PraisonAI Has Sandbox Escape via shell=True and Bypassable Blocklist

CVSS 8.8 praisonai View details

PraisonAI: Shell Injection in run_python() via Unescaped $() Substitution

CVSS 7.8 praisonaiagents View details
CVE CRITICAL CVE-2026-34938

PraisonAI: Python Sandbox Escape via str Subclass startswith() Override in

CVSS 10.0 praisonaiagents View details

OpenClaw has Sandbox Media Root Bypass via Unnormalized `mediaUrl` / `fileUrl

CVSS 7.7 openclaw View details

@mobilenext/mobile-mcp alllows arbitrary file write via Path Traversal in mobile

CVSS 8.1 @mobilenext/mobile-mcp View details
CVE CRITICAL CVE-2026-25130

CAI find_file Agent Tool has Command Injection Vulnerability Through

CVSS 9.7 cai-framework View details

LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt

CVSS 7.5 langchain-core View details
CVE MEDIUM CVE-2024-11896

Text Prompter – Unlimited chatgpt text prompts for openai tasks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'text_prompter' shortcode in all versions

banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI

CVSS 7.5 banks View details
CVE CRITICAL CVE-2024-34359

llama-cpp-python is the Python bindings for llama.cpp. `llama

Flowise: Parameter Override Bypass Remote Command Execution

CVSS 7.7 flowise-components View details
CVE CRITICAL CVE-2025-9556

files, which leads to a server side template injection vulnerability within langchaingo, allowing an attacker to insert a statement into a prompt to read the "etc/passwd" file

CVE MEDIUM CVE-2026-44222

vLLM Vulnerable to Remote DoS via Special-Token Placeholders

CVSS 6.5 vllm View details

LiteLLM: Server-Side Template Injection in /prompts/test endpoint

Open WebUI Affected by an External Model Server (Direct Connections

CVSS 7.3 open-webui View details
CVE CRITICAL CVE-2026-25481

Langroid has WAF Bypass Leading to RCE in TableChatAgent

Previous Page 4 of 4