Vulnerabilities
CVEs in model-serving infrastructure, agent frameworks and LLM application components. Three signals per row: CVSS says how bad, EPSS how likely it is to be exploited in the next 30 days, and Exploited that CISA has confirmed exploitation in the wild. Exploited rows sort first.
Updated · Sources: NVD, CISA KEV, FIRST EPSS
| CVE | Exploited | Severity | EPSS | Published | Summary | Risk |
|---|---|---|---|---|---|---|
| CVE-2026-64849 | ExploitedCISA due 02 Sep 2026 | Critical 9.3 | 9.8%top 4.6% | 17 Aug 2026 | MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Starting in 3.3.0 and prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without… |
|
| CVE-2026-9198 | ExploitedCISA due 07 Aug 2026 | Critical 9.8 | 28.7%top 1.9% | 17 Jul 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments |
|
| CVE-2026-59822 | ExploitedCISA due 16 Sep 2026 | High 8.2 | 0.8%top 43.8% | 08 Jul 2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a… |
|
| CVE-2026-55255 | ExploitedCISA due 10 Jul 2026 | High 8.4 | 0.9%top 42.1% | 23 Jun 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability is fixed in 1.9.1. |
|
| CVE-2026-33017 | ExploitedCISA due 08 Apr 2026 | Critical 9.8 | 24.8%top 2.2% | 20 Mar 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the optional data parameter is supplied, the endpoint uses attacker-controlled flow data (containing arbitrary Python code in node definitions) instead of the stored… |
LLM05:2025 |
| CVE-2026-0770 | ExploitedCISA due 24 Jul 2026 | Critical 9.8 | 63.0%top 0.8% | 23 Jan 2026 | Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint.… |
LLM05:2025 |
| CVE-2025-34291 | ExploitedCISA due 04 Jun 2026 | High 8.8 | 92.8%top 0.2% | 05 Dec 2025 | Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the… |
LLM05:2025 |
| CVE-2025-3248 | ExploitedRansomwareCISA due 26 May 2025 | Critical 9.8 | 100.0%top 0.1% | 07 Apr 2025 | Langflow versions prior to 1.3.0 are susceptible to code injection in
the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary
code. |
|
| CVE-2026-91108 | — | Medium 4.3 | 0.2%top 89.5% | 03 Oct 2026 | The Alt Text AI – Automatically generate image alt text for SEO and accessibility plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.10.41. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the… |
|
| CVE-2026-94378 | — | Medium 6.4 | 0.2%top 91.0% | 03 Oct 2026 | The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in… |
LLM05:2025 |
| CVE-2026-94539 | — | Medium 6.5 | 0.3%top 81.9% | 03 Oct 2026 | The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to time-based SQL Injection via the 'sort_by' parameter in all versions up to, and including, 3.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with… |
LLM05:2025 |
| CVE-2026-94485 | — | Unscored | 0.2%top 93.8% | 02 Oct 2026 | Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the `next dev` development server exposes a Model Context Protocol endpoint without reliably restricting cross-site requests. A malicious website visited by a developer can reach the endpoint and read the project's disk location, source code snippets from error reports, route inventory, and… |
|
| CVE-2026-94486 | — | Unscored | 0.2%top 94.0% | 02 Oct 2026 | Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the next dev development server exposes a Model Context Protocol endpoint without reliably restricting cross-site requests. A malicious website visited by a developer can reach the endpoint and read the project's disk location, source code snippets from error reports, route inventory, and development… |
|
| CVE-2026-96561 | — | High 7.2 | 0.3%top 76.3% | 01 Oct 2026 | The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.0 This is due to a chain of missing input neutralization and output escaping across the /mwai-ui/v1/chats/submit REST endpoint, the PHP error-log parser (MeowKit_MWAI_Helpers::php_error_logs), the Advisor task… |
LLM01:2025LLM05:2025 |
| CVE-2025-71427 | — | Medium 6.8 | 0.3%top 80.5% | 01 Oct 2026 | Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working directory by supplying absolute paths or ../ sequences. Attackers can steer an AI agent via prompt injection to abuse save_presentation, open_presentation, or manage_image output_path to overwrite any server-writable file or load external files. |
LLM01:2025LLM05:2025 |
| CVE-2026-51882 | — | Unscored | 0.1%top 96.8% | 01 Oct 2026 | The OpenAI-compatible file upload endpoint `/v1/files` in Langchain-Chatchat 0.3.0 is vulnerable to path traversal. An attacker can write files to arbitrary locations outside the `openai_files` directory by crafting malicious filenames. |
LLM05:2025 |
| CVE-2026-51883 | — | Unscored | 0.1%top 96.8% | 01 Oct 2026 | The knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is vulnerable to path traversal. An attacker can inject path traversal sequences (such as `..\`) into the `knowledge_base_name` parameter to write knowledge base content to arbitrary locations outside the configured knowledge base root directory. |
LLM05:2025 |
| CVE-2026-51884 | — | Unscored | 0.2%top 96.1% | 01 Oct 2026 | The /knowledge_base/upload_temp_docs temporary document upload endpoint in Langchain Chatchat 0.3.1 is vulnerable to path traversal. By crafting malicious filenames, an attacker can write files to arbitrary locations on the server, bypassing the intended restrictions on the temporary directory. |
LLM05:2025 |
| CVE-2026-51886 | — | Unscored | 0.2%top 94.2% | 01 Oct 2026 | langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The component is: src/backend/base/langflow/api/v1/validate.py:validate-post_validate_code-a-real-authenticated-http-post-to-api-v1. The attack vector is: Attack surface: HTTP or browser-backed service path. A public-facing route accepts raw Python source and forwards it into a server-side… |
LLM05:2025 |
| CVE-2026-51888 | — | Unscored | 0.2%top 87.0% | 01 Oct 2026 | langflow-ai langflow v1.8.4 is affected by: Directory Traversal. The impact is: Arbitrary file write outside the intended workspace or storage boundary.. The component is: src/backend/base/langflow/api/v1/knowledge_bases.py:knowledge_bases-create_knowledge_base-a-live-http-post-to-create-knowledge-base. The attack vector is: Attack surface: HTTP or browser-backed service path. A public-facing… |
LLM05:2025 |
| CVE-2026-51871 | — | Critical 9.8 | 0.4%top 67.7% | 30 Sep 2026 | Devika v1.0 is vulnerable to Code Injection in the Runner.execute function in src/agents/runner/runner.py which allows an attacker to achieve arbitrary code execution by exploiting the direct execution of LLM-generated content. |
LLM05:2025 |
| CVE-2026-103241 | — | Medium 5.3 | 0.7%top 50.3% | 30 Sep 2026 | A flaw has been found in vllm-project vLLM up to 0.26.0. This vulnerability affects unknown code of the file rust/src/parser/src/unified/gemma4.rs of the component Gemma4UnifiedParser. Executing a manipulation can lead to denial of service. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 0.29.1rc0 is able to resolve this issue. This patch… |
LLM10:2025 |
| CVE-2026-77177 | — | Critical 9.8 | 0.6%top 53.6% | 29 Sep 2026 | Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injection (with Jinja2 template syntax) can be used to achieve server-side expression evaluation without sanitization. |
LLM01:2025LLM05:2025 |
| CVE-2026-102697 | — | High 7.8 | 0.1%top 96.7% | 29 Sep 2026 | Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experimental agent mode Bash tool approval mechanism that fails to properly parse shell syntax. Attackers who can influence model output through prompt injection can execute additional shell commands by appending control operators like semicolons or logical operators to approved commands, bypassing the… |
LLM01:2025 |
| CVE-2026-55157 | — | High 8.4 | 0.7%top 48.3% | 28 Sep 2026 | Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge graph across 16 CLI clients. Prior to version 5.1.0, token-optimizer-mcp is vulnerable to OS command injection in the smart_user tool. Any MCP client that can call the smart_user tool can execute arbitrary shell commands through the username argument of the get-user-info operation.… |
LLM05:2025 |
| CVE-2026-101861 | — | Medium 4.1 | 0.2%top 91.5% | 28 Sep 2026 | Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows authenticated attackers to achieve code execution by placing a Python object with a malicious __repr__ method into component input options lists. The eval() sink is triggered when a component is converted into a LangChain tool via ComponentToolkit.get_tools(), including during… |
LLM05:2025 |
| CVE-2026-101065 | — | Critical 9.8 | 0.4%top 64.2% | 27 Sep 2026 | Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When authentication is disabled, every request is mapped to a synthetic "nobody" user that holds the Owner and Admin roles, so any unauthenticated party who… |
|
| CVE-2026-100863 | — | Medium 5.0 | 0.2%top 85.6% | 27 Sep 2026 | Heym versions 0.0.90 and earlier contain two server-side request forgery (SSRF) egress gaps, both remediated in app/services/ssrf_guard.py in 0.0.91. First, the LLM image-edit input loader (_load_image_bytes) fetched caller-controlled HTTP/HTTPS URLs with a bare httpx.get, applying only a scheme check and bypassing the egress-pinning HTTP client; because the workflow DSL supports "imageInput":… |
LLM05:2025 |
| CVE-2026-100653 | — | Medium 6.5 | 0.3%top 81.0% | 26 Sep 2026 | vLLM is an inference and serving engine for large language models. In versions from 0.22.1 through 0.28.0, the operator-supplied model revision pin (--revision / --code-revision) is not propagated to several Hugging Face artifact loads for the FunAudioChat and Tarsier2 architectures: the WhisperFeatureExtractor and speech_tokenizer PreTrainedTokenizerFast loads in… |
LLM05:2025 |
| CVE-2026-100647 | — | Medium 5.3 | 0.3%top 78.5% | 26 Sep 2026 | vLLM versions before 0.29.0 contain a denial-of-service vulnerability in the cache_salt parameter accepted on OpenAI-compatible and Anthropic API endpoints, which lacks maximum length validation and is processed on the single EngineCore scheduler thread. Unauthenticated attackers can send HTTP requests with multi-hundred-megabyte salt values that trigger expensive pickle serialization and SHA-256… |
|
| CVE-2026-100648 | — | Medium 5.3 | 0.3%top 75.8% | 26 Sep 2026 | vllm before 0.29.0 fails to enforce VLLM_MAX_AUDIO_CLIP_FILESIZE_MB limit in multimodal chat audio decoding, allowing unauthenticated clients to bypass file size restrictions. Attackers can submit oversized audio files through chat endpoints to consume excessive memory and CPU resources during decoding. |
|
| CVE-2026-100650 | — | Medium 6.5 | 0.6%top 52.4% | 26 Sep 2026 | vLLM through 0.29.0 fetches and fully materializes remote or inline media before enforcing its documented media controls (the VLLM_MAX_AUDIO_CLIP_FILESIZE_MB compressed-audio size cap, default 25 MB, and the per-modality --limit-mm-per-prompt item limits). Across four ingress paths — the shared media-acquisition layer (HTTPConnection.get_bytes()/async_get_bytes()), the chat completions… |
LLM05:2025LLM10:2025 |
| CVE-2026-100651 | — | Medium 6.5 | 0.3%top 78.7% | 26 Sep 2026 | vLLM before 0.29.0 fails to enforce decoder prompt-length validation on the disaggregated serving endpoint /inference/v1/generate. When the request contains a 'features' (multimodal) payload, vllm/entrypoints/serve/disagg/serving.py builds a multimodal EngineInput directly from the caller-supplied token_ids, and GenerateRequest.token_ids (vllm/entrypoints/serve/disagg/protocol.py) is not checked… |
LLM10:2025 |
| CVE-2026-100652 | — | Medium 5.9 | 0.3%top 76.3% | 26 Sep 2026 | vLLM versions 0.22.0 through 0.23.0 fail to validate stop_token_ids against vocabulary bounds in Rust HTTP and gRPC frontends, allowing out-of-vocabulary token IDs to reach MinTokensLogitsProcessor. Attackers can submit requests with min_tokens greater than zero and out-of-vocabulary stop_token_ids to trigger CUDA tensor indexing failures that leave EngineCore in a fatal state requiring service… |
|
| CVE-2026-100654 | — | Medium 6.5 | 0.3%top 78.7% | 26 Sep 2026 | vLLM before 0.29.0 accepts user-controlled stop_token_ids on the OpenAI-compatible POST /v1/completions and POST /v1/chat/completions endpoints but validates only that the values are integers, not that each token id is within the model vocabulary/logits range. When min_tokens > 0, the stop token ids are used as logits indices to suppress stop tokens, so an out-of-range id reaches a CUDA indexing… |
LLM10:2025 |
| CVE-2026-100649 | — | Low 3.7 | 0.3%top 78.3% | 26 Sep 2026 | vLLM before 0.29.0 contains a resource-limit bypass vulnerability in PyNvVideoCodec decoder allocation where sampler subclass shadowing allows independent counter increments. Unauthenticated attackers can select different sampler subclasses in video requests to exceed configured decoder limits and exhaust unaccounted GPU memory. |
|
| CVE-2026-97869 | — | Medium 4.1 | 0.4%top 70.8% | 25 Sep 2026 | A flaw has been found in langchain4j up to 1.5.3-beta10/1.11.10-beta18/1.18.1-beta27. This vulnerability affects the function AgenticScopeSerializer.fromJson of the file AgenticScopeJsonSerializationIT.java of the component LangChain4j-agentic. This manipulation causes deserialization. Remote exploitation of the attack is possible. The attack's complexity is rated as high. It is stated that the… |
|
| CVE-2026-97228 | — | Low 2.7 | 0.2%top 85.4% | 25 Sep 2026 | Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injection issue in the export-status component (`get_export_status` in `src/export_manager.py`), whereby the `export_id` value — an unvalidated MCP tool argument reaching the function via the `check_rapid7_export_status` and `download_rapid7_export` tools — is interpolated directly into the GraphQL query string. A… |
LLM01:2025 |
| CVE-2026-84462 | — | Unscored | 0.3%top 81.8% | 25 Sep 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filter that protects Zammad's AI Agent configuration can be bypassed by entering specially crafted text into one of an AI Agent's fields. An administrator with permission to create or edit AI Agents could exploit this to run arbitrary commands on the server that hosts Zammad, potentially reading,… |
LLM05:2025 |
| CVE-2026-63216 | — | Unscored | 0.2%top 85.9% | 25 Sep 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, unsanitized option labels are rendered in the configuration dialogs of AI Agents within Zammad's admin UI. When rendering the list of selected options, the option label is output as raw HTML without escaping. An attacker who can control an option label, for example by setting a malicious string as a user or… |
|
| CVE-2026-61732 | — | Critical 10.0 | 1.2%top 32.3% | 24 Sep 2026 | Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output of agent reconnaissance against target services — into LLM messages without neutralizing ChatML special-token literals. Under the BYOK (Bring Your Own Key) deployment model, users configure their own LLM credentials to any OpenAI-compatible endpoint. Most open-source and… |
LLM05:2025 |
| CVE-2026-77294 | — | High 8.1 | 0.3%top 78.5% | 24 Sep 2026 | TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authenticated user to store an attacker-controlled llm_base_url through the settings API when the LLM_PARSING feature is enabled. Write permission to the target trip instance is required to trigger the vulnerable AI-assisted import path. The value is consumed by the clients in… |
LLM05:2025 |
| CVE-2026-61742 | — | Unscored | 0.2%top 91.0% | 24 Sep 2026 | DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Versions prior to 0.22.5 expose an unauthenticated HTTP MCP endpoint when started with the documented HTTP transport mode, for example `--transport http --port 8080`. The HTTP server attempts to protect browser-origin access by checking whether the `Origin` hostname equals the `Host` hostname, then reflecting… |
LLM01:2025 |
| CVE-2026-18875 | — | High 7.3 | 0.2%top 88.9% | 23 Sep 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server (api.vectordb.runbooks.js:51). An unauthenticated attacker can insert malicious runbook content into the agent's vector database to steer AI-driven MCP tool calls, potentially triggering unauthorized payment actions or exfiltrating… |
|
| CVE-2026-96775 | — | High 8.8 | 0.4%top 69.8% | 23 Sep 2026 | MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control only when the model_path ends in .pkl, which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact. |
LLM05:2025 |
| CVE-2026-96804 | — | High 8.8 | 0.4%top 65.6% | 23 Sep 2026 | MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control entirely in _load_model(), which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact. |
LLM05:2025 |
| CVE-2026-93529 | — | Medium 6.5 | 0.2%top 89.5% | 23 Sep 2026 | Contributor Broken Access Control in WSP MCP – AI Agents Connector <= 2.7.0 versions. |
|
| CVE-2026-77244 | — | Critical 10.0 | 0.3%top 80.8% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the HTTP transport accepts requests without a verified user identity and downstream fetcher construction falls back to the operator's globally configured Jira or Confluence credentials. A network client that can reach the MCP endpoint can invoke Atlassian tools as the operator,… |
|
| CVE-2026-77254 | — | Critical 9.1 | 0.6%top 52.1% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, requests to the HTTP MCP endpoint without a per-user identity are allowed to reach tool handlers, which then use globally configured Jira or Confluence credentials. A network caller can perform operations with the operator account's permissions unless the deployment has an… |
|
| CVE-2026-56681 | — | High 7.3 | 1.0%top 39.5% | 22 Sep 2026 | 9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper trust the client-supplied X-9r-Real-Ip header in src/dashboardGuard.js when isLocalRequest decides whether canAccessPublicLlmApi may skip API-key validation for /api/v1/* routes. A remote unauthenticated attacker can set X-9r-Real-Ip to… |
|
| CVE-2026-77242 | — | High 7.5 | 0.3%top 79.3% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, validate_url_for_ssrf checks a hostname's resolved addresses, but Requests and urllib3 resolve the hostname again when connecting. A caller can use a short-lived DNS answer that is public during validation and private during connection, preserving unauthenticated access to… |
|
| CVE-2026-77243 | — | High 8.8 | 0.3%top 76.9% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, ENABLED_TOOLS and TOOLSETS are applied when tools are listed but are not rechecked when a tools/call request is dispatched. A client that knows a hidden tool name can directly invoke excluded read, write, or delete tools despite the operator's configured least-privilege… |
|
| CVE-2026-77258 | — | High 7.7 | 0.3%top 74.8% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment in src/mcp_atlassian/confluence/attachments.py accepts a caller-controlled file_path and opens the selected server-local file without restricting it to the workspace. A permitted Confluence MCP caller can upload the file as an attachment and disclose data… |
|
| CVE-2026-77260 | — | High 7.5 | 0.3%top 73.7% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Confluence and Jira upload_attachment implementations accept an unconstrained file_path and open the referenced server-local file. A permitted MCP caller can upload sensitive host files to an Atlassian destination and then retrieve their contents. The advisory traces the… |
|
| CVE-2026-77261 | — | High 7.1 | 0.3%top 77.1% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, _make_ssrf_safe_hook is omitted from JiraFetcher and ConfluenceFetcher sessions created through the basic-auth and oauth_pat branches. If an attacker-controlled or compromised configured Atlassian instance returns a redirect to an internal address, those sessions can follow the… |
|
| CVE-2026-77271 | — | High 8.8 | 0.5%top 57.2% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, validate_safe_path defaults its base directory to os.getcwd(), and affected Confluence attachment call sites omit base_dir, allowing attacker-selected writes within the working directory. This Python module overwrite can provide code execution when the application later imports… |
LLM05:2025 |
| CVE-2026-77274 | — | High 8.2 | 0.3%top 76.8% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, validate_url_for_ssrf has a backslash authority confusion because it interprets the authority differently from the Requests connection layer in the header-based Jira and Confluence URL authentication flow. A crafted URL can validate as an external hostname while the HTTP client… |
|
| CVE-2026-77246 | — | High 7.4 | 0.4%top 65.2% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, an HTTP transport deployment with READ_ONLY_MODE=false accepts a request without an Authorization identity and permits attacker-controlled Atlassian service headers, including X-Atlassian-Confluence-Url, to select a public attacker hostname or one allowed by… |
|
| CVE-2026-77248 | — | High 8.6 | 0.4%top 66.7% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the streamable HTTP transport accepts requests without a user identity and falls back to operator credentials, while upload_attachment accepts an unrestricted file_path. An unauthenticated network caller can read files available to the MCP process, upload them to an… |
|
| CVE-2026-77253 | — | High 7.1 | 0.4%top 71.0% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira and Confluence attachment upload tools accept arbitrary local filesystem paths and send the selected bytes to Atlassian. In HTTP or multi-user deployments, a caller can cross the client-to-server filesystem boundary and disclose configuration, credentials, mounted secrets, or… |
|
| CVE-2026-77255 | — | High 8.6 | 0.4%top 67.2% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Jira update_issue attachments argument is converted into local paths and routed to the attachment upload implementation without workspace validation. A caller can make the MCP server read arbitrary local files and attach them to a Jira issue, using the server as a confused… |
|
| CVE-2026-77259 | — | High 7.7 | 0.4%top 67.2% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment opens a caller-selected server-local file without checking that the resolved path remains in the workspace. A caller can upload environment files, credentials, or other readable host data to a Confluence page and retrieve it through Atlassian. The… |
|
| CVE-2026-77262 | — | High 8.6 | 0.5%top 60.1% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment accepts an attacker-controlled file_path and does not apply the path restriction added for the earlier download vulnerability. A caller can traverse outside the workspace and upload arbitrary server-readable files to Confluence. The advisory traces the… |
|
| CVE-2026-84301 | — | Medium 6.3 | 0.3%top 80.9% | 22 Sep 2026 | FastGPT is an open-source LLM platform for building AI applications on a knowledge base. Prior to 4.15.2, the safe Axios request interceptor in packages/service/common/api/axios.ts validates a hostname with isInternalAddress() before a later HTTP connection performs an independent DNS lookup, creating a DNS rebinding window, allowing an attacker-controlled hostname to resolve publicly during the… |
|
| CVE-2026-77250 | — | Medium 6.1 | 0.1%top 98.9% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, OAuthConfig writes a plaintext fallback file containing access and refresh tokens under the user's .mcp-atlassian directory using process-default permissions. On systems with a permissive umask, same-group or other local users and processes can read the persisted tokens and reuse… |
|
| CVE-2026-77251 | — | Medium 6.5 | 0.2%top 86.0% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira search accepts a forbidden project clause because it checks only for the presence of project syntax, Confluence search uses an incomplete case-sensitive space check, and Jira board APIs omit project-filter enforcement. These paths expose issues, boards, or pages outside… |
|
| CVE-2026-77252 | — | Medium 6.5 | 0.3%top 79.5% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, caller-supplied projects_filter and spaces_filter arguments can replace administrator-configured allowlists, and caller-provided project or space clauses can suppress the configured restriction. A caller can search projects or spaces outside the intended boundary when the… |
|
| CVE-2026-77265 | — | Medium 5.9 | 0.3%top 82.5% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, header-supplied Jira or Confluence URLs are resolved and validated before the HTTP client resolves the hostname again for the connection. An unauthenticated caller can use a DNS-rebinding hostname that returns a public address during validation and an internal address during… |
|
| CVE-2026-77267 | — | Medium 6.5 | 0.3%top 80.1% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url headers are processed by _process_authentication_headers and used to construct Atlassian fetchers without calling validate_url_for_ssrf. A caller who can set these headers can supply an internal or metadata-service URL and… |
|
| CVE-2026-77270 | — | Medium 6.5 | 0.4%top 70.9% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Jira and Confluence attachment upload tools treat caller-controlled file_path values as trusted server-local paths. The server opens the selected file and uploads it to an Atlassian issue or page, allowing an MCP caller with upload access to disclose any file readable by the… |
|
| CVE-2026-77247 | — | Medium 6.5 | 0.4%top 69.5% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira and Confluence upload tools interpret caller-controlled path arguments on the MCP server and open those files before sending them as attachments. In remote or multi-user deployments, a permitted client can disclose host files without shell or direct filesystem access. The… |
|
| CVE-2026-77249 | — | Medium 5.3 | 0.3%top 77.0% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, JiraUserMixin._lookup_user_by_permissions uses the module-level requests.get function instead of the fetcher's protected session. A caller-controlled public Jira URL can redirect that unhooked request to an internal address, bypassing the redirect checks added for CVE-2026-27826.… |
|
| CVE-2026-77256 | — | Medium 6.5 | 0.3%top 74.0% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the plaintext OAuth fallback file containing refresh and access tokens is written with permissions inherited from the process umask. Under common or permissive configurations, other local users can read the backup and retain Atlassian access through the refresh token. The advisory… |
|
| CVE-2026-77257 | — | Medium 6.5 | 0.4%top 69.7% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, HTTP-exposed Jira and Confluence upload tools pass a caller-provided file_path to local file operations without restricting it to the workspace. A remote MCP caller with tool access can cause the server to read sensitive local files and upload them as Atlassian attachments. The… |
|
| CVE-2026-77266 | — | Medium 6.5 | 0.4%top 63.8% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment accepts absolute paths and traversal sequences without constraining the resolved path to the server workspace. An MCP caller with attachment access can read a chosen server-local file and exfiltrate it through Jira or Confluence. The advisory traces the… |
LLM05:2025 |
| CVE-2026-77268 | — | Medium 5.5 | 0.1%top 98.3% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth fallback token directory and JSON file are created without explicit owner-only modes. Local users or processes with access through the resulting group or world permission bits can read access and refresh tokens and reuse the associated Atlassian session. The advisory… |
|
| CVE-2026-77269 | — | Medium 6.5 | 0.4%top 69.2% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the remediation for CVE-2026-27825 protects download destinations but does not constrain source paths used by attachment uploads. A caller can provide an absolute or traversal file_path and cause the server to upload the selected local file. The advisory traces the vulnerable… |
|
| CVE-2026-77272 | — | Medium 5.4 | 0.2%top 85.4% | 22 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth error query parameter is passed to CallbackHandler._send_response in oauth_setup.py and interpolated into an HTML page without escaping. A crafted authorization callback can inject markup or script that executes in the browser of a user completing the OAuth flow. This… |
|
| CVE-2026-94622 | — | High 7.5 | 0.6%top 51.8% | 21 Sep 2026 | vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode disaggregated deployments. Attackers can send requests with incomplete kv_transfer_params dictionary entries to trigger an uncaught KeyError in EngineCore scheduling, causing the decode engine to terminate and making all routed requests fail until manual restart. |
LLM10:2025 |
| CVE-2026-94623 | — | High 7.5 | 0.6%top 51.8% | 21 Sep 2026 | vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion requests in prefill/decode disaggregated deployments. Attackers can trigger an assertion failure in NixlBaseConnectorWorker._apply_prefix_caching by submitting completion requests with multiple prompts of… |
LLM10:2025 |
| CVE-2026-94624 | — | High 7.5 | 0.6%top 51.8% | 21 Sep 2026 | vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers can supply arbitrary remote host and port values in kv_transfer_params to create unreachable peer sessions that retain ZeroMQ sockets until the context quota is exhausted, causing an uncaught ZMQError… |
LLM10:2025 |
| CVE-2026-94626 | — | High 7.5 | 0.6%top 51.8% | 21 Sep 2026 | vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory. Attackers can supply arbitrary tp_size values in prefill/decode disaggregated deployments to exhaust memory and trigger kernel OOM-kill of the decode worker process. |
|
| CVE-2026-94627 | — | High 7.5 | 0.6%top 51.8% | 21 Sep 2026 | vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID in prefill/decode disaggregated deployments. Attackers can trigger GPU memory exhaustion by submitting completion requests with multiple prompts, causing orphaned KV cache blocks to accumulate until process restart and eventually preventing… |
LLM10:2025 |
| CVE-2026-61687 | — | High 7.1 | 0.2%top 94.1% | 21 Sep 2026 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ValidateOAuthState clears the oauth_state_ session value to an empty string after a successful OAuth callback and later accepts an empty state parameter as equal, allowing an unauthenticated attacker to bind a victim's Hatchet session to an attacker-controlled OAuth identity.… |
|
| CVE-2026-94625 | — | Medium 5.3 | 0.5%top 57.8% | 21 Sep 2026 | vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders that are never reclaimed. Attackers can send rejected requests to exhaust sender task pools, causing valid requests to be delayed by up to 480 seconds while health checks continue returning success. |
LLM10:2025 |
| CVE-2026-61681 | — | Medium 4.1 | 0.3%top 78.2% | 21 Sep 2026 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, the SNS UnsubscribeConfirmation handler in internal/integrations/ingestors/sns/sns.go calls http.Get() on payload.UnsubscribeURL after VerifyPayload() even though BuildSignature() excludes UnsubscribeURL, allowing an authenticated Hatchet tenant to replace that field in an… |
|
| CVE-2026-63342 | — | Medium 6.3 | 0.3%top 77.9% | 21 Sep 2026 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, api-contracts/openapi/paths/v1/workflow-runs/workflow_run.yaml defines the GET /api/v1/stable/durable-tasks/{durable-task} endpoint implemented by listDurableEventLog without requiring the target tenant as a parent resource, allowing an authenticated user who obtains another… |
|
| CVE-2026-88978 | — | Medium 4.3 | 0.3%top 81.3% | 21 Sep 2026 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.106.1, the WorkerStatus gRPC polling path in pkg/repository/durable_events.go passes caller-supplied durable task, node, and branch identifiers to ListSatisfiedEntries without a tenant filter, allowing an authenticated tenant worker that knows another tenant's durable-task UUID to… |
|
| CVE-2026-84298 | — | Low 3.1 | 0.2%top 85.9% | 21 Sep 2026 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.95.3, the V1 DurableTask stream handler stores worker-supplied task_external_id values in the durableInvocations routing map before tenant ownership is verified, and callback delivery resolves that map by task UUID without tenant identity. An authenticated tenant worker that knows… |
|
| CVE-2026-61647 | — | Unscored | 0.3%top 76.8% | 21 Sep 2026 | NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content to local vault directories. Versions 1.6.0 through 2.0.2 contain a path traversal vulnerability in the `POST /batch-to-vault` endpoint, also exposed through the `batch_to_vault` MCP tool beginning in version 1.7.0, because attacker-controlled `vault_dir` and `slug_prefix` values… |
LLM05:2025 |
| CVE-2026-94111 | — | Medium 6.6 | 0.1%top 97.5% | 20 Sep 2026 | Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension origin with 32 characters in range a-p. Attackers can register a malicious extension as a browser client to intercept and manipulate page content, DOM, and screenshots returned to the AI agent. |
|
| CVE-2026-93989 | — | Low 3.1 | 0.2%top 90.8% | 19 Sep 2026 | vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer(). Attackers can supply out-of-bounds token indices that corrupt logits memory of concurrent requests, causing different in-flight HTTP requests to return incorrect tokens. |
|
| CVE-2026-93982 | — | Low 3.3 | 0.2%top 94.6% | 19 Sep 2026 | OpenPanel through 2.3.0 writes Model Context Protocol authentication tokens from URL query parameters to plaintext application logs without redaction. Attackers with access to application stdout or centralized logging systems can capture base64-encoded credentials to replay MCP requests and access project analytics. |
|
| CVE-2025-66455 | — | Critical 9.8 | 0.7%top 48.8% | 18 Sep 2026 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control plane used `recv_pyobj()` to deserialize messages received through a ZeroMQ PULL socket. PyZMQ implements `recv_pyobj()` using Python pickle deserialization, which can execute arbitrary code while… |
LLM05:2025 |
| CVE-2026-33625 | — | High 8.8 | 0.4%top 63.8% | 18 Sep 2026 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.12.2 contain a code injection vulnerability in `lmdeploy/pytorch/config.py` line 620 that allows an attacker to execute arbitrary Python code by publishing a malicious HuggingFace model with a crafted `quantization_config.quant_dtype` value. When a user loads the model with lmdeploy, the… |
|
| CVE-2026-93592 | — | High 7.5 | 0.5%top 56.3% | 18 Sep 2026 | vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single request with a negative token ID triggers a CUDA device-side assertion that poisons the GPU context, causing all subsequent requests to fail until the process restarts. |
|
| CVE-2026-58197 | — | High 8.8 | 0.4%top 71.2% | 18 Sep 2026 | ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0, locally run MCP server containers use the default network permission profile without network isolation, permitting access to host.docker.internal while ToolHive API and MCP proxy endpoints are reachable without authentication. A… |
|
| CVE-2026-93840 | — | Low 3.7 | 0.2%top 85.6% | 18 Sep 2026 | vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in SamplingParams._validate_allowed_token_ids(). Attackers can supply token IDs above the output vocabulary that pass validation, causing LogitBiasState to corrupt GPU logits state and allow concurrent requests to sample tokens outside their allowlists. |
|
| CVE-2026-93841 | — | Low 3.7 | 0.2%top 86.6% | 18 Sep 2026 | vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs index the penalty prompt-presence bitset without bounds checking against vocabulary size. Attackers can submit multimodal audio requests with tokens equal to vocabulary size, causing out-of-bounds writes that corrupt concurrent requests' sampler state and alter repetition penalty… |
|
| CVE-2026-93436 | — | High 7.5 | 0.8%top 46.5% | 17 Sep 2026 | vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggregated deployments. Remote attackers can submit requests with max_tokens=0 to exhaust decode-worker memory without bound until the worker restarts. |
|
| CVE-2026-50125 | — | High 7.5 | 0.5%top 60.1% | 17 Sep 2026 | MKP is a Model Context Protocol server for Kubernetes. Prior to 0.4.1, cmd/server/main.go exposes the default HTTP endpoint and pkg/mcp/server.go registers the unauthenticated get_resource tool, which accepts attacker-controlled limitBytes and tailLines values for the pods logs subresource. buildPodLogOpts() in pkg/k8s/subresource.go parses those values as unbounded int64 parameters, and… |
|
| CVE-2026-54519 | — | High 8.8 | 0.5%top 58.2% | 17 Sep 2026 | AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, backend/src/controllers/memory.controller.js authenticates requests but listMemories, deleteMemory, and clearAgentMemory use a caller-supplied agentId or memory _id without verifying through the related Agent that the record belongs to req.user. An authenticated… |
|
| CVE-2026-54520 | — | High 8.1 | 0.5%top 60.0% | 17 Sep 2026 | AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.path value through path.resolve with process.cwd() and then uses the resulting path for read or write operations without checking that it remains in an approved… |
|
| CVE-2026-53554 | — | Unscored | 0.4%top 66.5% | 17 Sep 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/parseExcel endpoint in backend/apps/datasource/api/datasource.py uses attacker-controlled multipart filename data when selecting where uploaded content is stored, writes the content before spreadsheet parsing and validation finish, and can transform a double-extension… |
|
| CVE-2026-53555 | — | Unscored | 0.5%top 60.5% | 17 Sep 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated uploader can submit an image/svg+xml assistant UI logo through PATCH /api/v1/system/assistant/ui, and SQLBot stores the SVG without sanitizing or validating embedded active content. SQLBot later serves the file inline from the same application origin through GET… |
LLM05:2025 |
| CVE-2026-53556 | — | Unscored | 0.5%top 60.6% | 17 Sep 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/previewData endpoint in backend/apps/datasource/crud/datasource.py incorporates the client-controlled table_name value into generated SQL without safe identifier handling. An authenticated user can configure a datasource for SQLBot's internal PostgreSQL service and… |
|
| CVE-2026-53557 | — | Unscored | 0.3%top 75.3% | 17 Sep 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated user can supply a crafted sheet["tableName"] value in the Excel datasource configuration submitted through POST /api/v1/datasource/, and SQLBot stores that value without safe identifier handling. When the same datasource is later removed through DELETE /api/v1/datasource/{id}, the… |
LLM05:2025 |
| CVE-2025-59953 | — | Critical 9.8 | 0.8%top 44.9% | 16 Sep 2026 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC communications. In its core functionality call_and_response(), I found it will directly use the pickles.loads() to deserialize the received messages without any… |
LLM05:2025 |
| CVE-2026-63127 | — | High 8.2 | 0.2%top 90.8% | 16 Sep 2026 | RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in crates/rmcp/src/transport/auth.rs omits the RFC 9728 resource field from ResourceServerMetadata and allows discover_oauth_server_via_resource_metadata to use protected-resource metadata without confirming that the returned resource identifier exactly matches the configured MCP… |
|
| CVE-2026-63128 | — | High 7.5 | 0.6%top 51.6% | 16 Sep 2026 | RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's stateful Streamable HTTP server in crates/rmcp/src/transport/streamable_http_server/tower.rs allows an unauthenticated client to send a well-formed JSON-RPC POST that is not an initialization request, or an initialization request with a mismatched protocol header, causing… |
|
| CVE-2026-92816 | — | High 7.8 | 0.2%top 90.8% | 16 Sep 2026 | ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arbitrary paths outside the output directory. Attackers can load a crafted workflow that writes attacker-controlled content to arbitrary locations, enabling code execution through modified startup files or package initializers. |
LLM05:2025 |
| CVE-2026-57173 | — | Medium 6.5 | 0.7%top 49.0% | 16 Sep 2026 | vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling path for /v1/chat/completions calls AudioMediaIO.load_bytes or AudioMediaIO.load_file without passing VLLM_MAX_AUDIO_DECODE_DURATION_S to the shared audio decoder. An unauthenticated client can therefore submit a small compressed audio input that expands into a very large float32 PCM… |
|
| CVE-2026-69147 | — | Medium 6.5 | 0.5%top 56.0% | 16 Sep 2026 | vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions and Responses can set media_io_kwargs.video.video_backend to pynvvideocodec, and MediaConnector.fetch_video forwards that choice to VideoMediaIO even when startup configuration selected a software decoder. The engine's _reserve_mm_ipc_gpu_memory logic budgets decoder memory only… |
LLM10:2025 |
| CVE-2026-92220 | — | Medium 5.3 | 0.7%top 48.4% | 16 Sep 2026 | A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected is the function MoRIIOConnectorScheduler.request_finished/MoRIIOConnectorWorker.get_finished/MoRIIOWrapper._handle_release_message of the file vllm/distributed/kv_transfer/kv_connector/v1/moriio/moriio_connector.py of the component MoRIIO Acknowledgement Handler. Performing a manipulation of the argument… |
|
| CVE-2026-92365 | — | Medium 4.3 | 0.5%top 57.8% | 16 Sep 2026 | A vulnerability was found in vllm-project vllm up to 0.29.0. Affected by this issue is some unknown functionality of the file vllm/v1/sample/thinking_budget_state.py. The manipulation results in inefficient algorithmic complexity. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance. |
|
| CVE-2026-64684 | — | Medium 6.8 | 0.5%top 59.3% | 16 Sep 2026 | RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs builds its default_http_client with reqwest's automatic redirect policy and applies caller-supplied values from StreamableHttpClientTransportConfig.custom_headers without marking them as sensitive. When a… |
|
| CVE-2026-59823 | — | Unscored | 0.4%top 64.1% | 16 Sep 2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an authenticated LiteLLM Proxy caller with a valid virtual key can place api_base inside the user_config request body to bypass is_request_body_safe, which blocks top-level api_base and base_url but previously did not inspect or reject user_config. Because user_config constructs the outbound… |
|
| CVE-2026-59971 | — | Critical 10.0 | 0.4%top 66.1% | 15 Sep 2026 | MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct SseServerTransport without security_settings or enable_dns_rebinding_protection, while the Starlette routes /, /sse, and /messages/ have no authentication and the service binds to 0.0.0.0 by default.… |
LLM05:2025 |
| CVE-2026-61559 | — | Critical 9.6 | 0.4%top 65.3% | 15 Sep 2026 | `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the server reads the `X-GitLab-API-URL` HTTP request header and uses it as the base URL for all outbound GitLab API calls made within that request. The server validates that the value is a well-formed URL… |
|
| CVE-2026-61568 | — | Critical 9.6 | 0.5%top 57.0% | 15 Sep 2026 | `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route browser requests to a victim's local MCP listener while preserving an attacker-controlled `Host` and `Origin`. The server accepts those headers and reaches the MCP… |
|
| CVE-2026-61560 | — | Critical 9.8 | 2.9%top 13.5% | 15 Sep 2026 | `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`SSE=true`) exposes all MCP tools without any authentication. The `upload_markdown` tool reads arbitrary files from the server's local filesystem via an unsanitized `file_path` parameter and uploads them to a GitLab project. Combined, any unauthenticated network-reachable… |
|
| CVE-2026-53957 | — | High 7.7 | 0.4%top 66.5% | 15 Sep 2026 | Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to @contentful/mcp-server 1.7.19 and @contentful/mcp-tools 0.4.5, export_space and import_space in packages/mcp-tools/src/tools/jobs/space-to-space-migration/exportSpace.ts and packages/mcp-tools/src/tools/jobs/space-to-space-migration/importSpace.ts expose host, proxy, rawProxy, and insecure network… |
LLM01:2025 |
| CVE-2026-91935 | — | High 8.3 | 0.4%top 69.4% | 15 Sep 2026 | Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect requests to arbitrary hosts. Attackers with chatflows:create or chatflows:update permissions can exfiltrate LLM provider API keys by redirecting requests to cloud metadata services or internal hosts. |
|
| CVE-2026-59973 | — | High 8.5 | 0.4%top 68.9% | 15 Sep 2026 | FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). From mcp-from-openapi 2.3.0 until 2.5.0 and from frontmcp and @frontmcp/adapters 1.2.1 until 1.5.0, libs/adapters/src/openapi/openapi.adapter.ts loadOpenAPISpec() forwards untrusted OpenAPI url and spec inputs and loadOptions.refResolution to OpenAPIToolGenerator.fromURL() and OpenAPIToolGenerator.fromJSON(). The… |
|
| CVE-2026-54547 | — | High 7.4 | 0.5%top 58.0% | 15 Sep 2026 | Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, AuthInjectionMiddleware in meta_ads_mcp/core/http_auth_integration.py rejects HTTP MCP requests only when both auth_token and pipeboard_token are absent, while extract_token_from_headers() does not recognize X-Pipeboard-Token as a primary credential. A network caller using the… |
|
| CVE-2026-54549 | — | High 8.3 | 0.4%top 68.2% | 15 Sep 2026 | Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, the upload_ad_image tool in meta_ads_mcp/core/ads.py passes an attacker-controlled image_url to try_multiple_download_methods() in meta_ads_mcp/core/utils.py, where httpx.AsyncClient uses follow_redirects=True and performs HTTP requests without validating the scheme, host, or… |
LLM05:2025 |
| CVE-2026-58483 | — | High 7.5 | 0.7%top 49.8% | 15 Sep 2026 | mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.7.1, web_url_read in src/index.ts passes a caller-supplied URL to readUrlContent() in src/url-reader.ts, where checkContentLength() treats a missing Content-Length header as an inconclusive preflight and the normal and error paths then consume the complete… |
LLM10:2025 |
| CVE-2026-58485 | — | High 7.1 | 0.2%top 92.4% | 15 Sep 2026 | mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.7.1, web_url_read receives its caller-controlled URL through src/index.ts and validates only the literal hostname in assertUrlAllowed() within src/url-reader.ts before undiciFetch() performs operating-system DNS resolution. A public-looking… |
|
| CVE-2026-54561 | — | Medium 6.2 | 0.2%top 85.2% | 15 Sep 2026 | MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants. Prior to 0.13.0, context_import in src/index.ts passes the caller-controlled filePath directly to fs.readFileSync without restricting the path to an export directory. An MCP client, including an LLM agent induced to call the tool, can use ../ traversal or an absolute path to target any file readable by… |
|
| CVE-2026-90878 | — | Medium 4.3 | 0.5%top 57.0% | 15 Sep 2026 | A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. This manipulation of the argument chat_template causes resource consumption. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. |
|
| CVE-2026-58196 | — | Medium 4.7 | 0.4%top 65.1% | 15 Sep 2026 | ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.31.0, remote.Handler.Authenticate in pkg/auth/remote/handler.go invokes discovery.DetectAuthenticationFromServer in pkg/auth/discovery/discovery.go, whose host-side HTTP clients trust remote-server-controlled authentication discovery destinations, follow redirects without… |
|
| CVE-2026-54689 | — | Medium 6.3 | 0.2%top 92.2% | 15 Sep 2026 | mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, the web_url_read URL policy in src/url-reader.ts can be bypassed while MCP_HTTP_HARDEN is enabled and MCP_HTTP_ALLOW_PRIVATE_URLS is not enabled because redirect targets are not revalidated, 0.0.0.0 is not classified as an internal address, and… |
|
| CVE-2026-54450 | — | Unscored | 0.3%top 76.5% | 15 Sep 2026 | ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.29.1, networking.IsPrivateIP in pkg/networking/utilities.go omits the IPv6 NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48, so NAT64 addresses embedding private, loopback, or link-local IPv4 targets are classified as public and allowed. The most direct attacker-controlled… |
|
| CVE-2026-58201 | — | Unscored | 0.5%top 60.8% | 15 Sep 2026 | Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services. Prior to 2.1.2, the Lokka-Microsoft tool in src/mcp/src/main.ts uses direct URL string concatenation to append the user-controlled path value to the management.azure.com base URL. A specially crafted path can alter URL authority parsing and cause an Azure Resource Manager bearer token to be… |
|
| CVE-2026-57441 | — | Unscored | 0.2%top 90.9% | 15 Sep 2026 | MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.4, PathFilter in src/pathfilter.ts compiles restricted-directory patterns case-sensitively and compares paths without canonicalizing filesystem-equivalent segment names. On case-insensitive macOS and Windows filesystems, case variants of .git, .obsidian, or node_modules pass both… |
|
| CVE-2026-57442 | — | Unscored | 0.2%top 92.0% | 15 Sep 2026 | MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5, PathFilter in src/pathfilter.ts uses root-anchored deny-list patterns, so nested .git, .obsidian, and node_modules path segments do not match the restriction and pass both isAllowed() and isAllowedForListing(). An attacker who influences a path selected by an AI agent can… |
|
| CVE-2026-57145 | — | Critical 9.1 | 0.5%top 56.3% | 14 Sep 2026 | PraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py passes the LLM-controlled filepath parameter directly to open for reading and writing without traversal rejection, symlink resolution, a workspace boundary, or protected-path checks. Prompt-influenced agents can read files through edit and diff behavior or overwrite files accessible to the… |
|
| CVE-2026-12944 | — | Critical 9.6 | 0.4%top 65.1% | 14 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via IMDSv1 SSRF with full IAM role permissions, (2) arbitrary file exfiltration from the container filesystem, and (3) lateral movement to internal… |
LLM05:2025 |
| CVE-2026-90938 | — | High 8.6 | 0.6%top 54.6% | 14 Sep 2026 | LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server on 0.0.0.0:5401 (/plugin/ws) whose authentication is gated on plugin_debug_key, which defaults to an empty string and is never set by the upstream repository, Docker image, or docker-compose (which additionally publishes port 5401 to the host); the key check is therefore skipped entirely. Any… |
LLM10:2025 |
| CVE-2026-57130 | — | High 8.1 | 0.5%top 62.1% | 14 Sep 2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/email_tools.py interpolates LLM-controlled from_addr, subject, and query values directly into quoted IMAP SEARCH criteria. Embedded quote, backslash, newline, or null characters can escape the intended criterion and alter IMAP operations when search_emails, reply_email, or… |
|
| CVE-2026-55253 | — | High 7.7 | 0.5%top 57.1% | 14 Sep 2026 | LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. Prior to langgraph-checkpoint-mongodb 0.3.0 and langgraph-store-mongodb 0.4.0, MongoDBSaver.list(), MongoDBSaver.alist(), and MongoDBStore.search() incorporate filter dictionaries into MongoDB queries without recursively rejecting keys prefixed with $. An authenticated caller who controls a filter argument… |
|
| CVE-2026-73496 | — | High 7.7 | 0.5%top 60.7% | 14 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src/mcp_atlassian/confluence/attachments.py upload_attachment, and the jira_update_issue attachments parameter reaches src/mcp_atlassian/jira/attachments.py… |
|
| CVE-2026-55837 | — | Medium 6.8 | 0.3%top 82.1% | 14 Sep 2026 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.20.0, the local OAuth helper in src/dbt_mcp/oauth/fastapi_app.py exposes GET /dbt_platform_context without authentication or Host validation after a user completes the dbt Platform OAuth flow. The endpoint returns the full DbtPlatformContext, including access_token and refresh_token values persisted by the context… |
|
| CVE-2026-73497 | — | Medium 6.5 | 0.4%top 70.9% | 14 Sep 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). From 0.17.0 until 0.22.0, validate_url_for_ssrf resolves the attacker-controlled X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url header host once at middleware time, but the outbound request is built with the raw hostname and resolves it again at connection time with no IP pinning. An… |
|
| CVE-2026-17628 | — | Medium 5.4 | 0.3%top 75.2% | 14 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to change the password of an account due to improper authentication. |
|
| CVE-2026-12763 | — | Medium 4.2 | 0.1%top 96.6% | 14 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP Tools component. |
|
| CVE-2026-12765 | — | Medium 6.5 | 0.2%top 89.1% | 14 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. |
LLM05:2025 |
| CVE-2026-12766 | — | Medium 5.4 | 0.2%top 93.0% | 14 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. |
LLM05:2025 |
| CVE-2026-12767 | — | Medium 6.5 | 0.2%top 89.0% | 14 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. |
LLM05:2025 |
| CVE-2026-90713 | — | Low 3.3 | 0.2%top 95.5% | 14 Sep 2026 | A security flaw has been discovered in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the file rust/src/text/src/backend/hf/mod.rs of the component tiktoken vocab File Handler. The manipulation results in denial of service. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The… |
LLM10:2025 |
| CVE-2026-90553 | — | High 7.8 | 0.3%top 78.5% | 12 Sep 2026 | vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with vLLM process authority even when trust_remote_code is set to False. |
LLM05:2025 |
| CVE-2026-90534 | — | Medium 6.5 | 0.4%top 71.4% | 12 Sep 2026 | Flowise is a low-code platform for building LLM applications. In versions up to and including 3.1.3, the POST /api/v1/node-load-method/:name endpoint is mounted without any route-level permission check and invokes component loadMethods with an attacker-controlled nodeName, loadMethod, inputs, and credential value. The selected credential is resolved by raw Credential.id via getCredentialData()… |
|
| CVE-2026-90554 | — | Medium 6.2 | 0.2%top 91.0% | 12 Sep 2026 | vLLM versions >=0.10.2 and <0.28.0 do not apply any audio decode-size or duration limit when extracting audio from video input for NanoNemotronVL models. In nano_nemotron_vl.py, _extract_audio_from_videos calls load_audio_pyav(BytesIO(video_bytes)) without the max_duration_s or max_decode_bytes parameters, so neither VLLM_MAX_AUDIO_DECODE_DURATION_S nor VLLM_MAX_AUDIO_DECODE_BYTES is enforced… |
LLM10:2025 |
| CVE-2026-90555 | — | Medium 6.5 | 0.5%top 57.9% | 12 Sep 2026 | vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigger excessive memory allocation and crash the API server process affecting all tenants. |
|
| CVE-2026-71416 | — | High 8.8 | 0.2%top 88.8% | 11 Sep 2026 | Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to the upstream server, allowing malicious WebSocket clients to perform arbitrary LLM requests without authentication. This can be exploited by a malicious WebSocket… |
|
| CVE-2026-85025 | — | Critical 9.8 | 0.6%top 52.4% | 10 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session isolation controls. |
LLM05:2025 |
| CVE-2026-79724 | — | Critical 9.8 | 0.7%top 49.6% | 10 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command. |
|
| CVE-2026-81204 | — | Critical 9.8 | 0.9%top 42.9% | 10 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction. |
LLM05:2025 |
| CVE-2026-19136 | — | High 7.8 | 0.9%top 42.7% | 10 Sep 2026 | A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system commands to be executed if a local user opens a specially crafted link that is handled by the application. |
LLM05:2025 |
| CVE-2026-76059 | — | High 8.8 | 0.7%top 49.5% | 10 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom component source code could bypass the static security scanner by crafting an annotated class-body assignment that resolved to a dangerous callable through alias tracking; the resolved value was never checked against the dangerous callable blocklist due to the logic error. If the crafted component reached the runtime… |
|
| CVE-2026-78569 | — | High 8.8 | 0.7%top 50.5% | 10 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner. |
LLM05:2025 |
| CVE-2026-78571 | — | High 8.8 | 0.8%top 44.7% | 10 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an unguarded eval() call on attacker-controlled input. |
LLM05:2025 |
| CVE-2026-78575 | — | High 8.8 | 0.8%top 45.1% | 10 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration. |
LLM05:2025 |
| CVE-2026-79742 | — | High 8.8 | 0.8%top 44.7% | 10 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist. |
LLM05:2025 |
| CVE-2026-81211 | — | High 8.8 | 0.5%top 59.5% | 10 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows. |
|
| CVE-2026-81213 | — | High 8.6 | 0.5%top 60.1% | 10 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs. |
|
| CVE-2026-81265 | — | High 7.5 | 0.4%top 68.8% | 10 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.5. |
|
| CVE-2026-81268 | — | High 8.1 | 0.4%top 64.6% | 10 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation. |
|
| CVE-2026-81940 | — | High 8.8 | 0.8%top 44.7% | 10 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names. |
LLM05:2025 |
| CVE-2026-81941 | — | High 8.8 | 0.6%top 51.8% | 10 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component configured to use a local stdio subprocess transport. This bypasses both the LANGFLOW_CUSTOM_COMPONENT_ADMIN_ONLY and… |
LLM02:2025LLM05:2025 |
| CVE-2026-84889 | — | High 8.8 | 0.9%top 43.1% | 10 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory. |
LLM05:2025 |
| CVE-2026-88055 | — | Medium 5.5 | 0.3%top 81.5% | 10 Sep 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.16.1 and earlier, the manager role can store meta_page_title or meta_page_favicon through /api/admin/system-preferences, and MetaGenerator inserts those values into production homepage HTML without escaping attribute values or text content. The values pass unchanged… |
|
| CVE-2026-88938 | — | Medium 6.5 | 0.5%top 60.7% | 10 Sep 2026 | knowns through 0.33.0 fails to confine the path argument of the code.find MCP tool to the project root, allowing AI agent sessions to read source files anywhere on the host. Attackers can supply absolute paths or relative traversal sequences to the path argument and retrieve full file contents from outside the intended project directory. |
|
| CVE-2026-9225 | — | Medium 6.5 | 0.3%top 73.8% | 10 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access control in the File/Read File component. When executing flows through the /api/v1/run/advanced/{flow_id} endpoint, the application allows component inputs to reference storage paths using arbitrary user or flow identifiers without verifying… |
|
| CVE-2026-79723 | — | Medium 5.0 | 0.4%top 73.4% | 10 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API endpoints. |
|
| CVE-2026-79725 | — | Medium 6.5 | 0.4%top 66.5% | 10 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to improper access control. |
|
| CVE-2026-53937 | — | Medium 6.2 | 0.2%top 92.6% | 09 Sep 2026 | MCP Kotlin SDK is the Kotlin Multiplatform software development kit for the Model Context Protocol. In versions 0.7.0 through 0.12.0, `ReadBuffer.append` in `kotlin-sdk-core/src/commonMain/kotlin/io/modelcontextprotocol/kotlin/sdk/shared/ReadBuffer.kt` writes every chunk of bytes received from the stdio transport into a `kotlinx.io.Buffer` with no size cap. Frames are extracted from that buffer… |
LLM10:2025 |
| CVE-2026-79721 | — | Unscored | 0.5%top 61.2% | 08 Sep 2026 | Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project. |
LLM05:2025 |
| CVE-2026-86289 | — | Medium 4.3 | 0.7%top 48.9% | 07 Sep 2026 | A vulnerability was found in Ollama up to 0.31.1. This issue affects the function readGGUFV1String of the file fs/ggml/gguf.go of the component GGUF Decoder. Performing a manipulation results in integer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 0.31.2-rc1 is capable of addressing this issue. The patch is… |
|
| CVE-2026-31020 | — | Critical 9.8 | 1.0%top 37.3% | 04 Sep 2026 | In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionality renders user-supplied prompt data using Jinja templates without input sanitization or sandboxing. An unauthenticated attacker can inject malicious template expressions, leading to a server-side template injection (SSTI)… |
LLM05:2025 |
| CVE-2026-85674 | — | High 7.8 | 0.2%top 85.3% | 04 Sep 2026 | aider (aider-chat) automatically loads a .aider.conf.yml configuration file from the root of the git repository it is launched in. A crafted repository can set test-cmd (executed at startup) or lint-cmd (executed on the first file edit), which aider runs through a shell (subprocess with shell=True) without any user confirmation, LLM interaction, or API key. Consequently, a user who clones and… |
LLM05:2025 |
| CVE-2026-85675 | — | High 7.5 | 0.5%top 60.6% | 04 Sep 2026 | OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content tool that fetches caller-supplied URLs with no scheme, host, or IP filtering. Attackers can inject malicious URLs through prompt injection to make the server fetch internal resources, with responses returned to the agent context. |
LLM01:2025LLM05:2025 |
| CVE-2026-85694 | — | High 8.1 | 0.9%top 40.3% | 04 Sep 2026 | LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code through web pages using indirect prompt injection to execute arbitrary code on the operator's host without review. |
LLM01:2025LLM05:2025 |
| CVE-2026-19298 | — | High 8.8 | 0.5%top 59.3% | 04 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process. |
LLM05:2025 |
| CVE-2026-19300 | — | High 7.5 | 0.4%top 70.9% | 04 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields. |
|
| CVE-2026-19303 | — | High 8.1 | 0.4%top 68.6% | 04 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to a restricted directory. |
|
| CVE-2026-19304 | — | High 7.7 | 0.3%top 78.6% | 04 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from internal services due to a URL parser discrepancy. |
|
| CVE-2026-19305 | — | High 8.6 | 0.3%top 80.7% | 04 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery. |
LLM05:2025 |
| CVE-2026-19306 | — | High 7.7 | 0.4%top 68.0% | 04 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/self/environ, and other tenants' upload directories) — by supplying absolute paths or traversal sequences in the files parameter of an authenticated build request. The file… |
|
| CVE-2026-19645 | — | Medium 6.5 | 0.3%top 80.5% | 04 Sep 2026 | IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a valid session cookie can submit arbitrarily large or computationallyexpensive requests that cause the LLM agent workers to be held for extended periods — rangingfrom tens of seconds to over ten minutes per request. When multiple such requests are sentconcurrently, the agent worker pool becomes exhausted, causing all… |
|
| CVE-2026-8447 | — | Medium 6.1 | 0.3%top 79.4% | 04 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site scripting vulnerability in the Playground chat interface. |
LLM05:2025 |
| CVE-2026-9138 | — | Medium 6.5 | 0.4%top 67.1% | 04 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in the SaveToFileComponent. The application constructs local file paths using attacker‑controlled input without sufficient sanitization when handling requests to the /api/v1/run/{flow_id} endpoint. An attacker with low‑privileged… |
LLM05:2025 |
| CVE-2026-9186 | — | Medium 6.5 | 0.4%top 70.1% | 04 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 header, enabling arbitrary writes to IDE config files (~/.cursor/mcp.json, etc.). |
|
| CVE-2026-19299 | — | Medium 6.5 | 0.5%top 60.3% | 04 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to path traversal. |
LLM05:2025 |
| CVE-2026-19301 | — | Medium 5.0 | 0.3%top 80.8% | 04 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery. |
LLM05:2025 |
| CVE-2026-19302 | — | Medium 6.5 | 0.5%top 60.3% | 04 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links. |
|
| CVE-2026-14470 | — | Medium 6.5 | 0.3%top 75.3% | 04 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. |
|
| CVE-2026-17621 | — | Medium 5.4 | 0.3%top 80.2% | 04 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system. |
|
| CVE-2026-17622 | — | Medium 6.5 | 0.5%top 60.3% | 04 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory. |
|
| CVE-2026-17627 | — | Medium 4.9 | 0.2%top 91.2% | 04 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to improper authorization. |
|
| CVE-2026-17631 | — | Medium 5.0 | 0.2%top 87.2% | 04 Sep 2026 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability. |
LLM05:2025 |
| CVE-2026-84779 | — | High 8.1 | 0.4%top 73.7% | 03 Sep 2026 | Subscriber Broken Access Control in Agentimus – AI SEO, llms.txt & MCP for AI Agents <= 1.51.0 versions. |
|
| CVE-2026-85180 | — | High 7.5 | 0.5%top 59.5% | 03 Sep 2026 | Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenticated attackers to redirect blob downloads to arbitrary hosts. An attacker can control a registry, serve a malicious tensor-layer manifest, and cause the server to issue GET requests to internal hosts including cloud metadata endpoints. |
|
| CVE-2026-82404 | — | High 8.3 | 0.7%top 49.4% | 02 Sep 2026 | TOON is a compact, human-readable serialization of JSON data for LLM prompts. Prior to 2.3.1, decoding attacker-controlled TOON with a __proto__, constructor, or prototype key wrote through the object prototype chain instead of creating an own property, polluting Object.prototype for the runtime. In packages/toon/src/decode/expand.ts, the expandPaths: 'safe' path and insertPathSafe function made… |
LLM05:2025LLM10:2025 |
| CVE-2026-84377 | — | Medium 6.5 | 0.5%top 56.6% | 02 Sep 2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versions 1.88.6 and 1.96.2, any authenticated LiteLLM proxy user could redirect an outbound provider call to a destination the user controls and cause the proxy to send its configured provider credentials to that destination. Request validation in litellm/proxy/auth/auth_utils.py,… |
|
| CVE-2026-79745 | — | High 7.1 | 0.4%top 64.1% | 31 Aug 2026 | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, the built-in prompt and resource controllers perform no role checking. The mutating POST/PUT /api/prompts* and POST/PUT /api/resources* routes are attached to the authenticated router with no admin gate, and the… |
LLM01:2025 |
| CVE-2026-82217 | — | High 8.8 | 0.6%top 52.3% | 31 Aug 2026 | In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agent Mode" file-change tools (writeFileContent, suggestFileContent, and the replacement and state helpers) resolved a model-supplied file path without a workspace-containment check. A crafted relative path such as ../.bashrc, an absolute path, or a ~-expanded path could therefore write or delete files outside the workspace… |
LLM01:2025LLM05:2025 |
| CVE-2026-82640 | — | Medium 5.5 | 0.1%top 100.0% | 30 Aug 2026 | browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or access restrictions. Attackers with read access to the temporary settings directory can recover provider API keys from predictably-named JSON files. |
|
| CVE-2026-19286 | — | Critical 9.8 | 0.8%top 45.0% | 28 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint. |
LLM05:2025 |
| CVE-2026-19295 | — | Critical 9.9 | 3.3%top 12.0% | 28 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. This allowed privilege escalation from "authenticated flow user" to arbitrary OS-level command execution under the server process identity, bypassing… |
LLM06:2025 |
| CVE-2026-37237 | — | High 7.5 | 0.7%top 47.5% | 28 Aug 2026 | vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion. The AsyncMediaIO.fetch_audio and AsyncMediaIO.fetch_image functions in multimodal/inputs.py fetch user-supplied media URLs using aiohttp and call r.read() without enforcing a maximum response size, allowing an attacker to exhaust server memory by providing a URL to an arbitrarily large file. |
LLM10:2025 |
| CVE-2026-18729 | — | High 8.8 | 1.9%top 20.5% | 28 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code. |
LLM05:2025 |
| CVE-2026-18891 | — | High 8.2 | 0.3%top 77.4% | 28 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive information due to improper authentication. |
|
| CVE-2026-18899 | — | High 7.5 | 0.5%top 62.1% | 28 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traversal. |
LLM05:2025 |
| CVE-2026-18904 | — | High 8.2 | 0.3%top 78.5% | 28 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthorized messages due to a namespace collision between user identifiers. |
|
| CVE-2026-70331 | — | Medium 5.4 | 0.4%top 66.7% | 28 Aug 2026 | Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network. |
|
| CVE-2026-82233 | — | Medium 5.7 | 0.4%top 67.8% | 28 Aug 2026 | SiYuan before v3.8.1 contains a path traversal vulnerability in the asset.upload MCP tool that accepts arbitrary absolute file paths without workspace boundary validation. Attackers can induce the AI Agent to upload sensitive files such as SSH keys or credentials from outside the workspace into the asset directory through prompt injection. |
LLM01:2025LLM05:2025 |
| CVE-2026-54746 | — | Medium 6.4 | 0.4%top 71.7% | 28 Aug 2026 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. From 0.40.0 until 0.91.1, the Dispatcher gRPC service does not verify that a request's worker ID belongs to the tenant identified by the bearer-token context in Dispatcher/UpsertWorkerLabels and Dispatcher/Unsubscribe. An authenticated owner of any tenant who guesses another tenant's worker UUID… |
LLM10:2025 |
| CVE-2026-18545 | — | Medium 4.3 | 0.2%top 89.0% | 28 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. |
LLM05:2025 |
| CVE-2026-19294 | — | Medium 6.4 | 0.2%top 86.3% | 28 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute and read any user's private flow due to improper authorization. |
|
| CVE-2026-68929 | — | Unscored | 0.4%top 64.4% | 28 Aug 2026 | FastGPT is an open-source LLM platform for building AI applications on a knowledge base. In versions prior to 4.15.2, the WeChat (iLink) share-channel endpoints authorize requests using only the public shareId, with no authenticated identity or team-ownership check. As a result, an unauthenticated attacker who knows a victim team's shareId can take that team's WeChat bot offline or hijack the… |
|
| CVE-2026-37003 | — | Critical 9.8 | 1.3%top 30.1% | 27 Aug 2026 | Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection. The PythonTools and ShellTools components pass unsanitized, LLM-generated arguments directly to execution sinks including exec(), runpy.run_path(), and subprocess.run(). An unauthenticated attacker can exploit this by embedding malicious instructions in content processed by the agent (such as web… |
LLM01:2025LLM05:2025 |
| CVE-2026-37006 | — | Critical 9.8 | 0.9%top 42.0% | 27 Aug 2026 | A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker to achieve code execution via malicious Model Context Protocol configurations. |
LLM05:2025 |
| CVE-2026-55585 | — | High 8.8 | 0.8%top 45.8% | 25 Aug 2026 | QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, tool calls, code, schemas, and agent state before production execution. Prior to 5.1.2, the qwed package passes caller-controlled math expressions directly to SymPy parse_expr() without restricted global_dict and local_dict namespaces, allowing Python eval() to resolve builtins and execute arbitrary… |
|
| CVE-2026-78379 | — | High 8.1 | 0.6%top 54.5% | 25 Aug 2026 | Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute arbitrary Python code on the agent's host by bypassing the human consent gate, via a crafted prompt that forwards non_interactive_mode as a keyword argument through the batch tool. To remediate this issue, users should upgrade to version… |
|
| CVE-2026-78684 | — | Medium 5.3 | 0.6%top 52.7% | 25 Aug 2026 | vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream at request time to initialize the process-wide GPU decode pool and submit video that bypasses resource controls, causing partial denial of service for concurrent requests. |
LLM10:2025 |
| CVE-2026-55580 | — | Unscored | 0.2%top 91.5% | 25 Aug 2026 | mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, config.go initializes Security.Enabled to false, and when MCP_SHELL_SEC_CONFIG_FILE is unset, main.go starts the documented bare-binary deployment without a security policy. SecurityValidator.validateCommand in security.go then short-circuits and allows every command supplied to the… |
|
| CVE-2026-55557 | — | Unscored | 0.2%top 86.5% | 25 Aug 2026 | browse-mcp is a Playwright-based headless-browser MCP server for MCP-capable agents. Prior to 0.8.2, browser_download writes a fetched response body to join(save_dir, filename) without validating the caller-controlled save_dir, while browser_save_state and browser_load_state honor a caller-controlled path unchanged. A malicious MCP client, or an autonomous agent steered by indirect prompt… |
LLM01:2025LLM05:2025 |
| CVE-2026-53965 | — | Unscored | 0.6%top 52.4% | 25 Aug 2026 | The MCP PHP SDK (Composer package mcp/sdk) is the official Model Context Protocol SDK for PHP. In versions 0.5.0 through 0.7.0, the HTTP client transport reads a Server-Sent Events response stream incrementally and appends each chunk to an in-memory buffer with no upper bound. The buffer is only flushed when an SSE event delimiter, a double newline, is found, so a remote MCP server that streams… |
|
| CVE-2026-76072 | — | High 7.4 | 0.4%top 68.9% | 24 Aug 2026 | The Continue CLI applies an incomplete denylist as its only barrier to destructive shell commands when running unattended. In headless mode and auto mode the default policy in extensions/cli/src/permissions/defaultPolicies.ts grants the Bash tool the allow permission, and permissionChecker.ts hard-blocks a command only when the terminal-security evaluator returns a disabled verdict, so… |
LLM01:2025 |
| CVE-2026-77776 | — | Critical 9.1 | 0.6%top 52.5% | 21 Aug 2026 | Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat completion and websocket paths, and nothing binds the value to the caller. A client can therefore name another user's identifier and read or write that user's stored LLM memory. The fix introduces a single… |
|
| CVE-2026-62674 | — | Critical 9.0 | 0.5%top 58.9% | 21 Aug 2026 | Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent checks LEVEL_EDIT permission for a session but does not reject a bound shared or template agent whose agent.session_id is None. An authenticated user with edit access to a session can replace that shared agent bundle through… |
|
| CVE-2026-77775 | — | High 8.6 | 0.6%top 53.5% | 21 Aug 2026 | Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in headroom/proxy/handlers/openai.py accepts the header value, requires only that it parse with an http or https scheme and a hostname, and returns it for use as the upstream base; _select_passthrough_base_url in headroom/providers/proxy_routes.py reads the… |
|
| CVE-2026-54457 | — | High 7.7 | 0.4%top 67.9% | 21 Aug 2026 | TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026.6.0, the TensorZero Gateway /internal/object_storage endpoint accepts a caller-supplied JSON storage_path parameter that dynamically overrides the [object_storage] configuration. Selecting the filesystem storage type allows arbitrary files on the… |
|
| CVE-2026-62675 | — | High 8.8 | 0.7%top 50.6% | 21 Aug 2026 | Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipart POST /v1/sessions accepts an authenticated user's agent bundle and omnigent/server/bundles.py validate_agent_bundle does not reject a tools..callable dotted Python path. omnigent/runner/tool_dispatch.py _resolve_spec_callable imports the specified module and… |
|
| CVE-2026-62676 | — | High 7.1 | 0.4%top 67.9% | 21 Aug 2026 | Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, the shared shell-command parser in omnigent/policies/builtins/_shell.py fails to recognize combined interpreter flags, the timeout, nice, setsid, and stdbuf wrappers, command substitutions, and a single background control operator. A gated git push or gh write hidden with these forms… |
|
| CVE-2026-62677 | — | High 8.8 | 0.6%top 52.8% | 21 Aug 2026 | Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, an authenticated user can upload a session-scoped agent bundle with an absolute or traversal-containing os_env.cwd value because omnigent/spec/parser.py stores the value verbatim and omnigent/spec/validator.py does not constrain it. On a runner where OMNIGENT_RUNNER_WORKSPACE is unset,… |
|
| CVE-2026-18482 | — | Critical 9.8 | 1.7%top 24.3% | 20 Aug 2026 | Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, where the checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled absolutePath values into shell commands, enabling arbitrary OS command execution when an AI agent is induced to invoke these tools. Commit 88c77fc fixes these… |
LLM05:2025 |
| CVE-2026-54449 | — | High 8.8 | 0.7%top 47.7% | 20 Aug 2026 | LangBot is a global IM bot platform designed for LLMs. In version 4.10.7 and earlier, any authenticated user can add or change an STDIO MCP server configuration without an adequate authorization boundary. In src/langbot/pkg/provider/tools/loaders/mcp.py, StdioServerParameters accepts the configured command and arguments and starts a server-side subprocess on the LangBot server. An attacker who… |
LLM05:2025 |
| CVE-2026-17153 | — | Medium 5.3 | 0.5%top 62.1% | 20 Aug 2026 | The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to upload images to the WordPress media library, bypassing the upload_files capability restriction that Contributors… |
|
| CVE-2026-71492 | — | Unscored | 0.5%top 61.2% | 20 Aug 2026 | Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry.set() in src/banks/registries/directory.py interpolates attacker-controlled Prompt.name and Prompt.version values into a Path without canonicalization or containment validation. Relative traversal such as ../victim/foo and an absolute Prompt.name can escape or discard the… |
|
| CVE-2026-76832 | — | High 8.8 | 1.3%top 31.5% | 19 Aug 2026 | Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to read, write, or execute arbitrary files by supplying parent-directory traversal sequences in the file_name argument passed to read_file, save_to_file, or run_python_file tool actions. Attackers can inject traversal sequences such as '../../../../../../etc/passwd' through direct… |
LLM01:2025LLM05:2025 |
| CVE-2026-19875 | — | High 7.5 | 0.5%top 57.9% | 19 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information and abuse the server as an outbound relay due to missing authentication for the registration endpoint. |
|
| CVE-2026-75913 | — | Critical 9.3 | 0.5%top 61.0% | 18 Aug 2026 | CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv without an --end-of-options sentinel, so a value beginning with --output= is interpreted as a git flag. Because the tool is registered as auto-approved and advertised as read-only, an… |
LLM01:2025 |
| CVE-2026-75130 | — | Critical 9.0 | 0.5%top 60.1% | 18 Aug 2026 | Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents by injecting unsanitized content through the Custom AI Instructions feature served via the MCP server. Attackers can poison the custom instructions to exfiltrate credentials from environment files to an attacker-controlled service and perform… |
LLM01:2025 |
| CVE-2026-75857 | — | High 7.0 | 0.2%top 96.0% | 18 Aug 2026 | CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirement returns ApprovalRequirement::Auto. This overrides the default Required approval for code-executing tools, so LLM-controlled stdin is written into an already-approved long-running interactive shell (e.g., a python3 -i REPL, mysql, ssh, or sudo -i… |
|
| CVE-2026-75858 | — | High 7.8 | 0.4%top 72.0% | 18 Aug 2026 | CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool. The tool's approval_requirement() returns ApprovalRequirement::Auto, which the engine treats as 'never prompt,' causing arbitrary model-supplied Python code to run in a python3 interpreter without consulting the user's configured --approval-policy and… |
LLM01:2025LLM05:2025 |
| CVE-2026-50143 | — | High 8.1 | 0.5%top 60.1% | 18 Aug 2026 | The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior to 0.10.11, getActorMCPServerURL in src/mcp/actors.ts concatenates the trusted Actor standby URL with the attacker-controlled webServerMcpPath from an Actor definition without verifying the resulting origin, allowing a malicious Actor… |
|
| CVE-2026-75110 | — | Critical 9.8 | 0.7%top 50.0% | 17 Aug 2026 | MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, defaultless INTERNAL_SERVICE_SECRET environment variable is unset, the is_internal_request() check in src/memos/api/middleware/auth.py fails open: os.getenv("INTERNAL_SERVICE_SECRET") returns None and a request omitting the X-Internal-Service header… |
|
| CVE-2026-64859 | — | Critical 9.1 | 0.6%top 51.8% | 17 Aug 2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return User.AccessToken as access_token because User model objects are serialized after queries use Omit("password"), allowing an authenticated administrator to obtain the root user's bearer token and… |
|
| CVE-2026-69148 | — | High 7.1 | 0.4%top 71.5% | 17 Aug 2026 | MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_source_run() or _validate_source_model() in mlflow/server/handlers.py verifies only path containment, allowing authenticated users to create a model version that references another user's artifact… |
|
| CVE-2026-71486 | — | Medium 4.3 | 0.4%top 71.0% | 17 Aug 2026 | vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and /v1/chat/completions/derender endpoints accept caller-supplied GenerateResponse objects whose generate_responses, choices, token_ids, prompt_logprobs, logprobs.content, top_logprobs, and routed_experts structures are processed by OnlineDerenderer and tokenizer.decode before… |
|
| CVE-2026-73560 | — | Medium 6.5 | 0.4%top 67.3% | 17 Aug 2026 | vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the MiMoV2OmniMultiModalProcessor in vllm/transformers_utils/processors/mimo_v2_omni.py passes attacker-controlled image and audio strings through _fetch_image, requests.get, and Image.open instead of MediaConnector, bypassing allowed_media_domains and allowed_local_media_path protections and allowing server-side… |
|
| CVE-2026-69146 | — | Medium 6.5 | 0.4%top 69.4% | 17 Aug 2026 | MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the mlflow/server/auth package, allowing any authenticated user to call POST /api/2.0/mlflow/runs/log-inputs for another user's run_id and inject attacker-controlled DatasetInput records into the… |
|
| CVE-2026-73678 | — | Critical 10.0 | 1.6%top 25.2% | 14 Aug 2026 | MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/responses/ endpoint, which reaches the Anton agent's scratchpad tool that calls exec() on attacker-influenced Python source without sandboxing.… |
LLM05:2025 |
| CVE-2026-73487 | — | Critical 9.8 | 0.8%top 46.0% | 13 Aug 2026 | Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via prompt injection. Attackers can exploit unblocked pandas functions like pd.read_json() to exfiltrate datasets, perform SSRF against internal services, or achieve code execution through the unauthenticated prediction API. |
LLM01:2025LLM05:2025 |
| CVE-2026-73656 | — | Critical 9.9 | 0.5%top 59.6% | 13 Aug 2026 | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls CreateDeploymentBackgroundWorkerServiceV4.call() in apps/webapp/app/v3/services/createDeploymentBackgroundWorkerV4.server.ts, where workerDeployment.findFirst() selects a deployment by friendlyId without an environmentId… |
|
| CVE-2026-19297 | — | Critical 9.1 | 0.6%top 52.8% | 13 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts. |
|
| CVE-2026-73485 | — | High 8.8 | 0.6%top 53.3% | 13 Aug 2026 | Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Python code by bypassing the pythonCodeValidator blocklist through obfuscation techniques. Attackers can send crafted prompts to a chatflow using the Airtable Agent node to inject malicious Python code that executes in an unsandboxed pyodide… |
|
| CVE-2026-19753 | — | High 7.3 | 0.5%top 61.4% | 13 Aug 2026 | A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of the file src/mcp-rdf-explorer/server.py of the component MCP Server. Performing a manipulation of the argument url results in server-side request forgery. The attack may be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this… |
LLM05:2025 |
| CVE-2026-73654 | — | High 8.5 | 0.6%top 52.1% | 13 Aug 2026 | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 3.3.8 until 4.5.6, the PUT /api/v1/runs/:runId/metadata endpoint passes attacker-controlled operation.key values to new JSONHeroPath(operation.key).set(newMetadata, value) in packages/core/src/v3/runMetadata/operations.ts without rejecting dangerous constructor and prototype path segments. A caller… |
LLM10:2025 |
| CVE-2026-73655 | — | High 7.4 | 0.5%top 61.5% | 13 Aug 2026 | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.2, addGoogleStrategy() in apps/webapp/app/services/googleAuth.server.ts passes a Google profile email to findOrCreateGoogleUser() in apps/webapp/app/models/user.server.ts without requiring Google's email_verified assertion. When existingEmailUser && !existingUser is true, the flow writes the… |
|
| CVE-2026-73658 | — | High 8.2 | 0.4%top 66.8% | 13 Aug 2026 | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() and Aws4FetchClient.presign() in apps/webapp/app/v3/objectStoreClient.server.ts assign user-controlled packet keys to URL.pathname, while apps/webapp/app/routes/api.v1.packets.$.ts accepts params["*"] without rejecting dot segments and uses… |
|
| CVE-2026-73555 | — | Medium 5.3 | 0.4%top 66.8% | 13 Aug 2026 | vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in vllm/entrypoints/openai/server_utils.py converts FastAPI RequestValidationError objects with str(exc), and sanitize_message in vllm/entrypoints/utils.py does not remove traceback-style file paths, allowing unauthenticated malformed JSON requests to /v1/chat/completions,… |
|
| CVE-2026-73556 | — | Medium 5.3 | 0.5%top 58.2% | 13 Aug 2026 | vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex parameter in vllm/v1/structured_output/backend_lm_format_enforcer.py is passed to lmformatenforcer.RegexParser without compile_regex_with_timeout or validation in validate_structured_output_request_lm_format_enforcer, allowing an unauthenticated /v1/completions request against the… |
|
| CVE-2026-73558 | — | Medium 5.3 | 0.4%top 66.6% | 13 Aug 2026 | vLLM is an inference and serving engine for large language models. Prior to 0.27.0, an integer overflow in blockIdx.x * 2 * d in activation_kernels.cu can cause act_and_mul_kernel to consume another batched user's input, allowing a request processed in the same inference batch to receive a partial or complete copy of another user's inference result. This issue is fixed in version 0.27.0. |
|
| CVE-2026-73559 | — | Medium 6.5 | 0.6%top 54.0% | 13 Aug 2026 | vLLM is an inference and serving engine for large language models. From 0.19.0 until 0.26.0, the /v1/completions CompletionRequest.prompt field in vllm/entrypoints/openai/completion/protocol.py accepts an unbounded list[str] or list[list[int]], prompt_to_seq() in vllm/renderers/inputs/preprocess.py and OnlineRenderer.preprocess_completion() in vllm/renderers/online_renderer.py expand every… |
|
| CVE-2026-49856 | — | Medium 4.3 | 0.3%top 81.3% | 13 Aug 2026 | @jshookmcp/jshook is an MCP server that gives AI agents tools for JavaScript analysis and security research. In version 0.3.1, he network domain has a central SSRF authorization policy that blocks private, loopback, link-local, and reserved targets unless an explicit authorization object allows private network access. The policy is enforced by raw HTTP/TCP/TLS RTT tools, but the ICMP probe and… |
LLM05:2025 |
| CVE-2026-73657 | — | Medium 4.2 | 0.2%top 93.5% | 13 Aug 2026 | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.4, `POST /api/v1/runs/:runParam/replay` in apps/webapp/app/routes/api.v1.runs.$runParam.replay.ts uses `prisma.taskRun.findUnique({ where: { friendlyId: runParam } })` without a runtimeEnvironmentId filter, then ReplayTaskRunService in… |
|
| CVE-2026-73557 | — | Unscored | 0.4%top 67.6% | 13 Aug 2026 | vLLM is an inference and serving engine for large language models. From 0.20.2rc0 until 0.26.0, safe_load_prompt_embeds in vllm/renderers/embed_utils.py uses torch.sparse.check_sparse_tensor_invariants, whose process-global save, enable, and restore state can be raced by concurrent prompt_embeds parts submitted to POST /v1/chat/completions through AsyncMultiModalItemTracker.resolve_items,… |
|
| CVE-2026-73299 | — | Critical 10.0 | 1.8%top 22.5% | 12 Aug 2026 | Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype properties to execute JavaScript in the host Node.js process. This issue is fixed in versions 0.1.5 and… |
|
| CVE-2026-73498 | — | High 7.7 | 0.5%top 60.7% | 12 Aug 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplied file_path directly to open(file_path, "rb") in src/mcp_atlassian/confluence/attachments.py through _upload_attachment_direct() without calling validate_safe_path. An authenticated MCP client can read any file accessible to… |
|
| CVE-2026-73032 | — | Critical 9.6 | 0.6%top 55.5% | 11 Aug 2026 | PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning malicious code from an LLM endpoint that is passed unsanitized to window.eval() in views.ts. Attackers can exploit this through prompt injection in PDFs, MITM interception of API requests, or a malicious custom LLM endpoint to execute arbitrary code in… |
LLM01:2025LLM05:2025 |
| CVE-2026-72771 | — | Medium 6.5 | 0.4%top 72.8% | 11 Aug 2026 | n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoint URLs are configured. Low-privileged workflow editors with use-only access to shared credentials can redirect requests to attacker-controlled hosts and exfiltrate credential secrets for reuse against underlying services. |
|
| CVE-2026-27765 | — | Medium 5.5 | 0.1%top 99.0% | 11 Aug 2026 | Improper input validation for some vLLM Hardware Plugin for Intel(R) Gaudi(R) software before version 0.16.0 within Ring 3: User Applications may allow a denial of service. Authorized adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special… |
LLM10:2025 |
| CVE-2026-73068 | — | Medium 5.9 | 0.3%top 82.5% | 11 Aug 2026 | ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.207, the ToolJet Database HTTP API in server/src/modules/tooljet-db/controller.ts authorizes operations against the :organizationId URL path value without verifying that the caller belongs to that organization. JwtAuthGuard validates the tj-workspace-id… |
|
| CVE-2026-20755 | — | Unscored | 0.2%top 95.3% | 11 Aug 2026 | Protection mechanism failure for some LLM Scaler software within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires… |
|
| CVE-2026-21387 | — | Unscored | 0.2%top 95.3% | 11 Aug 2026 | Protection mechanism failure for some Intel(R) LLM Library for PyTorch within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and… |
|
| CVE-2026-28707 | — | Unscored | 0.2%top 95.3% | 11 Aug 2026 | Protection mechanism failure for some LLM-on-Ray before version 1.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and… |
|
| CVE-2026-72917 | — | Medium 5.9 | 0.3%top 74.0% | 10 Aug 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.0.0 to 1.15.0, AnythingLLM's unauthenticated account-recovery flow in server/utils/PasswordRecovery/index.js uses recoverAccount() to deduplicate the raw recoveryCodes values before trimming them, so one valid code submitted twice with different surrounding whitespace… |
|
| CVE-2026-72904 | — | Unscored | 0.5%top 62.2% | 10 Aug 2026 | Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in Firecrawl's extraction functionality due to unsafe schema dereferencing of user-supplied JSON schemas in apps/api/src/lib/extract/helpers/dereference-schema.ts. The affected code invokes the json-schema-ref-parser dependency with default resolver… |
LLM05:2025 |
| CVE-2026-72718 | — | Unscored | 0.2%top 93.8% | 10 Aug 2026 | goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the `goose review` command runs the system `git` executable to gather the diff for review without stripping attacker-controlled Git configuration. A malicious repository whose `.git/config` sets [`core] fsmonitor = <command>` causes Git to execute that command on the host during the index refresh performed by `git diff… |
LLM05:2025 |
| CVE-2026-19334 | — | Medium 5.3 | 1.1%top 36.0% | 09 Aug 2026 | A flaw has been found in NightTrek Ollama-mcp up to 80cf2e17cfc144963a475b619093a2d13c13dbc9. This affects an unknown part of the file src/index.ts. This manipulation of the argument name/modelfile/source/destination causes command injection. The attack can only be executed locally. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected… |
LLM05:2025 |
| CVE-2026-61808 | — | Critical 9.8 | 2.5%top 15.8% | 07 Aug 2026 | LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an unauthenticated network attacker to read indexed document content, upload or delete documents, modify the knowledge graph, cancel pipelines, clear caches, and consume LLM resources. This issue is… |
|
| CVE-2026-48039 | — | Critical 9.1 | 0.6%top 53.7% | 07 Aug 2026 | Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streamable HTTP requests to downstream MCP tool handlers without issuing a `401` response, allowing any network-reachable caller to invoke MCP tools without… |
|
| CVE-2026-19111 | — | High 8.1 | 0.5%top 57.9% | 06 Aug 2026 | Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Agents Tools before 0.8.3 might allow remote authenticated users to access, modify, or delete memories belonging to other tenants by influencing the LLM to emit tool calls with a forged namespace parameter.
To remediate this issue, users should upgrade to version 0.8.3. |
|
| CVE-2026-67531 | — | Unscored | 0.7%top 47.2% | 06 Aug 2026 | FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host Zod schema instances to the script via getTool(), and because Zod v4 defines _zod as a non-configurable, non-writable own property, the ECMAScript Proxy invariants force the security membrane to hand back the raw host object, letting a script… |
LLM01:2025LLM05:2025 |
| CVE-2026-9196 | — | High 8.1 | 0.5%top 57.4% | 05 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑generated components. The application executes model‑generated Python code in the backend during validation prior to user approval, which may allow an attacker to trigger side effects such as outbound network access, file system… |
|
| CVE-2026-9081 | — | High 7.1 | 0.3%top 78.7% | 05 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_provider_key() function for the Ollama provider. The function accepts a user-supplied OLLAMA_BASE_URL parameter and passes it directly to requests.get() without validation, scheme/host allowlisting, or filtering of private IP ranges (loopback, RFC1918,… |
LLM05:2025 |
| CVE-2026-8446 | — | High 7.5 | 0.5%top 60.1% | 05 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_composer_enabled=true (default) and projects are configured with auth_type=oauth . |
|
| CVE-2026-17623 | — | High 8.8 | 0.8%top 45.1% | 05 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of the command field in MCP server configurations. |
LLM05:2025 |
| CVE-2026-17626 | — | High 8.8 | 0.4%top 66.2% | 05 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due to incomplete filtering of dangerous Docker volume-mount and device-mapping arguments. |
|
| CVE-2026-17630 | — | High 7.2 | 0.8%top 46.4% | 05 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation of configuration parameters. |
LLM05:2025 |
| CVE-2026-9077 | — | High 8.5 | 0.4%top 64.2% | 05 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system. |
|
| CVE-2026-17625 | — | High 7.2 | 0.8%top 44.7% | 05 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. |
LLM05:2025 |
| CVE-2026-17624 | — | High 8.5 | 0.7%top 49.5% | 05 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of module imports. |
LLM05:2025 |
| CVE-2026-17632 | — | High 8.8 | 0.7%top 50.3% | 05 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based security scanning. |
LLM05:2025 |
| CVE-2026-17633 | — | High 8.5 | 0.7%top 49.5% | 05 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection. |
LLM05:2025 |
| CVE-2026-8182 | — | High 8.8 | 0.7%top 50.5% | 05 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via 2 HTTP requests. |
LLM05:2025 |
| CVE-2026-8183 | — | High 7.7 | 0.6%top 55.3% | 05 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to v i ew arbitrary files on the system. |
|
| CVE-2026-8470 | — | High 7.4 | 0.2%top 92.2% | 05 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic Mersenne Twister PRNG produces identical keys for identical seeds, allowing attackers to reproduce encryption keys and decrypt stored API keys and… |
|
| CVE-2026-8478 | — | High 8.8 | 0.6%top 51.5% | 05 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code. |
LLM05:2025 |
| CVE-2026-9130 | — | High 7.1 | 0.3%top 79.7% | 05 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users via session_id collision. The MemoryComponent.retrieve_messages and store_message methods filter on session_id without validating flow_id or user_id ownership, enabling cross-user information disclosure through multiple… |
LLM02:2025 |
| CVE-2026-9201 | — | High 8.8 | 0.4%top 70.9% | 05 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component validation mechanism. When the optional hardening mode that restricts execution to trusted component templates is enabled, the application validates component code using a truncated SHA‑256 hash. Because the hash comparison relies on only a… |
LLM05:2025 |
| CVE-2026-9205 | — | High 7.4 | 0.4%top 66.2% | 05 Aug 2026 | IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function. |
|
| CVE-2026-71211 | — | High 7.1 | 0.3%top 80.4% | 05 Aug 2026 | MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value is stored verbatim. The gateway proxy endpoint (mlflow/server/gateway_api.py, raw_proxy) subsequently issues an HTTP request to that stored api_base plus a caller-supplied path and returns the full… |
|
| CVE-2026-7646 | — | Medium 6.5 | 0.5%top 62.9% | 05 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other users' uploaded documents, the JWT signing secret, the SQLite database, and process environment variables, by sending a crafted MCP `resources/read` request with a URL-encoded path traversal sequence in the filename. |
LLM05:2025 |
| CVE-2026-10128 | — | Medium 6.5 | 0.4%top 70.4% | 05 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbitrary server environment variables, exposing sensitive secrets despite security controls intended to disable custom components. |
|
| CVE-2026-7657 | — | Medium 6.5 | 0.4%top 70.8% | 05 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and ineffective SSRF protection enforcement. |
LLM05:2025 |
| CVE-2026-10547 | — | Medium 5.9 | 0.4%top 67.6% | 05 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing an authenticated user to inject arbitrary graph data into a shared cache for any flow. This may result in cross-user cache pollution, unauthorized workflow execution, or denial of service. |
LLM10:2025 |
| CVE-2026-7658 | — | Medium 6.5 | 0.5%top 58.7% | 05 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass containment checks. This enables multiple severe impacts, including arbitrary directory deletion, cross-tenant data destruction, and JWT signing key deletion leading to session invalidation. |
LLM05:2025 |
| CVE-2026-7869 | — | Medium 5.4 | 0.3%top 77.4% | 05 Aug 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledge_bases`). This occurs because user-supplied knowledge base names are used directly to create file paths without proper sanitization or containment checks. An authenticated attacker can exploit this flaw to create directories and write files anywhere on the server's filesystem. |
LLM05:2025 |
| CVE-2026-70477 | — | Critical 9.8 | 0.8%top 44.5% | 04 Aug 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses the blocklist validator and executes in an unsandboxed Pyodide environment. The specific flaw exists within the run method of the CSV_Agents class, where… |
LLM01:2025LLM05:2025 |
| CVE-2026-69258 | — | Critical 9.1 | 0.7%top 49.9% | 04 Aug 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overrideConfig object and unconditionally spread it into internal flowConfig and flowData objects in packages/server/src/utils/buildChatflow.ts and packages/server/src/utils/index.ts without checking apiOverrideStatus. This… |
|
| CVE-2026-69263 | — | Critical 9.8 | 0.7%top 50.1% | 04 Aug 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes flags on npx, but packages/components/nodes/tools/MCP/core.ts denied only PATH, LD_LIBRARY_PATH, DYLD_LIBRARY_PATH, and NODE_OPTIONS by exact environment-variable name. Because npm reads configuration from npm_config_* variables, setting… |
|
| CVE-2026-70470 | — | Critical 9.8 | 1.0%top 39.3% | 04 Aug 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validatePythonCodeForDataFrame in packages/components/src/pythonCodeValidator.ts can be bypassed with Unicode homoglyph identifiers, allowing arbitrary Python execution inside Pyodide and full OS command execution on the Flowise host via Pyodide js module interop. The validator gates… |
|
| CVE-2026-70478 | — | Critical 10.0 | 0.6%top 52.4% | 04 Aug 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is included in WHITELIST_URLS and requires no authentication. The endpoint decrypts the stored credential, sends a refresh request to the configured OAuth provider with the client secret and refresh token, and returns the… |
|
| CVE-2026-69255 | — | High 8.8 | 0.7%top 47.9% | 04 Aug 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-controlled CSV data with file.split(',').pop() and interpolated it directly into executable Python as base64_string = "${base64String}" before calling Pyodide. The validatePythonCodeForDataFrame() denylist… |
|
| CVE-2026-69250 | — | High 7.5 | 0.6%top 54.6% | 04 Aug 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token refresh endpoint POST /api/v1/oauth2-credential/refresh/:credentialId is unauthenticated by design and performs a server-side HTTP request to the credential-controlled accessTokenUrl without SSRF protections. Runtime validation confirmed that the endpoint was reachable without… |
LLM05:2025 |
| CVE-2026-69251 | — | High 8.8 | 2.7%top 14.3% | 04 Aug 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record manager and agent memory nodes allowed users to set arbitrary TypeORM DataSource options through the additionalConfig input in packages/components/nodes/recordmanager/MySQLRecordManager/MySQLrecordManager.ts,… |
LLM05:2025 |
| CVE-2026-69252 | — | High 8.8 | 0.5%top 56.3% | 04 Aug 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/files route was protected only by the feat:files feature gate and did not enforce checkPermission on GET or DELETE. A low-privileged authenticated API key with unrelated permissions could call GET /api/v1/files to list files under the organization storage root and DELETE… |
|
| CVE-2026-69253 | — | High 8.8 | 0.7%top 50.0% | 04 Aug 2026 | Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several custom-tool components — AgentAsTool, ChatflowTool, and ExecuteFlow — ran code in the in-process vm2 sandbox. To build that code, they inserted a user-controlled baseURL value straight into the JavaScript source, for example const url = "${baseURL}/..."; . The… |
LLM05:2025 |
| CVE-2026-69254 | — | High 8.8 | 0.7%top 48.9% | 04 Aug 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriptCode() accepted caller-provided nodeVMOptions and merged them over the default NodeVM security settings in packages/components/src/utils.ts. An authenticated attacker reaching packages/server/src/routes/node-custom-functions/index.ts could run a custom function that imported… |
|
| CVE-2026-69256 | — | High 8.8 | 1.0%top 38.1% | 04 Aug 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is executed through pyodide; although a denylist blocked dangerous Python constructs, pandas.read_pickle() could deserialize a pickled payload and achieve code execution without matching the denied words. The affected file is… |
LLM05:2025 |
| CVE-2026-69257 | — | High 8.6 | 0.4%top 65.2% | 04 Aug 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IPv4-mapped IPv6 addresses such as ::ffff:127.0.0.1 and ::ffff:169.254.169.254 before checking them against the deny list. Because ipaddr.js reports these addresses as ipv6 while IPv4 CIDR deny-list entries are ipv4, isDeniedIP()… |
|
| CVE-2026-69259 | — | High 8.8 | 0.8%top 44.2% | 04 Aug 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts accepted user-controlled additionalConfig and spread it after the intended database setting, allowing additionalConfig.database to overwrite the SQLite database path. An… |
|
| CVE-2026-69262 | — | High 8.1 | 0.5%top 57.5% | 04 Aug 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with checkAnyPermission('chatflows:delete,agentflows:delete'), so possession of either permission was sufficient to reach the delete path. The delete logic then resolved the target record only by id and workspaceId and did not validate the… |
|
| CVE-2026-70472 | — | High 8.8 | 0.5%top 58.2% | 04 Aug 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a client-controlled credential parameter and load credentials by id without checking whether that credential belongs to the caller workspace. Route permissions assistants:* only check feature access. The controller passes… |
|
| CVE-2026-70473 | — | High 8.5 | 0.5%top 63.0% | 04 Aug 2026 | Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requesting user, tenant, or workspace. The response can exceed 100MB and includes sensitive configuration data, including Vector Store settings such as Qdrant Server URL… |
|
| CVE-2026-70474 | — | High 8.1 | 0.5%top 61.0% | 04 Aug 2026 | Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credential endpoints that look up credentials by id alone with no workspaceId filter. The authorize, callback, and refresh handlers query the Credential table by id only; callback and refresh are whitelisted from authentication. This allows any authenticated… |
|
| CVE-2026-70476 | — | High 8.2 | 0.5%top 58.0% | 04 Aug 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterprise/controllers/organization.controller.ts accept attacker-controlled Stripe subscriptionId values without verifying that the identifier belongs to the… |
|
| CVE-2026-70471 | — | Medium 6.5 | 0.4%top 66.8% | 04 Aug 2026 | Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the code execution sandbox without requiring variables:view, bypassing the permission-protected Variables API. Variables for the active workspace are fetched at packages/components/src/utils.ts and runtime variables are resolved from server environment… |
LLM05:2025 |
| CVE-2026-70475 | — | Medium 6.5 | 0.5%top 62.5% | 04 Aug 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in packages/server/src/routes/executions/index.ts lacks the checkAnyPermission() middleware that protects other execution endpoints. Any authenticated user, regardless of assigned permissions, can modify execution state, data, and metadata of any… |
LLM06:2025 |
| CVE-2026-47487 | — | Medium 4.4 | 0.2%top 86.9% | 04 Aug 2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to, or modified by providing a path in the model name to the Triton MLflow plugin. A successful exploit of this vulnerability might lead to denial of service and information disclosure. |
LLM02:2025LLM10:2025 |
| CVE-2026-67598 | — | High 7.4 | 0.3%top 84.0% | 03 Aug 2026 | Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configured LLM providers by presenting arbitrary TLS certificates, as CURLOPT_SSL_VERIFYPEER and CURLOPT_SSL_VERIFYHOST are unconditionally disabled across sendStream(), sendImageRequest(), send(), and… |
|
| CVE-2026-18733 | — | High 8.8 | 0.6%top 54.6% | 03 Aug 2026 | A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands on the agent's host via a crafted prompt that sets the non_interactive parameter to true, bypassing the human consent gate.
To remediate this issue, users should upgrade to version 0.8.0. |
LLM01:2025 |
| CVE-2026-18655 | — | Medium 6.5 | 0.4%top 65.6% | 03 Aug 2026 | Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated actor (via prompt injection) to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted endpoint controlled through a broker hostname introduced in the MCP client… |
LLM01:2025 |
| CVE-2026-66065 | — | Unscored | 0.2%top 86.2% | 03 Aug 2026 | Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. Versions prior to 0.42.1 have an incomplete denylist. Several execution-routing keys of the same RCE class were omitted, so a malicious cloned repo can still reach arbitrary command execution by shipping a .env (auto-loaded at import, with no review step).… |
LLM05:2025 |
| CVE-2026-17351 | — | Critical 9.0 | 0.5%top 60.5% | 31 Jul 2026 | The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION READ ONLY wrapper. sqlparse's string-literal lexing can disagree with PostgreSQL's own parser: under standard_conforming_strings = on (PostgreSQL's… |
|
| CVE-2026-68771 | — | Critical 9.8 | 1.1%top 34.3% | 31 Jul 2026 | ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. Attackers can upload a malicious shard_*.pkl file via the unauthenticated POST /upload/image endpoint and then queue a workflow graph via POST /prompt… |
LLM05:2025 |
| CVE-2026-18394 | — | High 7.4 | 0.5%top 57.8% | 31 Jul 2026 | Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via HTTP_REQUEST_TOKEN_CONFIG by influencing the LLM to route requests through actor-controlled proxy infrastructure.
To remediate this issue, users should upgrade to version 0.8.2. |
|
| CVE-2026-56670 | — | High 8.2 | 0.4%top 68.5% | 31 Jul 2026 | ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint served uploaded SVG files inline because image/svg+xml and related XML content types were absent from the dangerous-content-type handling, allowing stored cross-site scripting in the ComfyUI origin. This issue is fixed in version 0.28.0. |
LLM05:2025 |
| CVE-2026-56671 | — | High 7.5 | 1.0%top 39.4% | 31 Jul 2026 | ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_preview in app/model_manager.py joins an unrestricted filename route capture to a selected model directory without a containment check, allowing an unauthenticated remote attacker to use traversal, encoded traversal, absolute paths, or an unbounded path_index to read image-decodable… |
|
| CVE-2026-56672 | — | High 8.2 | 0.4%top 68.5% | 31 Jul 2026 | ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and access to browser-stored API tokens, settings, workflows, and authenticated-equivalent API calls. The handler used web.FileResponse(path), so an uploaded… |
LLM05:2025 |
| CVE-2026-56673 | — | High 7.5 | 0.6%top 51.5% | 31 Jul 2026 | ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_paths.get_annotated_filepath and exists_annotated_filepath join workflow-controlled annotated filenames to a base directory without a containment check, allowing an unauthenticated crafted POST /prompt workflow using LoadImage or sibling nodes to probe arbitrary host paths and… |
|
| CVE-2026-54785 | — | Medium 6.2 | 0.2%top 92.1% | 31 Jul 2026 | gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 until 1.3.1, consult_gemini_with_files in inline mode read any file path supplied in the files argument without confining it to the working directory, then forwarded the contents to the Gemini CLI. Because the caller also controls query, the file contents are echoed back through the… |
|
| CVE-2026-12940 | — | Critical 9.8 | 0.9%top 40.3% | 30 Jul 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py where the DANGEROUS_ENV_VARS blocklist fails to include SHELLOPTS , BASHOPTS , and PS4 environment variables. |
LLM05:2025 |
| CVE-2026-13435 | — | Critical 9.9 | 0.5%top 57.2% | 30 Jul 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation. |
|
| CVE-2026-12946 | — | Critical 9.9 | 0.6%top 51.5% | 30 Jul 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code. |
LLM05:2025 |
| CVE-2026-62663 | — | High 7.5 | 0.5%top 59.2% | 30 Jul 2026 | Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filters (image, audio, video, document) in banks accept untrusted user input as file paths via Path(value) and pass them directly to open(file_path, "rb") without any path sanitization, canonicalization, or directory restriction. An attacker who controls template variables passed to… |
LLM05:2025 |
| CVE-2026-61536 | — | High 7.5 | 0.5%top 58.7% | 30 Jul 2026 | Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered body of {% completion %} blocks and later resolves their import_path field through importlib.import_module(...) + getattr(...) to obtain the callable that handles a tool call. There is no allowlist or sanitization on import_path, so any importable… |
LLM05:2025 |
| CVE-2026-12945 | — | High 7.1 | 0.4%top 72.1% | 30 Jul 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on log retrieval and unauthenticated build endpoints. |
|
| CVE-2026-12942 | — | High 7.5 | 0.6%top 52.0% | 30 Jul 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system. |
|
| CVE-2026-13444 | — | High 8.1 | 0.4%top 73.7% | 30 Jul 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creating their own flow with matching Chroma persist_directory and collection_name values. The attacker receives exact victim content in their workflow output despite having no authorization to read the victim's flow. Additionally, the attacker can pollute the victim's collection by… |
|
| CVE-2026-10700 | — | Medium 6.5 | 0.5%top 56.5% | 30 Jul 2026 | IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API that allow unauthorized access to user files.The /api/v1/files/images/{flow_id}/{file_name} endpoint does not enforce authentication or authorization checks, allowing unauthenticated remote attackers to retrieve image files associated with any flow by specifying a valid flow_id… |
|
| CVE-2026-67425 | — | High 8.6 | 0.6%top 55.6% | 29 Jul 2026 | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as OPENAI_API_KEY and ANTHROPIC_API_KEY from the environment and sends them in the Authorization: Bearer header to caller-controlled base_url, allowing an attacker to receive the operator's key on a public host that passes the SSRF guard. This issue is fixed in version… |
LLM05:2025 |
| CVE-2026-67428 | — | High 8.5 | 0.4%top 63.3% | 29 Jul 2026 | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules including src/core/modules/third_party/developer/http/requests.py, core.api.http_get, core.api.http_post, graphql.query, graphql.mutation, monitor.http_check, communication.slack_send, notification.discord.send_message, notification.slack.send_message, notification.teams.send_message,… |
LLM05:2025 |
| CVE-2026-67432 | — | High 7.5 | 0.8%top 45.5% | 29 Jul 2026 | MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem reads and parses an entire JSON-RPC POST body without a size limit, allowing an unauthenticated remote attacker to exhaust process memory. This issue is fixed in version 0.23.0. |
|
| CVE-2026-63119 | — | Medium 6.2 | 0.2%top 92.8% | 29 Jul 2026 | MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StdioTransport and MCP::Client::Stdio in the mcp gem use IO#gets without a byte limit, allowing a peer that sends data without a newline to exhaust process memory. This issue is fixed in version 0.23.0. |
|
| CVE-2026-67430 | — | Medium 5.3 | 0.5%top 58.9% | 29 Jul 2026 | MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem does not expire sessions by default, so repeated initialize requests retain unbounded ServerSession objects and can exhaust process memory. This issue is fixed in version 0.23.0. |
|
| CVE-2026-46678 | — | Medium 6.8 | 0.4%top 70.3% | 29 Jul 2026 | Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.56.0 through 1.98.0, when an application opts a URL into force_download='allow-local' (disabling the default block on private/internal IPs), the cloud-metadata blocklist could be bypassed by encoding the metadata IP in an IPv6 transition form (IPv4-mapped IPv6, 6to4, or NAT64), exposing cloud IAM… |
|
| CVE-2026-54249 | — | Medium 6.8 | 0.3%top 77.8% | 29 Jul 2026 | Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and 2.0.0b1 through 2.0.0b5, a client that submits message history to a Pydantic AI UI adapter (such as the Vercel AI adapter) can reference arbitrary files in the application's model-provider or cloud-storage account. While file URL parts are validated against a scheme allowlist,… |
|
| CVE-2026-65975 | — | Medium 6.5 | 0.3%top 76.2% | 29 Jul 2026 | Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.88.0 up to but not including 1.107.1 and 2.0.0b1 up to but not including 2.5.0, the UI adapters (AG-UI via Agent.to_ag_ui()/AGUIAdapter, and Vercel AI via VercelAIAdapter) use sanitize_messages to strip unresolved ("dangling") client-submitted tool calls from untrusted message history… |
|
| CVE-2026-63118 | — | Unscored | 0.3%top 84.3% | 29 Jul 2026 | MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem does not validate the HTTP Host or Origin request headers, which allows a malicious browser page to use DNS rebinding to reach a locally running MCP server and invoke exposed tools. This issue is fixed in version 0.23.0. |
|
| CVE-2026-67431 | — | Unscored | 0.5%top 60.8% | 29 Jul 2026 | MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem does not bind a session ID to a session owner, allowing an attacker with a stolen session ID to send tools/call requests that execute in the victim's session. This issue is fixed in version 0.23.0. |
|
| CVE-2026-13442 | — | High 7.1 | 0.3%top 79.9% | 28 Jul 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence later query results. This causes cross-user information disclosure and limited integrity impact through persistent poisoning of returned results. |
LLM02:2025 |
| CVE-2026-17534 | — | Medium 5.5 | 0.2%top 95.6% | 27 Jul 2026 | Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal denylist in assertSafeFetchTarget, without resolving DNS or re-validating hosts after HTTP redirects. An attacker who can influence a FetchURL call (for example via prompt injection) can supply a crafted public hostname that resolves to loopback or another internal address, or a… |
LLM01:2025LLM05:2025 |
| CVE-2026-66027 | — | High 8.3 | 0.5%top 62.7% | 24 Jul 2026 | Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation checks. Attackers can read pending prompt queues of all users, read or delete individual sessions, and inject arbitrary prompts into another user's… |
|
| CVE-2026-66004 | — | Medium 5.3 | 0.4%top 65.6% | 24 Jul 2026 | BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that allows attackers to write arbitrary files by injecting traversal sequences in API response include keys. Attackers performing MITM attacks or prompt injection can supply malicious paths like '../../.bashrc' to overwrite sensitive files and achieve persistent code execution. |
LLM01:2025LLM05:2025 |
| CVE-2026-65699 | — | Medium 4.2 | 0.3%top 81.8% | 23 Jul 2026 | AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent run by supplying a target run_id in the request body without ownership verification. The AgentCRUD.create_task and validate_task_count functions look up the target AgentRun using the client-supplied run_id without confirming the… |
|
| CVE-2026-65698 | — | Medium 5.3 | 0.5%top 61.5% | 23 Jul 2026 | Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjacent attackers to read arbitrary host files outside the open workspace by injecting instructions into content the agent processes. Attackers can supply absolute paths or file:// URIs through the read_file, ls_dir, get_dir_tree, and search_* tools, which lack workspace confinement… |
LLM05:2025 |
| CVE-2026-65015 | — | High 8.8 | 0.6%top 52.7% | 22 Jul 2026 | n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project Viewer user can escalate privileges by chatting with an agent that has node tools enabled, executing arbitrary nodes and accessing credential secrets without proper authorization verification. |
LLM06:2025 |
| CVE-2026-65589 | — | Medium 6.5 | 0.5%top 60.5% | 22 Jul 2026 | n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can read exposed header values and credentials that persist in the database and can be exported. |
|
| CVE-2026-44192 | — | Medium 6.6 | 0.2%top 91.3% | 22 Jul 2026 | A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This vulnerability, known as path traversal, allows an attacker to manipulate an AI agent through indirect prompt injection. By doing so, the attacker can cause the server to write files to unauthorized locations on the user's system. This can result in the exposure of sensitive host information and enable the… |
LLM01:2025LLM05:2025 |
| CVE-2026-47391 | — | Critical 9.8 | 1.2%top 33.8% | 21 Jul 2026 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an unauthenticated A2A JSON-RPC endpoint and registers a `calculate(expression)` tool implemented with Python `eval()`. The example also binds to `0.0.0.0`. A remote unauthenticated attacker can send `message/send` to `/a2a`; the request reaches `agent.chat()`, and a real LLM can… |
|
| CVE-2026-47393 | — | Critical 9.8 | 0.8%top 45.6% | 21 Jul 2026 | PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-generator (`praisonai.deploy.api.generate_api_server_code`) that emits a Flask API server with authentication disabled by default. Users who follow the documented quickstart (`praisonai deploy --type api`) get a server that binds to `0.0.0.0` per the recommended sample YAML, exposes… |
|
| CVE-2026-65056 | — | High 8.2 | 0.4%top 67.2% | 21 Jul 2026 | mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to the visit_page tool, which only validates the URL protocol without filtering private or reserved IP ranges. Attackers can steer the LLM-controlled URL argument through prompt injection to navigate the… |
LLM01:2025LLM05:2025 |
| CVE-2026-65315 | — | High 7.5 | 0.8%top 44.6% | 21 Jul 2026 | Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows remote attackers to crash the server by supplying a crafted GGUF file with attacker-controlled length and count fields in string lengths, tensor dimension counts, and metadata array counts that are used as allocation sizes without validation against remaining file size. Attackers… |
|
| CVE-2026-46555 | — | High 7.7 | 0.2%top 90.2% | 20 Jul 2026 | WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1, the `whatsapp-bridge` HTTP API listens on `127.0.0.1:8080` without authentication and without Host header validation, and the `/api/send` endpoint accepts an absolute `media_path` parameter without confining it to a safe directory. Combined, these… |
LLM05:2025 |
| CVE-2026-47255 | — | High 8.2 | 0.3%top 84.9% | 20 Jul 2026 | AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and binding of inactive-agent hour filtering; storage SQL identifier validation; metadata-backed ownership checks for raw storage SQL; blocking direct storage metadata access through raw SQL; fail-closed… |
|
| CVE-2026-47128 | — | Medium 6.1 | 0.1%top 97.8% | 20 Jul 2026 | nono is software that allows users to run AI agents in a zero-latency sandbox. Prior to version 0.55.0, the nono Landlock/seccomp policies allow access to local Unix domain sockets (concrete and abstract). This allows an easy sandbox escape by talking to the per-user systemd dbus socket. Version 0.55.0 patches the issue. |
LLM06:2025 |
| CVE-2026-57495 | — | Unscored | 0.4%top 72.2% | 20 Jul 2026 | AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39, @agenticmail/codex prior to version 0.1.33, @agenticmail/core prior to version 0.9.43, and @agenticmail/openclaw prior to version 0.5.71, two inbound-mail handlers act on a privileged effect without verifying that the sender is the operator, while a sibling handler in the same… |
LLM01:2025 |
| CVE-2026-57494 | — | Unscored | 0.4%top 71.2% | 20 Jul 2026 | AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-privileged authenticated AgenticMail agent can enumerate another agent's pending/claimed tasks by supplying the target agent name to `GET /api/agenticmail/tasks/pending?assignee=<name>`. The returned task objects include the task IDs and payloads. The same task IDs can then be… |
|
| CVE-2026-9202 | — | Critical 9.8 | 0.5%top 59.2% | 17 Jul 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deployment option), newly created accounts are immediately active and can authenticate to reach RCE endpoints, bypassing the need for AUTO_LOGIN. |
|
| CVE-2026-9103 | — | Critical 9.8 | 3.2%top 12.3% | 17 Jul 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived superuser bearer tokens without requiring authentication when the AUTO_LOGIN configuration is enabled (enabled by default), which may allow an unauthenticated network attacker to obtain full… |
|
| CVE-2026-9135 | — | Critical 9.9 | 0.8%top 43.6% | 17 Jul 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that bypasses the allow_custom_components=false security control. The vulnerability exists because the validation mechanism only checks the main component source code in… |
LLM05:2025 |
| CVE-2026-8476 | — | Critical 9.9 | 1.0%top 39.2% | 17 Jul 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() function to deserialize cached objects from disk without validation, integrity verification, or authentication, enabling arbitrary code execution when malicious pickle payloads are processed. Attackers who… |
LLM05:2025 |
| CVE-2026-8481 | — | Critical 9.9 | 0.9%top 42.4% | 17 Jul 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied Python code and executes it directly using Python's built-in exec() function without sandboxing, input validation, or privilege restrictions, enabling any authenticated user to execute arbitrary system… |
LLM05:2025 |
| CVE-2026-8505 | — | Critical 9.8 | 1.0%top 37.2% | 17 Jul 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the WEBHOOK_AUTH_ENABLE configuration is set to False (which is the default setting). This allows a remote attacker who knows a flow's UUID to execute it as if they were the… |
LLM05:2025 |
| CVE-2026-8635 | — | Critical 9.9 | 0.5%top 57.2% | 17 Jul 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with Langflow service permissions. |
|
| CVE-2026-8859 | — | Critical 9.9 | 0.6%top 55.4% | 17 Jul 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the APIRequest component. A path traversal vulnerability exists when the "Save to File" feature is enabled, where filenames extracted from HTTP response Content-Disposition headers are not sanitized before being joined to the temporary… |
LLM05:2025 |
| CVE-2026-13446 | — | Critical 9.8 | 0.4%top 70.2% | 17 Jul 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. |
|
| CVE-2026-58195 | — | High 8.8 | 0.9%top 42.7% | 17 Jul 2026 | Agentic-Flow is an AI agent orchestration platform. Prior to 2.0.14, agentic-flow MCP server tools in src/mcp/standalone-stdio.ts, src/mcp/fastmcp/servers/claude-flow-sdk.ts, src/mcp/fastmcp/servers/stdio-full.ts, src/mcp/fastmcp/servers/http-streaming-updated.ts, src/mcp/fastmcp/servers/http-sse.ts, src/mcp/fastmcp/servers/poc-stdio.ts, src/mcp/fastmcp/tools/agent/{execute,list,parallel}.ts,… |
|
| CVE-2026-13448 | — | High 8.1 | 0.7%top 49.9% | 17 Jul 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint ( /api/v1/build_public_tmp/{flow_id}/flow ). The vulnerability stems from an incomplete denylist in the validate_public_flow_no_code_execution() function that fails to block several code-execution agent components including OpenDsStarAgent,… |
LLM05:2025 |
| CVE-2026-14499 | — | High 8.8 | 0.7%top 49.9% | 17 Jul 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input in the Python Interpreter component. |
LLM05:2025 |
| CVE-2026-7667 | — | High 8.8 | 0.6%top 55.4% | 17 Jul 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns a specially crafted Content-Disposition header (e.g., filename="../../../target/path" ), enabling arbitrary file write operations with attacker-controlled content to any path accessible by the Langflow process. |
|
| CVE-2026-7754 | — | High 7.7 | 0.3%top 74.8% | 17 Jul 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure default configuration and incomplete enforcement of the SSRF protection mechanism. |
LLM05:2025 |
| CVE-2026-7755 | — | High 8.8 | 0.7%top 46.8% | 17 Jul 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration files. |
LLM05:2025 |
| CVE-2026-7872 | — | High 7.5 | 0.6%top 55.0% | 17 Jul 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any user. |
|
| CVE-2026-8056 | — | High 8.8 | 0.5%top 57.2% | 17 Jul 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API. A critical security flaw exists in the parameter filtering mechanism within the `apply_tweaks()` function. |
|
| CVE-2026-13445 | — | High 8.1 | 0.4%top 73.7% | 17 Jul 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploaded files by specifying absolute paths pointing to victim storage locations. In append mode, the attacker's workflow reads victim file contents, appends attacker-controlled data, and uploads a copy containing victim data to the attacker's namespace… |
|
| CVE-2026-15995 | — | Medium 5.4 | 0.2%top 94.6% | 17 Jul 2026 | IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an attacker to obtain incorrect report summary results or cause report-processing failures due to a race condition in the Agentic AI assistant's concurrent request-handling logic when multiple authenticated users submit report-related tasks simultaneously. |
|
| CVE-2026-53598 | — | High 7.5 | 1.3%top 30.9% | 16 Jul 2026 | Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:...} references in .prompty frontmatter without enforcing that resolved paths stayed within the prompt directory or allowed roots, allowing an attacker-controlled prompt file to read local files through absolute paths, .. traversal, or symlink escapes. This issue is fixed in… |
|
| CVE-2026-46341 | — | Medium 6.1 | 0.3%top 75.1% | 16 Jul 2026 | The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior to 0.9.21, the fetch-apify-docs tool in src/tools/common/fetch_apify_docs.ts validates allowlisted documentation domains with String.startsWith() rather than URL hostname comparison, allowing attacker-controlled URLs such as… |
|
| CVE-2026-11371 | — | Medium 6.1 | 0.3%top 81.9% | 16 Jul 2026 | The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and outputting it, and the feature that generates it is exposed to unauthenticated users, allowing them to store a malicious payload via prompt injection that executes in the browser of any visitor who views the affected page, including administrators. |
LLM01:2025 |
| CVE-2026-44968 | — | Medium 6.3 | 0.2%top 90.4% | 16 Jul 2026 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, _run_dbt_command() in src/dbt_mcp/dbt_cli/tools.py appended unsanitized node_selection and resource_type values to the dbt subprocess argument list, allowing an MCP client to inject dbt global flags such as --profiles-dir, --project-dir, and --target into subprocess.Popen even though shell=False prevents shell… |
|
| CVE-2026-15737 | — | Medium 5.7 | 0.4%top 70.1% | 16 Jul 2026 | AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore platform.
Unintended logging of sensitive user content in the OpenTelemetry instrumentation in AWS Bedrock AgentCore Python SDK versions 1.4.8 and 1.5.0 might allow a local authenticated user with access to CloudWatch Logs to access raw user… |
|
| CVE-2026-44969 | — | Low 2.5 | 0.2%top 94.9% | 16 Jul 2026 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/mcp/server.py logged the raw arguments dictionary at INFO level before each tool call and at ERROR level on exceptions, and configure_file_logging() wrote those records to dbt-mcp.log when DBT_MCP_SERVER_FILE_LOGGING=true, preserving sensitive sql_query, vars, and node_selection… |
|
| CVE-2026-44970 | — | Low 3.1 | 0.4%top 71.1% | 16 Jul 2026 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DefaultUsageTracker.emit_tool_called_event() in src/dbt_mcp/tracking/tracking.py serialized every MCP tool call's complete arguments dictionary and sent it through dbtlabs_vortex.producer.log_proto without redaction, including sql_query from show, vars from run, build, and test, and node_selection from compile,… |
|
| CVE-2026-53597 | — | Unscored | 1.0%top 39.3% | 16 Jul 2026 | Prompty is a markdown file format (.prompty) for LLM prompts. From 2.0.0-alpha.1 until 2.0.0-beta.3, the @prompty/core TypeScript loader in runtime/typescript/packages/core/src/core/loader.ts used gray-matter without overriding executable js and javascript frontmatter engines, allowing an attacker-controlled .prompty file with ---js frontmatter to execute arbitrary JavaScript during prompt… |
|
| CVE-2026-52869 | — | High 7.1 | 0.5%top 56.9% | 15 Jul 2026 | The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp.server.sse.SseServerTransport and mcp.server.streamable_http_manager.StreamableHTTPSessionManager route requests to existing sessions using only the session_id query parameter or Mcp-Session-Id header without verifying the… |
|
| CVE-2026-52870 | — | High 7.6 | 0.4%top 69.4% | 15 Jul 2026 | The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/cancel operate only on task identifiers without recording the session that created each task, allowing any connected client to enumerate, read results… |
|
| CVE-2026-59950 | — | High 8.1 | 0.2%top 87.4% | 15 Jul 2026 | The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-level way to restrict which origins could connect to applications that exposed that transport. This issue is fixed in… |
|
| CVE-2026-15746 | — | Medium 6.5 | 0.4%top 65.6% | 15 Jul 2026 | Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the elasticsearch_memory tool for agent memory storage. We identified CVE-2026-15746, a server-side request forgery (SSRF) issue in the elasticsearch_memory tool. The tool exposed its connection parameters (es_url, cloud_id,… |
LLM05:2025 |
| CVE-2026-15643 | — | High 7.3 | 0.4%top 69.2% | 14 Jul 2026 | AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLake FHIR datastores. A server-side request forgery in the pagination handling component in AWS awslabs.healthlake-mcp-server before 0.0.14 on all platforms might allow a remote authenticated user to exfiltrate AWS temporary security credentials to an… |
LLM05:2025 |
| CVE-2026-15685 | — | High 7.5 | 0.7%top 47.9% | 13 Jul 2026 | Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the downloadBlob function. The issue results from the lack of proper validation of user-supplied… |
|
| CVE-2026-15574 | — | High 7.5 | 0.4%top 64.1% | 13 Jul 2026 | A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorization headers and full chat payloads, which may contain personally identifiable information (PII) and secrets, to persistent logs. This sensitive data, including bearer tokens and chat content, can be accessed by any user with logging privileges. This vulnerability leads to… |
LLM02:2025 |
| CVE-2026-56259 | — | High 8.2 | 0.4%top 64.6% | 12 Jul 2026 | Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to redirect LLM API calls to attacker-controlled endpoints and read arbitrary environment variables. Attackers can exploit the unauthenticated /md, /llm, and /llm/job endpoints by supplying a malicious base_url parameter and setting api_token to env:VARIABLE_NAME to exfiltrate… |
|
| CVE-2026-61445 | — | Critical 9.9 | 0.9%top 42.3% | 11 Jul 2026 | PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject malicious prompts through the chat interface to write files to arbitrary filesystem locations and execute arbitrary shell commands with root privileges. |
|
| CVE-2026-61447 | — | Critical 10.0 | 2.5%top 15.9% | 11 Jul 2026 | PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system. |
LLM01:2025LLM05:2025 |
| CVE-2026-61439 | — | High 7.5 | 0.4%top 64.7% | 11 Jul 2026 | PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked. Attackers can submit single-vector prompt injection attacks such as instruction overrides or financial manipulation that trigger HIGH severity detection but are logged without blocking, enabling system… |
LLM01:2025LLM06:2025 |
| CVE-2026-54769 | — | Critical 10.0 | 0.9%top 41.3% | 10 Jul 2026 | Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote Code Execution (RCE) in its `TableChatAgent` and `VectorStore` capabilities. When these agents evaluate LLM-generated tool messages with `full_eval=True`, they attempt to sandbox the execution by explicitly setting `locals` to an… |
LLM05:2025LLM06:2025 |
| CVE-2026-50181 | — | High 7.1 | 0.2%top 92.8% | 10 Jul 2026 | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, Langroid's `ReadFileTool` and `WriteFileTool` appear to treat `curr_dir` as the intended working-directory boundary for file operations. However, the tools only change the process working directory to `curr_dir` and then operate on the user-supplied `file_path` without resolving and enforcing… |
LLM05:2025 |
| CVE-2026-56676 | — | High 7.4 | 0.3%top 83.9% | 10 Jul 2026 | 9Router is an AI router & token saver. Prior to 0.5.2, 9router validates image URLs by resolving the host before fetching, but open-sse/translator/concerns/image.js performs the later server-side image fetch with a separate DNS resolution. An authenticated attacker with access to the LLM proxy can use a vision-capable model and an attacker-controlled DNS name that first resolves to a public IP… |
|
| CVE-2026-55638 | — | High 8.6 | 0.6%top 52.5% | 10 Jul 2026 | 9Router is an AI router & token saver. Prior to 0.5.2, 9router protects /v1, /v1beta, /api/v1, and /api/v1beta in src/dashboardGuard.js but omits /codex before next.config.mjs rewrites /codex/* to /api/v1/responses. A remote unauthenticated attacker can send requests to /codex/* to bypass the API-key gate and cause the server to make upstream provider calls using operator-stored LLM provider… |
|
| CVE-2026-55641 | — | High 8.2 | 0.3%top 76.9% | 10 Jul 2026 | 9Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by reading the client-controlled Host header, allowing a remote unauthenticated attacker to send Host: localhost and bypass API-key authentication. In the default configuration, this exposes the /v1 proxy to upstream provider calls using stored provider credentials and allows… |
|
| CVE-2026-55405 | — | High 7.6 | 0.5%top 61.2% | 10 Jul 2026 | LangChain4j is a Java library for building LLM-powered applications on the JVM. Prior to 1.2.1-beta8, 1.5.1-beta11, 1.11.8-beta19, and 1.16.3-beta26, the MariaDB and pgvector embedding stores build metadata-filter SQL by string-concatenating filter keys, and in MariaDB string values, directly into the query without adequate escaping. A crafted metadata key in EmbeddingSearchRequest.filter() can… |
LLM10:2025 |
| CVE-2026-60086 | — | Medium 5.3 | 0.4%top 72.5% | 10 Jul 2026 | PraisonAI before 4.6.78 contains a prompt injection defense bypass vulnerability where the injection defense only blocks threats classified as CRITICAL, requiring three or more detector families to match simultaneously. Attackers can craft single or double-vector prompt injections that are classified as HIGH threat level and pass through unblocked to reach the model. |
LLM01:2025 |
| CVE-2026-13236 | — | Medium 4.2 | 0.2%top 92.4% | 10 Jul 2026 | Missing Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1. |
|
| CVE-2026-13237 | — | Medium 4.8 | 0.2%top 89.0% | 10 Jul 2026 | Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1. |
|
| CVE-2026-50180 | — | Unscored | 0.7%top 49.0% | 10 Jul 2026 | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, `SQLChatAgent` in `langroid` ships a `_validate_query` defense-in-depth layer whose `_DANGEROUS_SQL_PATTERNS` regex blocklist enumerates dangerous SQL primitives by specific function name. The list misses the canonical PostgreSQL filesystem-disclosure family `pg_read_file()`, `pg_stat_file()`,… |
|
| CVE-2026-55615 | — | Unscored | 0.5%top 62.2% | 10 Jul 2026 | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.5, Neo4jChatAgent passes LLM-generated Cypher queries straight to the Neo4j driver with no validation, no statement-type allowlist, and no opt-out gate. The query text is influenceable by prompt injection (direct user input or indirect content the agent reads back via RAG), so an attacker who can… |
LLM01:2025 |
| CVE-2026-58122 | — | Critical 9.1 | 0.4%top 71.1% | 09 Jul 2026 | Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a spoofed X-Forwarded-For header with a loopback address. Attackers can exploit this bypass to perform server-side request forgery against internal services including cloud metadata endpoints,… |
LLM05:2025 |
| CVE-2026-43752 | — | Medium 4.9 | 0.5%top 60.0% | 09 Jul 2026 | An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMaker Server 26.0.1. |
LLM05:2025 |
| CVE-2026-59207 | — | Medium 6.5 | 0.4%top 63.3% | 09 Jul 2026 | n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not enforce the Allowed HTTP Request Domains restriction configured on credentials when an MCP tool was pointed at an arbitrary URL, allowing a member-level user with use-only access to a shared credential to send its secret to an external server they control. This issue is fixed in versions… |
|
| CVE-2026-59821 | — | High 7.2 | 0.9%top 41.6% | 08 Jul 2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's Custom Code Guardrails production create and update paths did not apply the same sandboxing and validation used by the test endpoint, allowing a privileged user with access to create or update guardrails to submit custom Python code that executed in the LiteLLM proxy environment… |
|
| CVE-2026-15154 | — | Medium 6.5 | 0.5%top 61.1% | 08 Jul 2026 | A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (ReDoS), allows a remote attacker to provide specially crafted regular expressions to the public detection API. This can cause catastrophic backtracking, leading to a worker process consuming 100% CPU indefinitely and resulting in a denial of service… |
LLM10:2025 |
| CVE-2026-59819 | — | Medium 4.9 | 0.6%top 54.6% | 08 Jul 2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's /health/test_connection endpoint resolved request-supplied environment and OIDC file references in litellm_params, allowing a proxy administrator or another privileged caller with permission to test model connections to read files from the local filesystem via an oidc/file/… |
|
| CVE-2026-59820 | — | Medium 6.5 | 0.6%top 53.8% | 08 Jul 2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives, allowing an authenticated user with access to LiteLLM LLM API routes or a key whose allowed_routes includes /v1/skills, anthropic_routes, or llm_api_routes to upload a crafted… |
LLM05:2025 |
| CVE-2026-59807 | — | Medium 6.8 | 0.5%top 61.8% | 08 Jul 2026 | Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and exfiltrate sensitive files by exploiting a missing assertSafeFileUploadPath check in the readFileFromDisk function within tool-file-uploads.ts. Attackers can exploit prompt injection to manipulate file_uploadable parameters to reference sensitive paths such as SSH private keys,… |
LLM01:2025 |
| CVE-2026-58473 | — | Critical 9.1 | 0.5%top 58.5% | 07 Jul 2026 | Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite the global LLM provider configuration by self-registering an account and calling the settings endpoint, which performs no admin or superuser check. Attackers can redirect all LLM operations instance-wide to an attacker-controlled endpoint by exploiting the process-wide… |
|
| CVE-2026-59706 | — | Critical 9.3 | 0.4%top 63.8% | 07 Jul 2026 | mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request forgery via attacker-controlled ollama_base_url parameter. Unauthenticated attackers can retrieve stored secrets like OpenAI API keys via GET /api/v1/config/ or trigger SSRF attacks by setting ollama_base_url to internal addresses like cloud IMDS via PUT /api/v1/config/mem0/llm… |
LLM05:2025 |
| CVE-2026-54602 | — | Unscored | 0.4%top 72.0% | 07 Jul 2026 | FastGPT is a knowledge-based AI application platform. Prior to 4.15.0, GET /api/core/ai/record/getRecord authenticates the caller but loads LLM request and response traces only by requestId without team scoping, allowing any authenticated user to read another team's prompts, retrieved RAG chunks, and completions if the requestId is known. This issue is fixed in version 4.15.0. |
|
| CVE-2026-57571 | — | Critical 9.6 | 0.8%top 44.6% | 06 Jul 2026 | Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename was taken from attacker-influenced input and joined to the downloads directory with no confinement. A filename containing an absolute path or traversal escaped the downloads directory, giving an arbitrary file write with attacker-controlled contents;… |
LLM05:2025 |
| CVE-2026-57572 | — | Critical 10.0 | 0.9%top 40.4% | 06 Jul 2026 | Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed into Chromium's launch arguments. An attacker could inject Chromium switches that replace a child-process launch command together with --no-zygote, causing Chromium to fork or exec an attacker-controlled command as the container's… |
LLM05:2025 |
| CVE-2026-54234 | — | High 7.5 | 0.6%top 52.3% | 06 Jul 2026 | vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal multi-request speculative decoding workload can cause the rejection sampler to produce a recovered token equal to the model vocabulary size boundary value, which is then converted to negative one when the engine selects the next live token for a request and is written back into… |
LLM10:2025 |
| CVE-2026-55574 | — | High 7.5 | 0.6%top 54.0% | 06 Jul 2026 | vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the structured_outputs.regex API parameter passes a user-supplied regular expression string directly to the grammar compiler backends with no compilation timeout; in the xgrammar backend the string reaches the regex compiler with no guard, and in the outlines backend the validation step blocks… |
|
| CVE-2026-57573 | — | High 8.6 | 0.4%top 63.5% | 06 Jul 2026 | Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF destination check on the non-streaming /crawl path but not on the streaming path. handle_stream_crawl_request passed seed URLs straight to the crawler with no destination validation, allowing a remote unauthenticated client to call POST /crawl/stream or POST /crawl with… |
LLM05:2025 |
| CVE-2026-55514 | — | Medium 6.5 | 0.7%top 50.0% | 06 Jul 2026 | vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a /v1/completions request with a model using M-RoPE causes EngineCore to fail an assertion and fatally crash, shutting down the entire server application. Any remote user who is authorized to make a /v1/completions request can make such a request and induce a crash. This issue is… |
|
| CVE-2026-14898 | — | Medium 6.5 | 0.4%top 71.0% | 06 Jul 2026 | The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. An attacker who could place an indirect prompt injection in content processed by Codex, such as a connected-tool result or another untrusted source, could induce the model to construct a remote image URL containing sensitive data. The app automatically fetched that URL when rendering the response,… |
LLM01:2025 |
| CVE-2026-55646 | — | Medium 6.5 | 0.5%top 57.9% | 06 Jul 2026 | vLLM is an inference and serving engine for large language models. From 0.22.0 to 0.23.0, the /v1/audio/transcriptions and /v1/audio/translations routes call request.file.read() to fully materialize an uploaded audio file into memory before vLLM checks the documented VLLM_MAX_AUDIO_CLIP_FILESIZE_MB compressed upload size limit (default 25 MB) later in the speech-to-text preprocessing step, so an… |
|
| CVE-2026-44934 | — | Unscored | 0.2%top 96.3% | 06 Jul 2026 | A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM response text with potential sensitive data into logfiles, allowing local attackers to misuse respective gained data or credentials. |
LLM02:2025 |
| CVE-2026-14742 | — | Low 3.1 | 0.2%top 87.1% | 05 Jul 2026 | A vulnerability was determined in langchain-ai langgraph up to 1.2.4. The affected element is the function _freeze of the file libs/langgraph/langgraph/_internal/_cache.py of the component Task Result Cache. This manipulation of the argument default_cache_key causes use of weak hash. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability… |
|
| CVE-2026-13341 | — | High 7.4 | 0.4%top 63.4% | 03 Jul 2026 | A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could allow a remote attacker to perform an indirect prompt injection attack and execute unintended API requests. |
LLM01:2025 |
| CVE-2026-8147 | — | High 8.1 | 0.5%top 56.1% | 02 Jul 2026 | In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators. This allows any authenticated user to bypass experiment-level authorization controls on all trace operations, including reading, deleting, and modifying traces on experiments they do not have permission to access. The issue arises from the `_before_request`… |
|
| CVE-2026-10134 | — | Critical 10.0 | 0.6%top 51.1% | 30 Jun 2026 | IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversation, message, file upload, and saved component in the Langflow database, can connect to internal services, abuse cloud metadata endpoints, laterally move to other tenants on the same Langflow instance, and Establish persistence by modifying the… |
|
| CVE-2026-10140 | — | Critical 9.6 | 0.4%top 73.7% | 30 Jun 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. An authenticated attacker can manipulate cache state to cause requests from other users to be processed using incorrect upstream API credentials, leading to cross-tenant billing and accountability misattribution. |
|
| CVE-2026-7663 | — | Critical 9.1 | 0.5%top 57.9% | 30 Jun 2026 | IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint. |
|
| CVE-2026-7803 | — | Critical 9.8 | 0.6%top 51.0% | 30 Jun 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes with missing or empty component type fields. |
LLM05:2025 |
| CVE-2026-7871 | — | Critical 9.8 | 0.7%top 48.7% | 30 Jun 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system integrity. |
LLM05:2025 |
| CVE-2026-7873 | — | Critical 9.9 | 0.5%top 57.2% | 30 Jun 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials, enabling complete system compromise and lateral movement. |
|
| CVE-2026-7874 | — | Critical 9.1 | 0.3%top 81.9% | 30 Jun 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use of a weak and reversible key derivation mechanism for encryption at rest. |
|
| CVE-2026-58169 | — | High 7.5 | 0.4%top 66.1% | 30 Jun 2026 | Vibe-Trading before 0.1.10 contains a DNS rebinding authentication bypass vulnerability that allows remote attackers to bypass bearer-token authentication by exploiting the server's trust of TCP peer addresses for loopback clients combined with missing Host header validation while binding to 0.0.0.0 with credentialed CORS. Attackers can craft a malicious DNS rebinding page to issue authenticated… |
LLM05:2025 |
| CVE-2026-10564 | — | High 8.2 | 0.3%top 75.0% | 30 Jun 2026 | IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSReaderComponent in rss.py and SearXNG component in searxng.py make unvalidated HTTP requests to user-controlled URLs, bypassing SSRF protections introduced in version 1.9.3. An authenticated attacker can exploit this to access internal resources including cloud metadata services (AWS/Azure/GCP IMDS),… |
LLM01:2025LLM05:2025 |
| CVE-2026-10129 | — | High 8.5 | 0.3%top 77.9% | 30 Jun 2026 | IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass vulnerability in the API Request component. An authenticated attacker with low-level privileges (flow author role) can bypass SSRF protections by enabling the follow_redirects parameter and supplying a public URL that redirects to internal/localhost addresses. The vulnerability exists because the… |
LLM05:2025 |
| CVE-2026-10546 | — | High 7.1 | 0.2%top 85.5% | 30 Jun 2026 | IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the URL component ( src/lfx/src/lfx/components/data_source/url.py ) due to a Time-of-Check/Time-of-Use (TOCTOU) race condition that can be exploited via DNS rebinding. |
LLM05:2025 |
| CVE-2026-10560 | — | High 8.2 | 0.5%top 60.5% | 30 Jun 2026 | IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints that allows an unauthenticated attacker to read build event data or cancel jobs using a valid job identifier, resulting in information disclosure and denial of service. |
LLM02:2025LLM10:2025 |
| CVE-2026-58446 | — | Medium 6.5 | 0.7%top 48.4% | 30 Jun 2026 | Presenton before 0.8.8-beta bundles an MCP server that, on server/Docker deployments configured with session authentication (AUTH_USERNAME/AUTH_PASSWORD), is reachable unauthenticated at /mcp because the nginx front-end does not apply the auth_request gate to that path and the MCP server auto-mints a valid internal session token for the configured user. A remote unauthenticated attacker can… |
|
| CVE-2026-55607 | — | High 8.8 | 0.7%top 49.0% | 29 Jun 2026 | Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to worktrees outside the sandbox context, enabling git directory confusion attacks. By exploiting symlink manipulation and git fsmonitor execution during worktree operations, an attacker could overwrite files in the user's home directory… |
LLM01:2025LLM05:2025 |
| CVE-2026-13437 | — | Medium 6.5 | 0.4%top 64.1% | 29 Jun 2026 | Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obtain reusable, potentially higher-privileged authentication tokens via App Tokens serialized in plaintext in job API responses. |
|
| CVE-2026-13484 | — | Medium 5.0 | 0.5%top 59.1% | 28 Jun 2026 | A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unknown function of the component Experiment-scoped Label Schema CRUD API. Such manipulation leads to missing authorization. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is regarded as difficult. The exploit… |
|
| CVE-2026-13493 | — | Low 3.1 | 0.4%top 71.9% | 28 Jun 2026 | A flaw has been found in AIDC-AI ComfyUI-Copilot up to 2.0.28. This issue affects some unknown processing of the file backend/controller/conversation_api.py of the component Workflow Checkpoint Restore Handler. Executing a manipulation can lead to improper control of resource identifiers. The attack may be performed from remote. A high complexity level is associated with this attack. The… |
|
| CVE-2026-5757 | — | High 7.5 | 0.7%top 47.2% | 26 Jun 2026 | Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive data exposure, further compromise, and stealthy persistence. |
LLM02:2025 |
| CVE-2026-55412 | — | High 8.3 | 0.3%top 77.3% | 25 Jun 2026 | ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts, there's an SSRF in the RestAPI data source component. The RestAPI data source executes HTTP requests server-side, and its private IP filter only checks the hostname string — not the resolved IP. DNS names like 169.254.169.254.nip.io resolve to the… |
LLM05:2025 |
| CVE-2026-55411 | — | Medium 6.8 | 0.2%top 91.2% | 25 Jun 2026 | ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.1780-lts, the authenticated endpoint POST /api/data-sources/decrypt returns the decrypted plaintext for any credential whose credential_id is supplied in the request body. Unlike every neighbouring data-source route, this handler is not protected by… |
|
| CVE-2026-55413 | — | Unscored | 0.4%top 68.5% | 25 Jun 2026 | ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts, any authenticated user with builder role (free tier) can overwrite a globally-shared marketplace plugin with arbitrary JavaScript that executes server-side with full Node.js access (require, process). The malicious code runs whenever any user on… |
|
| CVE-2026-55583 | — | High 7.6 | 0.3%top 83.8% | 24 Jun 2026 | Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.9.0, Twenty was vulnerable to a cross-workspace insecure direct object reference (IDOR) in the AI agent monitor's AgentTurnResolver, in packages/twenty-server/src/engine/metadata-modules/ai/ai-agent-monitor/reso lvers/agent-turn.resolver.ts. The agentTurns(agentId) query and the evaluateAgentTurn(turnId) mutation… |
|
| CVE-2026-48719 | — | High 8.0 | 1.3%top 30.1% | 24 Jun 2026 | Warp is an agentic development environment. From 0.2025.08.06.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection in the prompt branch selector. A user who can publish a branch to a Git repository opened in Warp can cause a crafted branch name to be interpreted by the victim's shell if the victim selects that branch from the UI. This vulnerability is fixed in… |
LLM05:2025 |
| CVE-2026-48789 | — | Medium 4.3 | 0.3%top 74.6% | 24 Jun 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, on Windows, the document folder listing route can accept an encoded absolute Windows path that resolves outside the intended documents directory. The shared path containment helper rejects POSIX-style "../" traversal but does not reject Windows-style parent… |
|
| CVE-2026-55611 | — | None 0.0 | 0.4%top 67.6% | 24 Jun 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.11.1 until 1.14.1, userId/workspaceId scoping to the parsed-files read/delete paths was added. However, the POST /api/workspace/:slug/embed-parsed-file/:fileId flow still deletes the target file by primary key only, with no ownership check, inside two finally{} blocks… |
|
| CVE-2026-53753 | — | Critical 9.8 | 2.9%top 13.5% | 23 Jun 2026 | Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature uses an AST validator that only blocks attributes starting with underscore. Python generator and frame object attributes (gi_frame, f_back, f_builtins) do NOT start with underscore, enabling a complete sandbox escape to achieve arbitrary code… |
LLM05:2025LLM06:2025 |
| CVE-2026-48519 | — | Critical 9.6 | 0.8%top 45.5% | 23 Jun 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the "Shareable Playground" (or "Public Flows" in code) contains a critical RCE vulnerability. Shareable Playground feature works by enabling the execution of workflows by unauthenticated users, by accessing a link. Specifically, it enables the route /api/v1/build_public_tmp to execute any public flow,… |
|
| CVE-2026-55447 | — | Critical 9.6 | 0.7%top 50.1% | 23 Jun 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files that are digested into the RAG, an attacker can direct the node to read any file on the file-system by absolute path. All components based on BaseFileComponent are vulnerable to the vulnerability. This includes Docling (DoclingInlineComponent), Docling Serve,… |
|
| CVE-2026-55450 | — | Critical 9.3 | 1.2%top 33.1% | 23 Jun 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to the server without any limitations. No need for any prior knowledge, only network access to Langflow. This can lead to space exhaustion on the server. In addition, in the response, the absolute path of the uploaded file is reported to the attacker,… |
|
| CVE-2026-33760 | — | High 8.8 | 0.5%top 59.7% | 23 Jun 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow's /api/v1/monitor router exposes 7 endpoints that perform read, write, and delete operations on user-owned resources — messages, sessions, build artifacts, and LLM transaction logs — without verifying that the authenticated requester owns the targeted resource. Any authenticated user can read,… |
|
| CVE-2026-53754 | — | High 7.5 | 0.4%top 64.6% | 23 Jun 2026 | Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.8, the Docker API server's SSRF protection (validate_webhook_url / validate_url_destination in deploy/docker/utils.py) used an explicit IPv4/IPv6 CIDR blocklist that missed several address families. An attacker could reach internal services and cloud metadata endpoints (e.g. 169.254.169.254) despite the filter by encoding… |
LLM05:2025 |
| CVE-2026-53755 | — | High 8.6 | 1.6%top 25.4% | 23 Jun 2026 | Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.9, the Docker API server applied its SSRF destination check to the crawl target URL only, not to the proxy address. An unauthenticated request could supply a proxy pointing at an internal IP and route the browser through it, reaching internal services and cloud-metadata endpoints, while using a perfectly valid crawl URL.… |
LLM05:2025 |
| CVE-2026-54555 | — | High 7.8 | 0.2%top 91.5% | 23 Jun 2026 | rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.42.2, the permission splitter did not conservatively split or reject several shell constructs that Bash treats as command execution boundaries or nested execution. As a result, a command beginning with an allowed prefix such as git could hide a second command behind one of these constructs. rtk rewrite… |
|
| CVE-2026-55446 | — | High 7.5 | 0.6%top 54.1% | 23 Jun 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.0.19, an attacker can send a /api/v1/files/upload/ request without any authentication token/cookies and abuse a very long multipart form boundary to make the langflow app unusable for all users for an indefinite amount of time. This vulnerability is fixed in 1.0.19. |
|
| CVE-2026-48520 | — | Medium 6.1 | 0.4%top 64.2% | 23 Jun 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.10.0, the "Shareable Playground" (or "Public Flows" in code) contains a potential arbitrary file-read vulnerability, depending on the exact flow configuration used. By making a flow public, public execution of the flow is allowed. The execution request can contain a list of files that gets read by Langflow… |
|
| CVE-2026-54009 | — | Medium 6.5 | 0.4%top 70.1% | 23 Jun 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, POST /api/chat/completions accepts an image_url.url value that, when it does NOT start with http://, https://, or data:image/, is interpreted as a file id and resolved against the global file table with no ownership check. an authenticated user can therefore set image_url.url to… |
|
| CVE-2026-55249 | — | Medium 6.3 | 0.6%top 55.8% | 23 Jun 2026 | @rtk-ai/rtk-rewrite transparently rewrites shell commands executed via OpenClaw's exec tool to their RTK equivalents. In 1.0.0, the @rtk-ai/rtk-rewrite OpenClaw plugin passes attacker-controlled input directly into a shell-backed execSync() template string without shell-safe escaping. JSON.stringify() wraps the value in double quotes and escapes inner double-quotes and backslashes, but leaves $()… |
|
| CVE-2026-45792 | — | Medium 5.5 | 0.1%top 98.9% | 23 Jun 2026 | rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.32.0, RTK (Rust Token Killer) improperly trusts project-local configuration files. RTK automatically loads .rtk/filters.toml from the working directory with highest priority and without user notification. An attacker can place a malicious filter file in a repository to apply regex-based modifications (e.g.,… |
|
| CVE-2026-54021 | — | Medium 6.3 | 0.3%top 81.1% | 23 Jun 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, several direct, index-addressed Ollama proxy routes accept a caller-supplied url_idx path parameter and use it as a raw index into the admin-configured OLLAMA_BASE_URLS list. Access control on these routes validates only whether the user may use the requested model, never which… |
|
| CVE-2026-42867 | — | Medium 6.5 | 0.5%top 61.8% | 23 Jun 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API (POST /api/v1/knowledge_bases). This occurs because user-supplied knowledge base names are used directly to create file paths without proper sanitization or containment checks. An authenticated attacker can exploit this flaw to create… |
LLM05:2025 |
| CVE-2026-55423 | — | Medium 6.1 | 0.2%top 88.4% | 23 Jun 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.7.0, the logout button does not clear the session. The previous user stays logged in unless another user explicitly logs in. This vulnerability is fixed in 1.7.0. |
|
| CVE-2026-49468 | — | Critical 9.8 | 3.0%top 12.9% | 22 Jun 2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, a Host-header parsing flaw in the LiteLLM proxy could, under specific conditions, allow unauthenticated access to protected management routes. The auth layer derived the effective route from request.url.path in litellm/proxy/auth/auth_utils.py::get_request_route(), which Starlette reconstructs… |
|
| CVE-2026-48746 | — | Critical 9.1 | 1.2%top 34.2% | 22 Jun 2026 | vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or --api-key. This vulnerability is fixed in 0.22.0. |
|
| CVE-2026-10561 | — | Critical 10.0 | 1.0%top 38.3% | 22 Jun 2026 | IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise |
LLM05:2025 |
| CVE-2026-7664 | — | Critical 9.8 | 0.5%top 59.5% | 22 Jun 2026 | IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint. |
Showing the 500 most relevant of 548 — exploited first, then newest. Everything else is in the archive.
Selection is narrow on purpose: "AI" appears in many advisories that have nothing to do with model security. Risk chips are this site's mapping onto the OWASP list and are indicative only. A CISA due date is the deadline for US federal agencies — a useful urgency signal for everyone else.