Prompt injection and jailbreaks
Inputs that override a model's instructions, directly or through content it reads, and attempts to bypass its safeguards.
- All items
- 194
- Last 90 days
- 43
- Change
- -17%vs 52 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 0 |
| Jul 2025 | 3 |
| Aug 2025 | 24 |
| Sep 2025 | 0 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 1 |
| Jan 2026 | 2 |
| Feb 2026 | 7 |
| Mar 2026 | 10 |
| Apr 2026 | 19 |
| May 2026 | 7 |
| Jun 2026 | 15 |
| Jul 2026 | 26 |
| Aug 2026 | 18 |
| Sep 2026 | 7 |
| Oct 2026 | 8 |
56 items
CVE-2025-54135: Cursor writes in-workspace files without user approval
Aug 4, 2025HighVulnerabilitySecurityCVE-2025-54135Cursor, an AI-assisted code editor, allows writing files inside the workspace without user approval in versions below 1.3.9. Approval is required to edit an existing dotfile but not to create a new one, so when a sensitive file such as .cursor/mcp.json does not yet exist, an attacker can chain an indirect prompt injection to hijack the context, write the settings file, and trigger RCE on the victim without approval.
Fix: Fixed in version 1.3.9.
NVD/CVE DatabaseCVE-2025-54130: Cursor writes in-workspace files without user approval
Aug 4, 2025HighVulnerabilitySecurityCVE-2025-54130Cursor, an AI-assisted code editor, allows in-workspace file writes without user approval in versions less than 1.3.9. Creating a new dotfile does not require approval, even though editing an existing one does. If files such as .vscode/settings.json do not already exist, an attacker can chain an indirect prompt injection to hijack the context, write the settings file, and trigger RCE on the victim without approval.
Fix: Fixed in version 1.3.9.
NVD/CVE DatabaseCVE-2025-54132: Cursor data exfiltration through Mermaid image rendering in chat
Aug 1, 2025MediumVulnerabilitySecurityCVE-2025-54132CVE-2025-54132 affects Cursor, a code editor built for programming with AI, in versions below 1.3. Mermaid diagram rendering allows embedded images that Cursor displays in the chat box, and an attacker can use this to exfiltrate sensitive information to an attacker-controlled server via an image fetch after a successful prompt injection. The flaw can also be triggered by a malicious or backdoored model, and exploitation requires prompt injection from malicious data such as web content, image uploads or source code.
Fix: Fixed in version 1.3.
NVD/CVE DatabaseCVE-2025-54131: Cursor allow list bypass in auto-run mode via backtick or command substitution
Aug 1, 2025MediumVulnerabilitySecurityCVE-2025-54131CVE-2025-54131 affects Cursor, a code editor built for programming with AI, in versions below 1.3. When a user has switched from the default approval-for-every-terminal-call setting to an allowlist, an attacker can bypass the allow list in auto-run mode using a backtick (`) or $(cmd) and execute arbitrary commands without user approval. The flaw can be triggered when chained with indirect prompt injection.
Fix: This is fixed in version 1.3.
NVD/CVE DatabaseCVE-2025-46059: langchain-ai GmailToolkit indirect prompt injection via crafted email
Jul 29, 2025CriticalVulnerabilitySecurityCVE-2025-46059CVE-2025-46059 describes an indirect prompt injection flaw in the GmailToolkit component of langchain-ai v0.3.51. According to the description, a crafted email message can lead attackers to execute arbitrary code and compromise the application. The supplier disputes the entry, stating that the code-execution issue comes from user-written code that does not follow LangChain security practices.
NVD/CVE DatabaseCVE-2025-53107: @cyanheads/git-mcp-server command injection via unsanitized input
Jul 1, 2025HighVulnerabilitySecurityCVE-2025-53107EPSS: 24.5%@cyanheads/git-mcp-server, an MCP server for Git repositories, prior to version 2.1.5 has a command injection flaw. Unsanitized input parameters are passed into a child_process.exec call, so an attacker can inject shell metacharacters such as |, >, and && to run arbitrary system commands with the server process's privileges, potentially leading to remote code execution. An MCP client can also be steered into this through indirect prompt injection when asked to read git logs.
Fix: This issue has been patched in version 2.1.5.
NVD/CVE DatabaseCVE-2024-12366: PandasAI prompt injection leads to arbitrary Python code execution
Feb 11, 2025CriticalVulnerabilitySecurityCVE-2024-12366CVE-2024-12366 affects PandasAI, which uses an interactive prompt function that is vulnerable to prompt injection. Attackers can run arbitrary Python code through it, leading to Remote Code Execution (RCE) in place of the intended natural language explanation from the LLM. NVD has not yet provided an assessment, and the entry was published 02/11/2025 with source CERT/CC.
NVD/CVE DatabaseCVE-2024-48142: Monica ChatGPT AI Assistant prompt injection in chatbox exposes chat data
Oct 24, 2024HighVulnerabilitySecurityCVE-2024-48142CVE-2024-48142 describes a prompt injection vulnerability in the chatbox of Butterfly Effect Limited's Monica ChatGPT AI Assistant v2.4.0. A crafted message allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant. The NVD had not yet provided an assessment, and the weakness is mapped to CWE-77.
NVD/CVE DatabaseCVE-2024-48140: Monica Your AI Copilot prompt injection in chatbox exposes chat data
Oct 24, 2024HighVulnerabilitySecurityCVE-2024-48140CVE-2024-48140 describes a prompt injection vulnerability in the chatbox of Butterfly Effect Limited's Monica Your AI Copilot powered by ChatGPT4, version 6.3.0. A crafted message lets an attacker access and exfiltrate all previous and subsequent chat data between the user and the AI assistant. The source lists CWE-77 (Command Injection) as the weakness, and NVD has not yet provided an assessment.
NVD/CVE DatabaseCVE-2024-48145: Netangular Technologies ChatNet AI prompt injection in chatbox exposes chat data
Oct 24, 2024CriticalVulnerabilitySecurityCVE-2024-48145CVE-2024-48145 describes a prompt injection vulnerability in the chatbox of Netangular Technologies ChatNet AI, Version v1.0. A crafted message allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant. The NVD assessment is not yet provided, and the weakness is classified as CWE-77.
NVD/CVE DatabaseCVE-2024-48144: Fusion Chat AI Assistant prompt injection exposes chat data
Oct 24, 2024CriticalVulnerabilitySecurityCVE-2024-48144CVE-2024-48144 describes a prompt injection vulnerability in the chatbox of Fusion Chat Chat AI Assistant Ask Me Anything v1.2.4.0. A crafted message lets attackers access and exfiltrate all previous and subsequent chat data between the user and the AI assistant. NVD has not yet provided an assessment, and the record is linked to CWE-77 (Command Injection).
NVD/CVE DatabaseCVE-2024-48141: Zhipu AI CodeGeeX prompt injection in chatbox exposes chat data
Oct 24, 2024HighVulnerabilitySecurityCVE-2024-48141CVE-2024-48141 is a prompt injection vulnerability in the chatbox of Zhipu AI CodeGeeX v2.17.0. A crafted message lets an attacker access and exfiltrate all previous and subsequent chat data between the user and the AI assistant. The weakness is catalogued as CWE-77, Improper Neutralization of Special Elements used in a Command ('Command Injection'), and NVD published the entry on 10/24/2024.
NVD/CVE DatabaseCVE-2024-48139: Blackbox AI prompt injection in chatbox exposes chat data
Oct 24, 2024HighVulnerabilitySecurityCVE-2024-48139CVE-2024-48139 is a prompt injection vulnerability in the chatbox of Blackbox AI v1.3.95. A crafted message lets an attacker access and exfiltrate all previous and subsequent chat data between the user and the AI assistant. The NVD assessment has not yet been provided, and the source maps the weakness to CWE-77 (Command Injection).
NVD/CVE DatabaseCVE-2024-5184: EmailGPT prompt injection that leaks system prompts and runs unwanted prompts
Jun 5, 2024MediumVulnerabilitySecuritySafetyCVE-2024-5184CVE-2024-5184 affects the EmailGPT service, which relies on an API service that lets a malicious user inject a direct prompt and take over the service logic. An attacker can force the AI service to leak its hard-coded system prompts and/or execute unwanted prompts, and any individual with access to the service can exploit it.
NVD/CVE DatabaseCVE-2023-32786: Langchain prompt injection enables SSRF via arbitrary URL retrieval
Oct 20, 2023HighVulnerabilitySecurityCVE-2023-32786CVE-2023-32786 affects Langchain through 0.0.155. Prompt injection in that version allows an attacker to force the service to retrieve data from an arbitrary URL, which the source describes as providing SSRF and potentially injecting content into downstream tasks. NIST has not yet provided an NVD assessment.
NVD/CVE DatabaseCVE-2023-29374: LangChain LLMMathChain prompt injection leads to arbitrary code execution
Apr 5, 2023CriticalVulnerabilitySecurityCVE-2023-29374EPSS: 39.7%CVE-2023-29374 affects LangChain through 0.0.131. Its LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via the Python exec method. NIST has not yet provided an NVD assessment, and the weakness is classified as CWE-74.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.