MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url

CVSS 8.2 mcp-atlassian View details

TaskWeaver has Protection Mechanism Failure and Server-Side Request Forgery

CVSS 6.5 agentos-taskweaver View details

OpenClaw: Lower-trust background runtime output is injected into trusted

LangChain vulnerable to unsafe deserialization of attacker-controlled objects through

CVSS 8.2 langchain-core View details
CVE MEDIUM CVE-2026-40151

PraisonAI: Unauthenticated Information Disclosure of Agent Instructions via /api/agents in

CVSS 5.3 PraisonAI View details
CVE UNKNOWN CVE-2024-48919

Cursor is a code editor built for programming with AI

CVE MEDIUM CVE-2026-43901

wireshark-mcp vulnerable to arbitrary file write via export_objects

CVSS 6.8 wireshark-mcp View details

PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated

CVSS 8.6 pptagent View details

OpenClaw's gateway config mutation guard allowed unsafe model-driven

CVSS 8.8 openclaw View details

OpenClaw: Webchat audio embedding could read local files without local

OpenClaw: Agent gateway config mutations could change protected operator settings

OpenClaw: Isolated cron awareness events were recorded as trusted system

Gemini CLI: Remote Code Execution via workspace trust and tool

CVSS 10.0 google-github-actions/run-gemini-cli View details

Claude Code is an agentic coding tool. Prior to version

@anthropic-ai/claude-code View details

SSH/SCP option injection allowing local RCE in @aiondadotcom/mcp-ssh

@aiondadotcom/mcp-ssh View details

PraisonAIAgents: SSRF via unvalidated URL in `web_crawl` httpx fallback

praisonaiagents View details

PraisonAI: Hardcoded `approval_mode="auto"` in Chainlit UI Overrides Administrator

CVSS 8.8 PraisonAI View details
CVE CRITICAL CVE-2026-40111

PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128

praisonaiagents View details
CVE MEDIUM CVE-2026-39398

openclaw-claude-bridge: sandbox is not effective - `--allowed-tools ""` does

claude-code View details

PraisonAI Has SSRF in FileTools.download_file() via Unvalidated URL

CVSS 8.6 praisonaiagents View details
Previous Page 3 of 4 Next