ATLAS Landscape
AML.T0053

AI Agent Tool Invocation

Adversaries may use their access to an AI agent to invoke tools the agent has access to. LLMs are often connected to other services or resources via tools to increase their capabilities. Tools may include integrations with other applications, access to public or private data sources, and the ability to execute code. This may allow adversaries to execute API calls to integrated applications or services, providing the adversary with increased privileges on the system. Adversaries may take advantage of connected data sources to retrieve sensitive information. They may also use an LLM integrated with a command or script interpreter to execute arbitrary instructions. AI agents may be configured to have access to tools that are not directly accessible by users. Adversaries may abuse this to gain access to tools they otherwise wouldn't be able to use.

Severity CVE CVSS
CRITICAL CVE-2025-59528 10.0
CRITICAL CVE-2026-34938 10.0
CRITICAL CVE-2026-33663 10.0
CRITICAL CVE-2026-39888 10.0
CRITICAL CVE-2024-12909 10.0
CRITICAL CVE-2025-2828 10.0
CRITICAL CVE-2025-5120 10.0
CRITICAL CVE-2026-26030 10.0
CRITICAL GHSA-wpqr-6v78-jr5g 10.0
CRITICAL CVE-2026-0863 9.9
CRITICAL CVE-2026-25115 9.9
CRITICAL CVE-2026-1470 9.9
CRITICAL CVE-2026-27495 9.9
CRITICAL CVE-2025-68668 9.9
CRITICAL CVE-2026-21877 9.9
CRITICAL CVE-2026-27577 9.9
CRITICAL CVE-2026-25052 9.9
CRITICAL CVE-2025-61913 9.9
CRITICAL CVE-2026-25049 9.9
CRITICAL CVE-2026-40933 9.9
CRITICAL CVE-2026-25592 9.9
CRITICAL CVE-2026-25053 9.9
CRITICAL CVE-2026-27494 9.9
CRITICAL GHSA-vc46-vw85-3wvm 9.8
CRITICAL CVE-2026-41264 9.8
CRITICAL CVE-2026-2654 9.8
CRITICAL CVE-2026-41265 9.8
CRITICAL CVE-2025-13374 9.8
CRITICAL CVE-2026-41267 9.8
CRITICAL CVE-2025-46059 9.8
CRITICAL CVE-2024-42835 9.8
CRITICAL CVE-2024-8309 9.8
CRITICAL CVE-2024-7042 9.8
CRITICAL CVE-2024-12366 9.8
CRITICAL CVE-2024-27444 9.8
CRITICAL CVE-2024-23751 9.8
CRITICAL CVE-2023-32785 9.8
CRITICAL CVE-2023-39631 9.8
CRITICAL CVE-2023-39659 9.8
CRITICAL CVE-2023-38860 9.8
CRITICAL CVE-2023-36095 9.8
CRITICAL CVE-2023-36188 9.8
CRITICAL CVE-2023-36258 9.8
CRITICAL CVE-2023-34540 9.8
CRITICAL CVE-2023-29374 9.8
CRITICAL CVE-2026-27966 9.8
CRITICAL CVE-2026-30741 9.8
CRITICAL CVE-2026-30824 9.8
CRITICAL CVE-2025-58434 9.8
CRITICAL CVE-2026-25130 9.7
CRITICAL GHSA-2763-cj5r-c79m 9.7
CRITICAL CVE-2026-44211 9.6
CRITICAL CVE-2025-67511 9.6
CRITICAL CVE-2025-47241 9.3
CRITICAL CVE-2026-28451 9.3
CRITICAL CVE-2026-44007 9.1
CRITICAL CVE-2025-68665 9.1
CRITICAL CVE-2026-27825 9.1
CRITICAL CVE-2024-7774 9.1
CRITICAL GHSA-8x8f-54wf-vv92 9.1
CRITICAL CVE-2026-27493 9.0
CRITICAL CVE-2026-39305 9.0
CRITICAL CVE-2026-33749 9.0
HIGH GHSA-cwj3-vqpp-pmxr 8.8
HIGH CVE-2026-33696 8.8
HIGH CVE-2026-41137 8.8
HIGH CVE-2026-30820 8.8
HIGH CVE-2026-25056 8.8
HIGH CVE-2026-24780 8.8
HIGH CVE-2026-27497 8.8
HIGH CVE-2024-7297 8.8
HIGH CVE-2026-31829 8.8
HIGH CVE-2026-39891 8.8
HIGH CVE-2026-33713 8.8
HIGH CVE-2025-68613 8.8
HIGH CVE-2026-27498 8.8
HIGH CVE-2025-65964 8.8
HIGH CVE-2025-34291 8.8
HIGH CVE-2025-66404 8.8
HIGH CVE-2025-56265 8.8
HIGH CVE-2025-57760 8.8
HIGH CVE-2025-9141 8.8
HIGH GHSA-qwgj-rrpj-75xm 8.8
HIGH CVE-2026-41138 8.8
HIGH CVE-2025-62726 8.8
HIGH CVE-2024-3571 8.8
HIGH CVE-2026-34955 8.8
HIGH CVE-2023-27563 8.8
HIGH GHSA-gqqj-85qm-8qhf 8.7
HIGH CVE-2026-25580 8.6
HIGH CVE-2026-42079 8.6
HIGH CVE-2026-34954 8.6
HIGH CVE-2026-30617 8.6
HIGH CVE-2026-40158 8.6
HIGH GHSA-4ggg-h7ph-26qr 8.5
HIGH CVE-2026-39974 8.5
HIGH CVE-2026-42449 8.5
HIGH CVE-2026-35020 8.4
HIGH CVE-2026-44334 8.4
HIGH GHSA-8g7g-hmwm-6rv2 8.3
HIGH GHSA-f228-chmx-v6j6 8.3
HIGH CVE-2026-35394 8.3
HIGH CVE-2026-41270 8.3
HIGH CVE-2026-41271 8.3
HIGH CVE-2026-33665 8.2
HIGH GHSA-75hx-xj24-mqrw 8.2
HIGH CVE-2026-27826 8.2
HIGH CVE-2025-68664 8.2
HIGH CVE-2026-33989 8.1
HIGH CVE-2026-25055 8.1
HIGH GHSA-x462-jjpc-q4q4 8.1
HIGH CVE-2026-40149 7.9
HIGH CVE-2026-34937 7.8
HIGH CVE-2024-38459 7.8
HIGH CVE-2026-35021 7.8
HIGH CVE-2026-27001 7.8
HIGH CVE-2024-3095 7.7
HIGH GHSA-hr5v-j9h9-xjhg 7.7
HIGH CVE-2025-61917 7.7
HIGH CVE-2026-40150 7.7
HIGH GHSA-cvrr-qhgw-2mm6 7.7
HIGH CVE-2026-26321 7.5
HIGH CVE-2023-36189 7.5
HIGH CVE-2024-58339 7.5
HIGH CVE-2025-59527 7.5
HIGH CVE-2023-32786 7.5
HIGH CVE-2026-40153 7.4
HIGH CVE-2025-64496 7.3
HIGH GHSA-w8hx-hqjv-vjcq 7.3
HIGH CVE-2026-44721 7.3
HIGH CVE-2026-21893 7.2
HIGH CVE-2024-12911 7.1
HIGH GHSA-2x8m-83vc-6wv4 7.1
HIGH CVE-2026-41272 7.1
HIGH GHSA-6r77-hqx7-7vw8 7.1
HIGH GHSA-xhmj-rg95-44hv 7.1
MEDIUM CVE-2026-43901 6.8
MEDIUM CVE-2026-26972 6.7
MEDIUM CVE-2026-41481 6.5
MEDIUM CVE-2026-25475 6.5
MEDIUM CVE-2025-68477 6.5
MEDIUM GHSA-gpx9-96j6-pp87 6.5
MEDIUM CVE-2026-26320 6.5
MEDIUM CVE-2026-25631 6.5
MEDIUM CVE-2026-21894 6.5
MEDIUM CVE-2023-27562 6.5
MEDIUM CVE-2025-57749 6.5
MEDIUM CVE-2024-53526 6.4
MEDIUM CVE-2026-4963 6.3
MEDIUM CVE-2026-7687 6.3
MEDIUM CVE-2026-6599 6.3
MEDIUM CVE-2026-40117 6.2
MEDIUM GHSA-q8ff-7ffm-m3r9 6.0
MEDIUM CVE-2025-12695 5.9
MEDIUM CVE-2026-6011 5.6
MEDIUM GHSA-ffp3-3562-8cv3 5.5
MEDIUM CVE-2026-40159 5.5
MEDIUM GHSA-3c7f-5hgj-h279 5.4
MEDIUM CVE-2026-27578 5.4
MEDIUM CVE-2026-25054 5.4
MEDIUM CVE-2026-25051 5.4
MEDIUM CVE-2025-68697 5.4
MEDIUM CVE-2025-61914 5.4
MEDIUM CVE-2025-52478 5.4
MEDIUM CVE-2025-46343 5.4
MEDIUM GHSA-364x-8g5j-x2pr 5.4
MEDIUM CVE-2025-68949 5.3
MEDIUM CVE-2026-40152 5.3
MEDIUM CVE-2026-33751 4.8
MEDIUM CVE-2026-35651 4.3
MEDIUM GHSA-wg4g-395p-mqv3 4.3
MEDIUM CVE-2026-42282 4.3
MEDIUM CVE-2025-52554 4.3
MEDIUM CVE-2026-33720 4.2
MEDIUM CVE-2025-54558 4.1
MEDIUM CVE-2026-26019 4.1
MEDIUM CVE-2026-27795 4.1
LOW CVE-2026-26013 3.7
LOW CVE-2026-24764 3.7
LOW CVE-2026-41488 3.1
MEDIUM GHSA-q2gc-xjqw-qp89
MEDIUM GHSA-h2v7-xc88-xx8c
CRITICAL CVE-2026-40111
LOW GHSA-cm8v-2vh9-cxf3
MEDIUM GHSA-vjx8-8p7h-82gr
MEDIUM GHSA-3q42-xmxv-9vfr
MEDIUM GHSA-fwjq-xwfj-gv75
LOW GHSA-767m-xrhc-fxm7
HIGH CVE-2026-40160
MEDIUM GHSA-wpc6-37g7-8q4w
MEDIUM GHSA-846p-hgpv-vphc
MEDIUM GHSA-4p4f-fc8q-84m3
MEDIUM GHSA-98ch-45wp-ch47
MEDIUM GHSA-w6wx-jq6j-6mcj
MEDIUM GHSA-fh32-73r9-rgh5
MEDIUM GHSA-rxmx-g7hr-8mx4
UNKNOWN CVE-2024-10950
MEDIUM CVE-2026-35646
HIGH CVE-2026-35629
HIGH GHSA-p4h8-56qp-hpgv
MEDIUM CVE-2026-34425
CRITICAL CVE-2026-35615
HIGH GHSA-28g4-38q8-3cwc
HIGH GHSA-6f7g-v4pp-r667
MEDIUM CVE-2026-34451
MEDIUM GHSA-9q7v-8mr7-g23p
MEDIUM CVE-2026-34452
UNKNOWN CVE-2026-2275
CRITICAL GHSA-9wc7-mj3f-74xv
UNKNOWN CVE-2026-2285
MEDIUM GHSA-9hrv-gvrv-6gf2
MEDIUM GHSA-qqvm-66q4-vf5c
MEDIUM GHSA-w6v6-49gh-mc9w
LOW GHSA-gj9q-8w99-mp8j
UNKNOWN CVE-2026-2286
UNKNOWN CVE-2026-2287
UNKNOWN CVE-2026-44694
UNKNOWN CVE-2026-33873
UNKNOWN CVE-2024-12775
HIGH CVE-2026-44335
LOW CVE-2026-44220
UNKNOWN CVE-2025-34072
UNKNOWN CVE-2025-55012
MEDIUM GHSA-5h3g-6xhh-rg6p
HIGH GHSA-wppj-c6mr-83jj
MEDIUM GHSA-x3h8-jrgh-p8jx
HIGH GHSA-r6xh-pqhr-v4xh
MEDIUM GHSA-55cf-xx38-4p9p
MEDIUM GHSA-q3jj-46pq-826r
MEDIUM GHSA-2hh7-c75g-qj2r
UNKNOWN CVE-2025-59532
UNKNOWN CVE-2025-66479
MEDIUM GHSA-gfg9-5357-hv4c
MEDIUM GHSA-c28g-vh7m-fm7v
UNKNOWN CVE-2026-42232
UNKNOWN CVE-2026-42231
UNKNOWN CVE-2026-42235
UNKNOWN CVE-2026-42234
UNKNOWN CVE-2026-42228
UNKNOWN CVE-2026-42229
UNKNOWN CVE-2026-42233
UNKNOWN CVE-2026-42237
MEDIUM GHSA-7jm2-g593-4qrc
MEDIUM GHSA-qrp5-gfw2-gxv4
MEDIUM GHSA-72q8-jcmc-97wx
LOW GHSA-j4c5-89f5-f3pm
LOW GHSA-xrq9-jm7v-g9h7
LOW GHSA-c4qg-j8jg-42q5
MEDIUM GHSA-2xcp-x87w-q377
HIGH GHSA-v4p8-mg3p-g94g
UNKNOWN CVE-2026-0769
UNKNOWN CVE-2026-41274
HIGH CVE-2025-64439
UNKNOWN CVE-2025-15063
UNKNOWN CVE-2026-0771
UNKNOWN CVE-2026-0772
CRITICAL CVE-2026-25481
HIGH CVE-2026-39861
HIGH CVE-2025-65106
CRITICAL GHSA-v38x-c887-992f
MEDIUM GHSA-f934-5rqf-xx47
HIGH GHSA-mr34-9552-qr95
CRITICAL GHSA-xh72-v6v9-mwhc
HIGH GHSA-2gvc-4f3c-2855
MEDIUM CVE-2026-39398
HIGH GHSA-xmxx-7p24-h892
HIGH GHSA-qx8j-g322-qj6m
MEDIUM GHSA-w9j9-w4cp-6wgr
MEDIUM GHSA-w8g9-x8gx-crmm
LOW GHSA-4f8g-77mw-3rxc
MEDIUM GHSA-vr5g-mmx7-h897
LOW GHSA-5fc7-f62m-8983
MEDIUM GHSA-3fv3-6p2v-gxwj
HIGH GHSA-5wj5-87vq-39xm
MEDIUM GHSA-vc32-h5mq-453v
MEDIUM GHSA-cmfr-9m2r-xwhq
MEDIUM GHSA-67mf-f936-ppxf
MEDIUM GHSA-whf9-3hcx-gq54
MEDIUM GHSA-qqq7-4hxc-x63c