Social Engineering
Generative AI lowers the cost of social engineering by orders of magnitude. Spear-phishing emails that previously required a fluent writer and target research are now produced in seconds with reasonable per-target personalisation. Voice cloning (ElevenLabs, OpenVoice, and others) enables real-time impersonation of executives and family members; multiple confirmed business-email-compromise and CFO-fraud incidents in 2023-2024 used cloned voices. Deepfake video is good enough for short verification clips and live calls under poor video conditions. Beyond direct attacks, AI-generated content fuels disinformation campaigns, fake review economies, and pig-butchering scams at unprecedented scale. AI Threat Alert tracks this category through CVEs in voice/face-recognition systems that fail to detect synthetic media, plus incidents in AIID (the AI Incident Database). Defenses: out-of-band verification for sensitive actions, deepfake detection layered with provenance signals (C2PA), and user education that assumes any voice or video can be faked.
| Severity | CVE | Headline | Package | CVSS |
|---|---|---|---|---|
| HIGH | CVE-2026-26192 | Open WebUI: stored XSS via citation iFrame → admin RCE | open-webui | 7.3 |
| MEDIUM | CVE-2025-46571 | Open WebUI: Stored XSS via HTML upload enables admin RCE | open-webui | - |
| MEDIUM | CVE-2026-56359 | n8n: XSS via malicious OAuth2 Authorization URL | n8n | 5.4 |
| HIGH | CVE-2026-59806 | Gradio: SSRF via file_fetch() leaks cloud IAM creds | gradio | 7.4 |
| MEDIUM | CVE-2026-56354 | n8n: stored XSS + phishing redirect in Form Node | n8n | 5.4 |
| HIGH | CVE-2026-61428 | PraisonAI: webhook signature bypass enables spoofing | praisonai | 7.3 |
| MEDIUM | CVE-2025-34430 | 1Panel: CSRF allows unauthorized panel rename | - | |
| HIGH | CVE-2026-56400 | Open WebUI: CORS misconfig + CSRF enables admin RCE | open-webui | 8.3 |
| HIGH | CVE-2026-61436 | PraisonAI: missing webhook signature check spoofs agents | PraisonAI | 8.6 |
| HIGH | CVE-2026-65592 | n8n: stored XSS via javascript: URI in Resource Locator | n8n | - |
| HIGH | GHSA-pppj-hq3g-57pj | JupyterLab: crafted settings file executes code | jupyterlab | - |
| HIGH | GHSA-gx64-gj6p-pc4c | JupyterLab: image viewer XSS escalates to RCE | jupyterlab | - |
| HIGH | CVE-2026-59714 | Open WebUI: broken authz lets users overwrite channel chats | open-webui | 7.1 |
| HIGH | GHSA-pvcr-8mvp-w8qr | Budibase: CSRF hijacks AI chat-agent identity binding | 7.7 | |
| MEDIUM | CVE-2026-16774 | WPBot: unauthenticated email abuse via wp_mail() | WPBot – AI ChatBot for Live Support, Lead Generation, AI Services | 5.3 |
| MEDIUM | CVE-2026-67338 | JupyterLab: stored XSS via malicious extension metadata | 6.1 | |
| MEDIUM | CVE-2026-67618 | marimo: PEP-723 config injection steals API keys | 6.5 | |
| HIGH | CVE-2026-66881 | Livebook: path traversal in notebooks writes any file | 8.1 | |
| MEDIUM | CVE-2026-66885 | Livebook: CSRF binds victim session to attacker | 6.5 | |
| MEDIUM | CVE-2023-35394 | Azure HDInsight: Jupyter Notebook XSS enables spoofing | 4.6 |