AI Component

Plugin

Plugins and tools are the bridge between an LLM and the world outside it: a web-fetch tool, a code interpreter, a shell, an email API, a calendar integration. Each tool the agent can invoke is a new piece of attack surface, and the agent's prompt-injection problem becomes the tool's authorization problem. Common patterns we see in CVEs and AIID reports include over-broad tool permissions (an email-sending tool with no recipient allowlist), SSRF in browse-the-web tools, RCE in code-interpreter sandboxes that escape too easily, and confused-deputy attacks where the agent invokes a tool on behalf of an attacker-controlled prompt instead of the legitimate user. OpenAI's plugin ecosystem and ChatGPT's tool framework have shipped published vulnerabilities; LangChain, LangGraph, CrewAI, and AutoGen have each had agent-tool CVEs. Defenses: least-privilege tool scopes, human-in-the-loop on irreversible actions, separate trust contexts, and auditable tool invocation logs.

244
Total CVEs
13
Pages
Page 3 of 13
Current
Severity CVE CVSS
UNKNOWN CVE-2025-15063 -
CRITICAL CVE-2024-42835 9.8
UNKNOWN CVE-2026-0769 -
UNKNOWN CVE-2026-0771 -
HIGH CVE-2024-11030 7.5
HIGH CVE-2024-11031 7.5
HIGH CVE-2024-45848 8.8
UNKNOWN CVE-2025-34072 -
MEDIUM CVE-2025-11844 5.4
CRITICAL CVE-2025-13374 9.8
MEDIUM CVE-2026-25475 6.5
CRITICAL CVE-2026-25592 9.9
MEDIUM CVE-2026-26972 6.7
CRITICAL CVE-2025-59528 10.0
CRITICAL CVE-2025-61913 9.9
HIGH CVE-2025-56265 8.8
HIGH CVE-2025-62726 8.8
HIGH CVE-2025-68613 8.8
MEDIUM CVE-2025-61914 5.4
CRITICAL CVE-2025-68668 9.9

Page 3 of 13