CVE MEDIUM CVE-2026-35651

OpenClaw versions 2026.2.13 through 2026.3.24 contain an ANSI escape sequence injection vulnerability in approval prompts that allows attackers to spoof terminal output. Untrusted tool metadata can carry ANSI control sequences

CVSS 4.3 openclaw View details

Open WebUI has Knowledge Base Destruction and RAG Poisoning via

CVSS 8.1 open-webui View details
CVE CRITICAL CVE-2023-32785

Langchain SQL Injection vulnerability

CVSS 9.8 langchain View details

Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family

From versions 0.3.79 and prior and 1.0.0 to 1.0.6, a template injection vulnerability exists in LangChain's prompt template system that allows attackers to access Python object internals through template

langchain-core View details
CVE UNKNOWN CVE-2026-57495

AgenticMail gives AI agents real email addresses and phone numbers

CVE MEDIUM CVE-2026-45387

Open WebUI: Sharing models for others to use (read permission

CVSS 4.3 open-webui View details

@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not

CVSS 4.3 @dynatrace-oss/dynatrace-mcp-server View details

PraisonAI: Webhook signature verification skipped (fail-open) when secret unset

CVSS 8.6 praisonai View details

@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create

CVSS 4.2 @dynatrace-oss/dynatrace-mcp-server View details

MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url

CVSS 8.2 mcp-atlassian View details

TaskWeaver has Protection Mechanism Failure and Server-Side Request Forgery

CVSS 6.5 agentos-taskweaver View details
CVE CRITICAL CVE-2026-50027

mcp-memory-service: Missing Authentication on Document API Endpoints Allows

CVSS 9.8 mcp-memory-service View details

OpenClaw: Lower-trust background runtime output is injected into trusted

npm PraisonAI AgentOS exposes unauthenticated agent listing and invocation

CVSS 9.4 praisonai View details

DeepSeek TUI has SSRF via HTTP Redirect Bypass in fetch

CVSS 7.4 deepseek-tui View details
CVE MEDIUM CVE-2026-40151

PraisonAI: Unauthenticated Information Disclosure of Agent Instructions via /api/agents in

CVSS 5.3 PraisonAI View details
CVE UNKNOWN CVE-2024-48919

Cursor is a code editor built for programming with AI

Open WebUI: Same-origin XSS to account takeover via terminal

CVSS 8.2 open-webui View details

@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human

CVSS 3.7 @dynatrace-oss/dynatrace-mcp-server View details
Previous Page 4 of 7 Next