2 includes fail-closed auth on non-public routes (Bearer header or HttpOnly cookie, constant-time comparison, 256-bit token at `~/.engram/http-server.token`), removal of wildcard CORS with an opt-in allowlist via `ENGRAM_ALLOWED_ORIGINS`, Host and Origin validation, enforced `Content-Type: application/json` on mutations, and a `/ui?token=` bootstrap with a `Sec-Fetch-Site` gate. Workarounds if upgrading is not possible: do not run `engram server` or `engram ui`, or set `ENGRAM_API_TOKEN` to a long random value and stop the server before browsing the web.
GitHub Advisory DatabaseGHSA-3hjv-c53m-58jj: Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
Apr 21, 2026CriticalVulnerabilitySecurityCVE-2026-41264Trend Micro's Zero Day Initiative reports an unauthenticated remote code execution flaw in FlowiseAI Flowise, tested at version 3.0.13. The flaw sits in the run method of the CSV_Agents class, which evaluates an LLM-generated Python script without proper sandboxing. The input validation that checks for forbidden patterns can be bypassed, allowing arbitrary OS commands to run on the server as the user running it.
GitHub Advisory DatabaseGHSA-6r77-hqx7-7vw8: Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains
Apr 16, 2026HighVulnerabilitySecurityFlowiseAI's POST and GET API Chain components build request URLs from LLM output without validating them against the intended API documentation. Unauthenticated attackers can inject a crafted documentation prompt that overrides the BASE URL, causing the server to send arbitrary HTTP requests to internal and external hosts, as demonstrated against /flag on host.docker.internal:8080. The source affects FlowiseAI instances at version 2.2.1 and below.
GitHub Advisory DatabaseCVE-2026-30615: Windsurf prompt injection allows arbitrary command execution via HTML content
Apr 15, 2026CriticalVulnerabilitySecurityCVE-2026-30615A prompt injection flaw in Windsurf 1.9544.26 lets remote attackers run arbitrary commands on a victim system. When Windsurf processes attacker-controlled HTML, injected instructions can modify the local MCP configuration and automatically register a malicious MCP STDIO server, with no further user interaction. Successful exploitation can execute commands as the user, persist the malicious configuration, and expose sensitive information accessible through the application.
NVD/CVE DatabaseGHSA-44c2-3rw4-5gvh: PraisonAI Has SSRF in FileTools.download_file() via Unvalidated URL
Apr 1, 2026HighVulnerabilitySecurityCVE-2026-34954GHSA-44c2-3rw4-5gvh reports an SSRF flaw in FileTools.download_file() in praisonaiagents. The function checks the destination path but passes the caller-supplied url directly to httpx.stream() with follow_redirects=True, so an attacker who controls the URL can reach any host the server can access, including cloud metadata services and internal services. On EC2 instances with IMDSv1 enabled, IAM credentials can be retrieved and written to disk, and the flaw is reachable through indirect prompt injection without authentication.
Fix: Suggested fix: validate the url before the request by allowing only the http and https schemes and blocking loopback, link-local (169.254.0.0/16), and private RFC 1918 address ranges, as shown in the source's _validate_url() example.
GitHub Advisory DatabaseGHSA-w37c-qqfp-c67f: PraisonAI: Shell Injection in run_python() via Unescaped $() Substitution
Apr 1, 2026HighVulnerabilitySecurityCVE-2026-34937PraisonAI's `run_python()` in `praisonai` builds a shell command by placing user-controlled code inside `python3 -c "<code>"` and runs it with `subprocess.run(..., shell=True)`. Its escaping only handles `\` and `"`, so `$()` and backtick substitutions execute as OS commands before Python starts, enabling arbitrary command execution as the process user. The advisory notes the function is reachable through indirect prompt injection, and the auto-generated Flask server ships with `AUTH_ENABLED = False` when no token is configured.
GitHub Advisory DatabaseGHSA-6vh2-h83c-9294: PraisonAI: Python Sandbox Escape via str Subclass startswith() Override in execute_code
Apr 1, 2026CriticalVulnerabilitySecurityCVE-2026-34938The execute_code() function in praisonai-agents runs attacker-controlled Python inside a three-layer sandbox. Passing a str subclass with an overridden startswith() method to the _safe_getattr wrapper bypasses the sandbox, allowing arbitrary OS command execution on the host as the process user. Deployments using bot.py, autonomy_mode.py, or bots_cli.py set PRAISONAI_AUTO_APPROVE=true by default, so the tool can fire without human confirmation when triggered via indirect prompt injection.
GitHub Advisory DatabaseCVE-2026-4399: 1millionbot Millie chatbot prompt injection evades chat restrictions
Mar 31, 2026HighVulnerabilitySecuritySafetyCVE-2026-4399CVE-2026-4399 is a prompt injection vulnerability in the 1millionbot Millie chatbot. A user can evade chat restrictions with Boolean prompt injection, phrasing a question so that an affirmative ('true') reply causes the model to execute the injected instruction. A remote attacker could then obtain prohibited or out-of-context information, use 1millionbot's resources or OpenAI's API key for unintended tasks, and bypass restrictions set during model training.
NVD/CVE DatabaseCVE-2026-33654: nanobot indirect prompt injection through email channel processing
Mar 27, 2026HighVulnerabilitySecuritySafetyCVE-2026-33654CVE-2026-33654 affects nanobot, a personal AI assistant, prior to version 0.1.6. An indirect prompt injection flaw in the email channel processing module (`nanobot/channels/email.py`) lets a remote, unauthenticated attacker run arbitrary LLM instructions, and then system tools, by sending an email to the bot's monitored address. The bot polls and processes that content as highly trusted input, bypassing channel isolation, so the attack needs no action from the bot owner.
Fix: Version 0.1.6 patches the issue. Upgrade to 0.1.6 or later.
NVD/CVE DatabaseGHSA-67q9-58vj-32qx: WeKnora Vulnerable to Tool Execution Hijacking via Ambigous Naming Convention In MCP client and Indirect Prompt Injection
Mar 6, 2026MediumVulnerabilitySecurityCVE-2026-30856WeKnora's MCP client builds internal tool names as `mcp_{service}_{tool}` after sanitizing each part, and its registry (`internal/agent/tools/registry.go`) silently overwrites existing entries. A malicious remote MCP server can register a tool such as `tavily_extract` that replaces the legitimate one, and the client also feeds MCP tool descriptions and results into the LLM context without sanitization. The source states that this lets an attacker redirect LLM execution, exfiltrate system prompts and context, and potentially run other tools with the user's privileges, with a precondition that the user registers the malicious service before the legitimate one.
GitHub Advisory DatabaseGHSA-g27f-9qjv-22pm: OpenClaw log poisoning (indirect prompt injection) via WebSocket headers
Feb 17, 2026LowVulnerabilitySecuritySafetyOpenClaw versions up to and including 2026.2.12 logged WebSocket request headers such as Origin and User-Agent without neutralization or length limits when a connection closed before the connect handshake completed. An unauthenticated client that can reach the gateway can send crafted header values that are written into core logs. The main risk is indirect prompt injection (log poisoning) when those logs are later read by an LLM, and the advisory says impact is limited if logs are not fed into an LLM or other automation.
Fix: Fixed in 2026.2.13 (openclaw >= 2026.2.13), which sanitizes and truncates header values written to gateway logs, including removal of control and format characters and length limiting. Fix commits: d637a263505448bf4505b85535babbfaacedbaac, e84318e4bcdc948d92e57fda1eb763a65e1774f0 (PR #15592). Additional workarounds: treat logs as untrusted input during AI-assisted debugging (sanitize or escape them, and do not auto-execute instructions derived from logs), restrict gateway network exposure, and apply reverse-proxy limits on header size where applicable.
GitHub Advisory DatabaseGHSA-782p-5fr5-7fj8: OpenClaw Affected by Remote Code Execution via System Prompt Injection in Slack Channel Descriptions
Feb 17, 2026LowVulnerabilitySecurityCVE-2026-24764OpenClaw versions before 2026.2.3 let Slack channel topic and description metadata enter the model's system prompt when the Slack integration is enabled. That treats untrusted channel text as higher-trust input, and in deployments with tool execution enabled, a successful injection could cause unintended tool invocations or data exposure.
Fix: Upgrade the npm package `openclaw` to version 2026.2.3 or later. If Slack is not used, no action is required.
GitHub Advisory DatabaseCVE-2026-22708: Cursor shell built-ins bypass allowlist approval in Auto-Run Mode
Jan 14, 2026CriticalVulnerabilitySecurityCVE-2026-22708CVE-2026-22708 affects Cursor, a code editor built for programming with AI, prior to 2.3. When the Cursor Agent runs in Auto-Run Mode with Allowlist mode enabled, certain shell built-ins can execute without appearing in the allowlist and without user approval. An attacker using direct or indirect prompt injection can set, modify, or remove environment variables that influence trusted commands, poisoning the shell environment.
Fix: Fixed in 2.3.
NVD/CVE DatabaseCVE-2025-66404: MCP Server Kubernetes command injection in exec_in_pod tool
Dec 3, 2025MediumVulnerabilitySecurityCVE-2025-66404CVE-2025-66404 affects the exec_in_pod tool in mcp-server-kubernetes, an MCP Server that connects to and manages Kubernetes clusters, in versions prior to 2.9.8. When the tool receives a command as a string, it is passed directly to sh -c without input validation, so shell metacharacters are interpreted. Exploitation can occur through direct command injection or through indirect prompt injection, where AI agents may run commands without explicit user intent.
Fix: Fixed in 2.9.8.
NVD/CVE DatabaseCVE-2025-64108: Cursor NTFS path quirks allow file overwrite via prompt injection
Nov 4, 2025HighVulnerabilitySecurityCVE-2025-64108CVE-2025-64108 affects Cursor, a code editor built for programming with AI, in versions 1.7.44 and below. Various NTFS path quirks let a prompt injection attacker bypass sensitive file protections and overwrite files that Cursor normally requires human approval to overwrite. Modifying some of these protected files can lead to RCE, and the issue must be chained with a prompt injection or malicious model attack and only affects systems supporting NTFS.
Fix: Fixed in version 2.0.
NVD/CVE DatabaseCVE-2025-62356: Qodo Gen IDE path traversal enables arbitrary local file read
Oct 17, 2025HighVulnerabilitySecurityCVE-2025-62356CVE-2025-62356 is a path traversal vulnerability in all versions of the Qodo Qodo Gen IDE, classified as CWE-22. A threat actor can read arbitrary local files in and outside of current projects on an end user's system. The vulnerability can be reached directly and through indirect prompt injection.
NVD/CVE DatabaseCVE-2025-62353: Windsurf IDE path traversal allowing arbitrary local file read and write
Oct 17, 2025CriticalVulnerabilitySecurityCVE-2025-62353CVE-2025-62353 is a path traversal vulnerability (CWE-22) in all versions of the Windsurf IDE. It lets a threat actor read and write arbitrary local files inside and outside current projects on an end user's system. The flaw can be reached directly or through indirect prompt injection.
NVD/CVE DatabaseCVE-2025-36730: Windsurf prompt injection via crafted file name in Write mode
Oct 14, 2025MediumVulnerabilitySecurityCVE-2025-36730CVE-2025-36730 describes a prompt injection vulnerability in Windsurft version 1.10.7 when used in Write mode with the SWE-1 model. An attacker can create a file name that is appended to the user prompt, causing Windsurf to follow instructions embedded in that name. Tenable Network Security, Inc. is the CNA, rating it CVSS 4.0 MEDIUM (4.6), and NIST has not yet provided an assessment.
NVD/CVE DatabaseCVE-2025-61589: Cursor data exfiltration through Mermaid image rendering in chat
Oct 3, 2025MediumVulnerabilitySecurityCVE-2025-61589CVE-2025-61589 affects Cursor, a code editor built for programming with AI, in versions 1.6 and below. Mermaid diagram rendering allows embedded images that Cursor renders in the chat box, and an attacker can use this after a successful prompt injection to exfiltrate sensitive information to an attacker-controlled server through an image fetch. A malicious model, hallucination or backdoor might also trigger the exploit, and the issue requires prompt injection from malicious data such as web content, image uploads or source code. Additional bypasses not covered by the initial fix were found and are described in GHSA-43wj-mwcc-x93p.
Fix: Fixed in version 1.7.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.