Data Extraction
Data extraction attacks target the information processed or memorised by AI/ML systems. They take three main forms. First, training-data extraction: large language models can memorise verbatim spans of their training corpus, and an attacker who crafts the right prompts can pull back PII, API keys, or copyrighted text — a result demonstrated against GPT-2 by Carlini et al. and reproduced against several production models. Second, model extraction: by repeatedly querying a hosted model and observing outputs, an attacker can reconstruct enough behaviour to clone proprietary fine-tunes. Third, system-prompt and conversation leakage: indirect prompt injection or insecure logging can leak the application's instructions and other users' conversations. Multi-tenant inference platforms (vLLM, Triton, hosted APIs) and RAG systems are particularly exposed. Defenses: output filtering, differential privacy in training, rate limits, and strict tenant isolation.
| Severity | CVE | Headline | Package | CVSS |
|---|---|---|---|---|
| MEDIUM | CVE-2026-9557 | Mautic Focus: SSRF enables internal network recon | mautic/core | 6.4 |
| UNKNOWN | CVE-2026-54760 | Langroid: SQLChatAgent regex bypass exposes pg_read_file | langroid | - |
| MEDIUM | CVE-2026-59819 | LiteLLM: admin-scope local file read via OIDC ref | litellm | 4.9 |
| MEDIUM | CVE-2026-61432 | PraisonAI: FastContext path traversal leaks host files | praisonaiagents | 5.7 |
| HIGH | GHSA-wm45-qh3g-v83f | mcp-atlassian: path traversal leaks server files+creds | mcp-atlassian | 7.7 |
| MEDIUM | GHSA-489g-7rxv-6c8q | mcp-atlassian: DNS-rebind bypass revives header SSRF | mcp-atlassian | 6.5 |
| HIGH | CVE-2026-61439 | PraisonAI: umbral de bloqueo mal configurado permite prompt injection | praisonai | 7.5 |
| HIGH | CVE-2026-61426 | PraisonAI: insecure defaults expose agent secrets | praisonai | 8.6 |
| CRITICAL | CVE-2026-61667 | DIRAC: SQLi chained into eval() gives RCE | DIRAC | 9.9 |
| HIGH | CVE-2026-32846 | OpenClaw: path traversal in media parsing leaks secrets | OpenClaw | - |
| UNKNOWN | CVE-2026-45535 | DataEase: stored SQL injection via dataset variables | - | |
| MEDIUM | CVE-2026-53656 | FiftyOne: wildcard CORS enables local file exfiltration | fiftyone | 6.3 |
| HIGH | CVE-2026-63086 | TGI: SSRF via image_url exposes cloud metadata creds | text-generation-inference | 8.6 |
| MEDIUM | CVE-2026-7754 | Langflow: SSRF via incomplete protection bypass | langflow | 6.5 |
| HIGH | CVE-2026-7872 | Langflow: path traversal enables auth token forgery | langflow | 8.1 |
| MEDIUM | CVE-2026-65593 | n8n: SSRF bypass in dynamic-node-parameters endpoint | n8n | - |
| MEDIUM | GHSA-vhf8-cg2h-cg3p | n8n: MCP Client SSRF bypasses egress protection | n8n | - |
| HIGH | GHSA-v42f-v8xc-j435 | Budibase: SSRF guard bypass via DNS rebinding | @budibase/server | 8.5 |
| MEDIUM | CVE-2026-17458 | openclaw-cn: unpatched SSRF in browser agent click API | 6.3 | |
| HIGH | CVE-2026-67428 | Flyto2 Core: SSRF via unvalidated URLs in agent tools | flyto-core | 8.5 |