Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability

flowise-components View details
CVE MEDIUM CVE-2026-47395

PraisonAI CLI automatically resolves @url mentions in prompt text and

CVSS 5.5 PraisonAI View details

PraisonAI Vulnerable to OS Command Injection

CVSS 9.7 PraisonAI View details
CVE CRITICAL CVE-2026-44336

PraisonAI MCP `tools/call` path-traversal => RCE via Python `.pth` injection

CVSS 9.6 PraisonAI View details
CVE UNKNOWN CVE-2024-10950

husky/gpt_academic version <= 3.83, the plugin `CodeInterpreter` is vulnerable to code injection caused by prompt injection. The root cause is the execution of user-provided prompts that generate untrusted code

gpt_academic View details

Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack

CVSS 8.3 flowise-components View details

enabled, channel metadata (topic/description) can be incorporated into the model's system prompt. Prompt injection is a documented risk for LLM-driven systems. This issue increases the injection surface

CVSS 3.7 openclaw View details

Prompt injection vulnerability in 1millionbot Millie chatbot that occurs when a user manages to evade chat restrictions using Boolean prompt injection techniques (formulating a question in such a way that

CVE CRITICAL CVE-2026-42074

OpenClaude Sandbox Bypass via Model-Controlled `dangerouslyDisableSandbox` Input

openclaude View details

JSONalyzeQueryEngine` in the run-llama/llama_index repository allows for SQL injection via prompt injection. This can lead to arbitrary file creation and Denial-of-Service (DoS) attacks. The vulnerability affects

CVSS 7.1 llamaindex View details
CVE CRITICAL CVE-2024-8309

GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial of service

CVSS 9.8 langchain View details

server CORS wildcard + auth-off-by-default enables CSRF graph exfiltration and persistent indirect prompt injection

Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains

CVSS 7.1 flowise-components View details
CVE CRITICAL CVE-2024-7042

langchain-ai/langchainjs versions 0.2.5 and all versions with this class allows for prompt injection, leading to SQL injection. This vulnerability permits unauthorized data manipulation, data exfiltration, denial of service

CVSS 9.8 langchain View details
CVE CRITICAL CVE-2024-12366

PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that can lead to Remote Code Execution (RCE) instead of the intended explanation

CVSS 9.8 pandasai View details
CVE CRITICAL CVE-2026-45311

DeepSeek TUI: run_tests Tool Enables RCE via Malicious Repository

CVSS 9.6 deepseek-tui View details

PraisonAIAgents: Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False

CVSS 7.4 praisonaiagents View details
CVE MEDIUM CVE-2026-40117

requires critical-level approval, read_skill_file has neither protection. An agent influenced by prompt injection can exfiltrate sensitive files without triggering any approval prompt

CVSS 6.2 praisonaiagents View details
CVE MEDIUM CVE-2026-46341

Apify Model Context Protocol (MCP) server: Domain Allowlist Bypass in

CVSS 6.1 @apify/actors-mcp-server View details

PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web

CVSS 8.8 praisonaiagents View details
Page 1 of 6 Next