OpenClaw: Isolated cron awareness events were recorded as trusted system

Gemini CLI: Remote Code Execution via workspace trust and tool

CVSS 10.0 google-github-actions/run-gemini-cli View details

Claude Code is an agentic coding tool. Prior to version

@anthropic-ai/claude-code View details

SSH/SCP option injection allowing local RCE in @aiondadotcom/mcp-ssh

@aiondadotcom/mcp-ssh View details

PraisonAIAgents: SSRF via unvalidated URL in `web_crawl` httpx fallback

praisonaiagents View details

PraisonAI: Hardcoded `approval_mode="auto"` in Chainlit UI Overrides Administrator

CVSS 8.8 PraisonAI View details
CVE CRITICAL CVE-2026-40111

PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128

praisonaiagents View details
CVE MEDIUM CVE-2026-39398

openclaw-claude-bridge: sandbox is not effective - `--allowed-tools ""` does

claude-code View details

PraisonAI Has SSRF in FileTools.download_file() via Unvalidated URL

CVSS 8.6 praisonaiagents View details

PraisonAI Has Sandbox Escape via shell=True and Bypassable Blocklist

CVSS 8.8 praisonai View details

PraisonAI: Shell Injection in run_python() via Unescaped $() Substitution

CVSS 7.8 praisonaiagents View details
CVE CRITICAL CVE-2026-34938

PraisonAI: Python Sandbox Escape via str Subclass startswith() Override in

CVSS 10.0 praisonaiagents View details

OpenClaw has Sandbox Media Root Bypass via Unnormalized `mediaUrl` / `fileUrl

CVSS 7.7 openclaw View details

@mobilenext/mobile-mcp alllows arbitrary file write via Path Traversal in mobile

CVSS 8.1 @mobilenext/mobile-mcp View details
CVE CRITICAL CVE-2026-25130

CAI find_file Agent Tool has Command Injection Vulnerability Through

CVSS 9.7 cai-framework View details

PraisonAI: Jobs API exposes agent-execution endpoints with no authentication

CVSS 9.8 praisonai View details

LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt

CVSS 7.5 langchain-core View details

PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal

CVSS 7.5 praisonaiagents View details
CVE MEDIUM CVE-2024-11896

Text Prompter – Unlimited chatgpt text prompts for openai tasks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'text_prompter' shortcode in all versions

CVE CRITICAL CVE-2024-34359

llama-cpp-python is the Python bindings for llama.cpp. `llama

Previous Page 5 of 6 Next