Prompt injection and jailbreaks
Inputs that override a model's instructions, directly or through content it reads, and attempts to bypass its safeguards.
- All items
- 194
- Last 90 days
- 43
- Change
- -17%vs 52 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 0 |
| Jul 2025 | 3 |
| Aug 2025 | 24 |
| Sep 2025 | 0 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 1 |
| Jan 2026 | 2 |
| Feb 2026 | 7 |
| Mar 2026 | 10 |
| Apr 2026 | 19 |
| May 2026 | 7 |
| Jun 2026 | 15 |
| Jul 2026 | 26 |
| Aug 2026 | 18 |
| Sep 2026 | 7 |
| Oct 2026 | 8 |
56 items
VTCode is vulnerable to Arbitrary Command Execution via an ANSI-C Quote Bypass of the find Approval Check
Oct 4, 2026MediumVulnerabilitySecurityCVE-2026-104247 affects vtcode versions below 0.171.5. An empty ANSI-C quote spliced into a find flag (for example -exe$''c) bypasses the is_destructive_find_option check, so the command is still treated as a safe find. Once the agent has learned that find family from three prior approvals, prompt_tool_permission auto-approves it and the shell runs it as the user running VTCode, with no new prompt. Exploitation requires a local session, those prior approvals, and something that can steer the agent, such as indirect prompt injection.
Fix: Upgrade to VTCode 0.171.5 or later. Until upgrading, do not rely on learned find approvals. The 0.171.5 release (PR #778, commit 5840697cd0dc8f94b9b53d88185329eecba8de11) refuses family learning for path-qualified find, mixed-case or quote-spliced flags, wrapper and environment prefixes, and compound commands.
JFrog Security Research (Vulnerabilities)CVE-2026-97228: Rapid7 Bulk Export MCP GraphQL query injection in export-status component
Sep 25, 2026LowVulnerabilitySecurityCVE-2026-97228Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 contain a GraphQL query injection in `get_export_status` in `src/export_manager.py`. The unvalidated `export_id` argument, passed via the `check_rapid7_export_status` and `download_rapid7_export` tools, is interpolated directly into the query string, so a crafted value can append attacker-chosen root-level selections such as schema introspection. The injected query runs under the operator's own API key and cannot cross a tenant or account boundary, so the realistic exposure is a compromised or careless upstream MCP client or indirect prompt injection.
Fix: Fixed in version 0.6.2, which passes `export_id` as a parameterized GraphQL variable (`$exportId: ID!`).
NVD/CVE DatabaseCVE-2026-85694: LaVague remote code execution via web page prompt injection
Sep 4, 2026HighVulnerabilitySecurityCVE-2026-85694LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object, which evaluates untrusted language model output derived from web page content. Attackers can use indirect prompt injection through web pages to inject malicious Python code that runs on the operator's host without review.
NVD/CVE DatabaseCVE-2026-37003: Agno RCE via prompt injection in PythonTools and ShellTools
Aug 27, 2026CriticalVulnerabilitySecurityCVE-2026-37003Agno up to and including 2.5.8 contains CVE-2026-37003, a remote code execution flaw reached through prompt injection. The PythonTools and ShellTools components pass unsanitized, LLM-generated arguments directly to exec(), runpy.run_path() and subprocess.run(). An unauthenticated attacker can embed malicious instructions in content the agent processes, such as web pages or documents, and gain arbitrary code and OS command execution on the host server.
NVD/CVE DatabaseCVE-2026-76072: Continue CLI denylist misses destructive shell commands in unattended mode
Aug 24, 2026HighVulnerabilitySecurityCVE-2026-76072The Continue CLI relies on an incomplete denylist as its only barrier to destructive shell commands in headless and auto mode, where the default policy grants the Bash tool allow permission. The critical-command check blocks only a small set of root and system paths, so recursive forced removal of directories such as /home or /root, and $HOME expansion, pass through. An indirect prompt injection in content the agent reads, such as web pages, repository files or issue text, can cause an unattended run to destroy the invoking user's data.
NVD/CVE DatabaseCVE-2026-75130: Context7 prompt injection through Custom AI Instructions served via MCP server
Aug 18, 2026CriticalVulnerabilitySecurityCVE-2026-75130Context7 through version 2.1.2 contains a prompt injection flaw in its Custom AI Instructions feature, served through the MCP server. An attacker can inject unsanitized content into those instructions, which connected AI coding agents then execute. The poisoned instructions can exfiltrate credentials from environment files to an attacker-controlled service and delete files on the victim's machine when the agent makes a routine library documentation request.
NVD/CVE DatabaseCVE-2026-21832: HCL AION indirect prompt injection leading to HTML injection in rendered output
Aug 13, 2026MediumVulnerabilitySecurityCVE-2026-21832HCL AION is affected by CVE-2026-21832, in which indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially causing unintended behavior or security impact under certain conditions. NVD had not yet provided an assessment at the time of publication on 08/13/2026.
NVD/CVE DatabaseCVE-2026-67531: FrontMCP sandbox escape to remote code execution through codecall:execute tool
Aug 5, 2026CriticalVulnerabilitySecurityCVE-2026-67531FrontMCP, a TypeScript framework for the Model Context Protocol, is affected by CVE-2026-67531 in versions prior to 1.5.7. The sandboxed codecall:execute tool exposes live host Zod schema instances through getTool(), and because Zod v4 defines _zod as non-configurable and non-writable, the Proxy invariants return the raw host object, letting a script reach the host Function constructor and run arbitrary code in the server process. A single tools/call is enough, and the attacker gains the server user's privileges, including OAuth client secrets, JWT_SECRET, session keys, database credentials, and cloud instance metadata. Because DEFAULT_AUTH_OPTIONS defaults to public mode, unconfigured servers expose this to unauthenticated callers, and on authenticated servers an indirect prompt injection in tool output or fetched content can trigger it without a human attacker.
Fix: Fixed in version 1.5.7.
NVD/CVE DatabaseGHSA-5xvg-pmgg-3mxr: Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
Aug 4, 2026CriticalVulnerabilitySecuritySafetyCVE-2026-70477Flowise version 3.1.1 (tested on Ubuntu 25.10) contains a flaw in the run method of the CSV_Agents class, used by the CSV Agent node. Untrusted input is placed into an LLM prompt without adequate sanitization, so a prompt injection can make the LLM return a malicious Python script. That script passes a regex blocklist validator in packages/components/src/pythonCodeValidator.ts, which can be bypassed, and then runs in pyodide, which is not sandboxed from the host OS, giving code execution as the server's service account. Authentication is not required to exploit it.
GitHub Advisory DatabaseCVE-2026-18733: Amazon Strands Agents Tools prompt injection in shell tool
Aug 3, 2026HighVulnerabilitySecurityCVE-2026-18733Amazon Strands Agents Tools before 0.8.0 contains a prompt injection vulnerability in its shell tool. A crafted prompt that sets the non_interactive parameter to true bypasses the human consent gate, allowing remote actors to execute arbitrary operating system commands on the agent's host. The CNA, AMZN, rates it CVSS 4.0 7.5 (HIGH), and NVD has not yet provided an assessment.
Fix: To remediate this issue, users should upgrade to version 0.8.0.
NVD/CVE DatabaseCVE-2026-18733 - Prompt injection bypasses shell tool consent gate in Strands Agents Tools
Aug 3, 2026HighVulnerabilitySecurityCVE-2026-18733 affects the shell tool in the strands-agents-tools package for Strands Agents, an open-source SDK for building AI agents, in versions below 0.8.0. The tool's input schema exposed a non_interactive parameter that the LLM could control, so a crafted prompt, including one delivered through untrusted content the agent reads, could set it to true. This bypasses the operator consent gate and allows arbitrary operating system commands to run on the agent's host without approval.
AWS Security BulletinsCVE-2026-18655 - Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection
Aug 3, 2026HighVulnerabilitySecurityCVE-2026-18655 is an improper restriction of intended endpoints in the RabbitMQ broker connection tools of the AWS Labs Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24, affecting versions <= 2.0.23. A remote unauthenticated actor may obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens by sending them to a crafted endpoint controlled through a broker hostname introduced in the MCP client context.
Fix: Fixed in 2.0.24. Upgrade awslabs.amazon-mq-mcp-server to version 2.0.24 or later.
AWS Security BulletinsCVE-2026-44192: Ansible Lightspeed MCP server path traversal via indirect prompt injection
Jul 22, 2026MediumVulnerabilitySecurityCVE-2026-44192CVE-2026-44192 is a path traversal flaw in the Ansible Lightspeed Model Context Protocol (MCP) server, classified as CWE-22. An attacker can use indirect prompt injection to manipulate an AI agent, causing the server to write files to unauthorized locations on the user's system. The source says this can expose sensitive host information and enable execution of malicious commands, potentially leading to full system compromise.
NVD/CVE DatabaseCVE-2026-61439: PraisonAI prompt injection defense fails to block HIGH-level threats
Jul 11, 2026HighVulnerabilitySecuritySafetyCVE-2026-61439PraisonAI versions before 4.6.78 default the prompt injection defense block threshold to CRITICAL severity, so HIGH-level threats pass through unblocked. Attackers can submit single-vector prompt injections, such as instruction overrides or financial manipulation, that are detected at HIGH severity and logged without being blocked, enabling system prompt extraction and unauthorized tool invocations. VulnCheck rates the issue CVSS 4.0 8.7 HIGH, and NVD has not yet provided an assessment.
NVD/CVE DatabaseCVE-2026-60086: PraisonAI prompt injection defense bypass via single or double-vector injections
Jul 10, 2026MediumVulnerabilitySecuritySafetyCVE-2026-60086CVE-2026-60086 affects PraisonAI before 4.6.78. Its prompt injection defense only blocks threats classified as CRITICAL, which requires three or more detector families to match at once. Single or double-vector prompt injections rated HIGH pass through unblocked and reach the model.
NVD/CVE DatabaseCVE-2026-14898: OpenAI Codex macOS app remote image exfiltration via prompt injection
Jul 6, 2026HighVulnerabilitySecuritySafetyCVE-2026-14898CVE-2026-14898 affects the OpenAI Codex desktop app for macOS, which rendered remote images from Markdown in model responses. An attacker who planted an indirect prompt injection in content Codex processed could make the model build a remote image URL carrying sensitive data, and the app fetched that URL automatically during rendering, sending the data to an attacker-controlled server without a user click. Exploitation could expose API keys, source code, and data returned by connected tools, though no integrity or availability impact was demonstrated and no exploitation in the wild is known.
NVD/CVE DatabaseCVE-2026-13341: Kong Konnect MCP server indirect prompt injection flaw
Jul 3, 2026HighVulnerabilitySecurityCVE-2026-13341A vulnerability in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0 could allow a remote attacker to perform an indirect prompt injection attack and execute unintended API requests. The weakness is classified as CWE-20, Improper Input Validation, and NVD has not yet provided an assessment.
NVD/CVE DatabaseAmazon Q Developer and Kiro – Prompt Injection Issues in Kiro and Q IDE plugins
Jun 5, 2026HighVulnerabilitySecuritySafetyAWS published bulletin AWS-2025-019 on prompt injection issues in Amazon Q Developer and Kiro, reported in Embrace The Red's "The Month of AI Bugs" blog posts. The Amazon Q Developer flaws, affecting find, grep and echo commands (versions below 1.22.0) and ping and dig commands (versions below 1.24.0), could run commands or exfiltrate metadata via DNS without Human-in-the-Loop confirmation. The Kiro flaw requires local system access and can lead to arbitrary code execution via IDE or MCP settings files, in Autopilot or Supervised mode, affecting version 0.1.42.
Fix: Amazon Q Developer Language Server v1.22.0 (released July 17, 2025) requires HITL confirmation for find, grep and echo commands. Language Server v1.24.0 (released July 29, 2025) requires HITL confirmation for ping and dig commands. Kiro version 0.1.42 (released August 1, 2025) requires HITL confirmation for these actions when configured in Supervised mode. AWS also recommends that customers evaluate and implement appropriate security controls and policies for their environments.
AWS Security BulletinsGHSA-72w5-pf8h-xfp4: DeepSeek TUI: task_create Insecure Defaults Enable RCE via Prompt Injection in Project Files
May 14, 2026CriticalVulnerabilitySecurityCVE-2026-45374The task_create tool in DeepSeek TUI spawns durable sub-agents that default to allow_shell=true (config.rs:1499) and auto_approve=true (task_manager.rs:297). A user who approves a benign-looking task_create call therefore unknowingly grants the sub-agent unapproved shell access, which can follow attacker-controlled instructions in a cloned repository's AGENTS.md file and run commands without a further approval prompt. The reporter demonstrates remote code execution through a proof of concept that triggers a callback to a collaborator server.
Fix: Default allow_shell to false for durable tasks (config.rs:1499: self.allow_shell.unwrap_or(false)); default auto_approve to false for durable tasks (task_manager.rs:297: auto_approve: None, instead of Some(true)); and, when the model requests task_create with allow_shell=true, surface that in the approval prompt so the user knows they are granting shell access.
GitHub Advisory DatabaseGHSA-rp7v-4384-hfrp: k8sGPT has Prompt Injection through its k8sGPT-Operator
Apr 24, 2026HighVulnerabilitySecuritySafetyk8sGPT's auto-remediation pipeline deserializes AI-generated YAML directly into a Deployment object in `object_to_execution.go`, without validating it against the original Deployment object. The issue was fixed after coordination with Alex Jones, and the proof of concept was shared only with the maintainers.
GitHub Advisory Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.