AI Component

Plugin

Plugins and tools are the bridge between an LLM and the world outside it: a web-fetch tool, a code interpreter, a shell, an email API, a calendar integration. Each tool the agent can invoke is a new piece of attack surface, and the agent's prompt-injection problem becomes the tool's authorization problem. Common patterns we see in CVEs and AIID reports include over-broad tool permissions (an email-sending tool with no recipient allowlist), SSRF in browse-the-web tools, RCE in code-interpreter sandboxes that escape too easily, and confused-deputy attacks where the agent invokes a tool on behalf of an attacker-controlled prompt instead of the legitimate user. OpenAI's plugin ecosystem and ChatGPT's tool framework have shipped published vulnerabilities; LangChain, LangGraph, CrewAI, and AutoGen have each had agent-tool CVEs. Defenses: least-privilege tool scopes, human-in-the-loop on irreversible actions, separate trust contexts, and auditable tool invocation logs.

244
Total CVEs
13
Pages
Page 2 of 13
Current
Severity CVE CVSS
MEDIUM CVE-2025-6716 6.4
MEDIUM CVE-2025-7780 6.5
MEDIUM CVE-2025-54558 4.1
HIGH CVE-2025-7725 7.2
MEDIUM CVE-2025-60511 4.3
MEDIUM CVE-2025-12360 4.3
MEDIUM CVE-2025-11972 4.9
MEDIUM CVE-2025-12732 4.3
HIGH CVE-2025-12973 7.2
MEDIUM CVE-2025-13354 4.3
MEDIUM CVE-2025-13359 6.5
MEDIUM CVE-2025-13922 6.5
MEDIUM CVE-2025-14371 4.3
MEDIUM CVE-2025-14980 6.5
UNKNOWN CVE-2024-10950 -
HIGH CVE-2025-66404 8.8
LOW CVE-2026-24764 3.7
HIGH CVE-2026-26321 7.5
CRITICAL CVE-2026-2654 9.8
MEDIUM CVE-2021-28796 6.1

Page 2 of 13