ATLAS Landscape
AML.T0086

Exfiltration via AI Agent Tool Invocation

AI agent tools capable of performing write operations may be invoked to exfiltrate data to an adversary. Sensitive information can be encoded into the tool's input parameters and transmitted to an adversary-controlled location (such as an inbox, document, or server) as part of a seemingly legitimate action. Variants include sending emails, creating or modifying documents, updating CRM records, or even generating media such as images or videos. The invoked tool itself may be legitimate but invoked by an adversary via [LLM Prompt Injection](/techniques/AML.T0051), or the tool may be malicious (See [AI Agent Tool Poisoning](/techniques/AML.T0110). [AI Agent Tool Poisoning](/techniques/AML.T0110) can also be used manipulate the inputs and destination of a separate legitimate tool, invoked through normal usage by the victim.

Severity CVE CVSS
CRITICAL CVE-2025-2828 10.0
CRITICAL CVE-2026-25053 9.9
CRITICAL CVE-2025-61913 9.9
CRITICAL CVE-2026-25592 9.9
CRITICAL CVE-2025-46059 9.8
CRITICAL CVE-2026-2654 9.8
CRITICAL CVE-2024-7042 9.8
CRITICAL CVE-2026-25130 9.7
CRITICAL GHSA-2763-cj5r-c79m 9.7
CRITICAL CVE-2026-28451 9.3
CRITICAL CVE-2026-27825 9.1
CRITICAL GHSA-8x8f-54wf-vv92 9.1
HIGH GHSA-qwgj-rrpj-75xm 8.8
HIGH CVE-2026-27498 8.8
HIGH GHSA-cwj3-vqpp-pmxr 8.8
HIGH CVE-2025-66404 8.8
HIGH CVE-2026-44552 8.7
HIGH GHSA-gqqj-85qm-8qhf 8.7
HIGH CVE-2026-34954 8.6
HIGH GHSA-4ggg-h7ph-26qr 8.5
HIGH CVE-2026-42449 8.5
HIGH CVE-2026-39974 8.5
HIGH CVE-2026-35394 8.3
HIGH GHSA-8g7g-hmwm-6rv2 8.3
HIGH CVE-2026-33989 8.1
HIGH GHSA-x462-jjpc-q4q4 8.1
HIGH CVE-2026-40150 7.7
HIGH CVE-2026-26321 7.5
HIGH CVE-2026-40153 7.4
HIGH GHSA-w8hx-hqjv-vjcq 7.3
HIGH CVE-2026-40114 7.2
MEDIUM CVE-2026-43901 6.8
MEDIUM CVE-2026-25631 6.5
MEDIUM CVE-2026-25475 6.5
MEDIUM CVE-2026-40117 6.2
MEDIUM CVE-2026-6011 5.6
MEDIUM GHSA-ffp3-3562-8cv3 5.5
MEDIUM CVE-2025-68697 5.4
MEDIUM CVE-2026-27795 4.1
HIGH GHSA-mr34-9552-qr95
UNKNOWN CVE-2025-34072
UNKNOWN CVE-2026-2286
UNKNOWN CVE-2026-2285
MEDIUM CVE-2026-34451
CRITICAL CVE-2026-35615
MEDIUM GHSA-846p-hgpv-vphc
HIGH GHSA-qx8j-g322-qj6m
MEDIUM GHSA-w8g9-x8gx-crmm
LOW GHSA-5fc7-f62m-8983
MEDIUM GHSA-3fv3-6p2v-gxwj
MEDIUM GHSA-vr5g-mmx7-h897
MEDIUM GHSA-qqq7-4hxc-x63c
HIGH CVE-2026-40160
HIGH GHSA-28g4-38q8-3cwc
MEDIUM GHSA-qqvm-66q4-vf5c
UNKNOWN CVE-2026-44694
HIGH CVE-2026-44335
LOW CVE-2026-44220
MEDIUM GHSA-55cf-xx38-4p9p
MEDIUM GHSA-gfg9-5357-hv4c
UNKNOWN CVE-2026-42226
UNKNOWN CVE-2026-42233
UNKNOWN CVE-2026-42237
LOW GHSA-c4qg-j8jg-42q5
UNKNOWN CVE-2026-41274