CVE CRITICAL CVE-2026-61447

without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system

CVSS 10.0 praisonai View details

Open WebUI: Redis Cache Keys tool_servers and terminal_servers

CVSS 8.7 open-webui View details
CVE MEDIUM CVE-2026-14898

remote images from Markdown in model responses. An attacker who could place an indirect prompt injection in content processed by Codex, such as a connected-tool result or another untrusted

SearXNG MCP Server: Unbounded Response Body Read Bypasses URL Size

CVSS 7.5 mcp-searxng View details
CVE MEDIUM CVE-2026-22551

from AI responses, triggering HTTP requests to arbitrary external URLs without restriction. Combined with prompt injection in a malicious workspace, an attacker could induce the AI agent to construct image

@theia/ai-ide View details

blocklisting, or private network checks are applied before fetching. This allows an attacker (or prompt injection in crawled content) to force the agent to fetch cloud metadata endpoints, internal services

CVSS 7.7 praisonaiagents View details
CVE MEDIUM CVE-2026-34451

prefix check that did not append a trailing path separator. A model steered by prompt injection could supply a crafted path that resolved to a sibling directory sharing the memory

@anthropic-ai/sdk View details
CVE CRITICAL CVE-2026-28451

function and markdown image processing. Attackers can influence tool calls through direct manipulation or prompt injection to trigger requests to internal services and re-upload responses as Feishu media

CVSS 9.3 openclaw View details
CVE CRITICAL CVE-2026-27966

result, an attacker can execute arbitrary Python and OS commands on the server via prompt injection, leading to full Remote Code Execution (RCE). Version 1.8.0 fixes the issue

CVSS 9.8 langflow View details

read them directly. If an attacker can influence tool calls (directly or via prompt injection), they may be able to exfiltrate local files by supplying paths such as `/etc/passwd

CVSS 7.5 openclaw View details

output. An attacker who can supply or influence the parsed text (for example via prompt injection in downstream applications that pass LLM output directly into MRKLOutputParser.parse

CVSS 7.5 langchain View details
CVE CRITICAL CVE-2025-46059

langchain-ai v0.3.51 was discovered to contain an indirect prompt injection vulnerability in the GmailToolkit component. This vulnerability allows attackers to execute arbitrary code and compromise the application

CVE UNKNOWN CVE-2026-55615

Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed

CVE CRITICAL CVE-2026-61445

missing path validation and command sanitization in LLM tool calls. Attackers can inject malicious prompts through the chat interface to write files to arbitrary filesystem locations and execute arbitrary shell

CVSS 9.9 praisonai View details

server to make arbitrary HTTP requests to internal and external systems. By injecting malicious prompt templates, attackers can bypass the intended API documentation constraints and redirect requests to sensitive internal

CVSS 8.3 flowise View details
CVE CRITICAL CVE-2026-25879

Langroid has Prompt to SQL Injection, Leading

CVSS 9.8 langroid View details
CVE MEDIUM CVE-2026-40112

PraisonAI is a multi-agent teams system. Prior to 4.5.128

CVSS 5.4 praisonai View details

MCP Server Kubernetes is an MCP Server that can connect

CVSS 8.8 mcp-server-kubernetes View details

Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in the prompt editor invocation utility that allows attackers to execute arbitrary commands by crafting malicious

characters (for example newlines or Unicode bidi/zero-width markers), those characters could break the prompt structure and inject attacker-controlled instructions. Starting in version 2026.2.15, the workspace path is saniti

CVSS 7.8 openclaw View details
Previous Page 3 of 7 Next