PraisonAIAgents: Path Traversal via Unvalidated Glob Pattern in list_files
from the lack of proper sandboxing when evaluating an LLM generated python script. Using prompt injection techniques, an unauthenticated attacker with the ability to send prompts to a chatflow using
AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator
@mobilenext/mobile-mcp: Arbitrary Android Intent Execution via mobile_open_url
Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks
auth-fetch-mcp: SSRF and disk exfiltration via unvalidated auth
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
sandbox escape, denial of service by crashing the server, server-side request forgery, prompt injection, and server
Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base
PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters
LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via the Python exec method
PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent
malicious repository containing prompt template files that, when the workspace was opened in Theia, replaced the AI's system instructions with attacker-controlled content (indirect prompt injection). Combined with other
OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbitrary code via a Request-Side prompt injection attack
agent, would cause the agent to follow attacker-controlled instructions (indirect prompt injection). Combined with other AI chat features available in untrusted workspaces, this enabled attack
Open WebUI: Redis Cache Keys tool_servers and terminal_servers
SearXNG MCP Server: Unbounded Response Body Read Bypasses URL Size
from AI responses, triggering HTTP requests to arbitrary external URLs without restriction. Combined with prompt injection in a malicious workspace, an attacker could induce the AI agent to construct image