OpenClaw versions 2026.2.13 through 2026.3.24 contain an ANSI escape sequence injection vulnerability in approval prompts that allows attackers to spoof terminal output. Untrusted tool metadata can carry ANSI control sequences
Open WebUI has Knowledge Base Destruction and RAG Poisoning via
From versions 0.3.79 and prior and 1.0.0 to 1.0.6, a template injection vulnerability exists in LangChain's prompt template system that allows attackers to access Python object internals through template
AgenticMail gives AI agents real email addresses and phone numbers
Open WebUI: Sharing models for others to use (read permission
@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not
PraisonAI: Webhook signature verification skipped (fail-open) when secret unset
@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create
MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url
TaskWeaver has Protection Mechanism Failure and Server-Side Request Forgery
mcp-memory-service: Missing Authentication on Document API Endpoints Allows
npm PraisonAI AgentOS exposes unauthenticated agent listing and invocation
DeepSeek TUI has SSRF via HTTP Redirect Bypass in fetch
PraisonAI: Unauthenticated Information Disclosure of Agent Instructions via /api/agents in
Open WebUI: Same-origin XSS to account takeover via terminal
@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human