Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability

flowise-components View details

PraisonAI Vulnerable to OS Command Injection

CVSS 9.7 PraisonAI View details
CVE CRITICAL CVE-2026-44336

PraisonAI MCP `tools/call` path-traversal => RCE via Python `.pth` injection

CVSS 9.6 PraisonAI View details
CVE CRITICAL CVE-2026-42074

OpenClaude Sandbox Bypass via Model-Controlled `dangerouslyDisableSandbox` Input

openclaude View details
CVE CRITICAL CVE-2024-8309

GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial of service

CVSS 9.8 langchain View details
CVE CRITICAL CVE-2024-7042

langchain-ai/langchainjs versions 0.2.5 and all versions with this class allows for prompt injection, leading to SQL injection. This vulnerability permits unauthorized data manipulation, data exfiltration, denial of service

CVSS 9.8 langchain View details
CVE CRITICAL CVE-2024-12366

PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that can lead to Remote Code Execution (RCE) instead of the intended explanation

CVSS 9.8 pandasai View details
CVE CRITICAL CVE-2026-45311

DeepSeek TUI: run_tests Tool Enables RCE via Malicious Repository

CVSS 9.6 deepseek-tui View details
CVE CRITICAL CVE-2026-41265

from the lack of proper sandboxing when evaluating an LLM generated python script. Using prompt injection techniques, an unauthenticated attacker with the ability to send prompts to a chatflow using

CVSS 9.8 flowise View details
CVE CRITICAL CVE-2026-41264

Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability

CVSS 9.8 flowise-components View details
CVE CRITICAL CVE-2024-58351

sandbox escape, denial of service by crashing the server, server-side request forgery, prompt injection, and server

CVSS 9.8 Flowise View details
CVE CRITICAL CVE-2023-29374

LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via the Python exec method

CVSS 9.8 langchain View details
CVE CRITICAL CVE-2026-30741

OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbitrary code via a Request-Side prompt injection attack

CVSS 9.8 openclaw View details
CVE CRITICAL CVE-2026-28451

function and markdown image processing. Attackers can influence tool calls through direct manipulation or prompt injection to trigger requests to internal services and re-upload responses as Feishu media

CVSS 9.3 openclaw View details
CVE CRITICAL CVE-2026-27966

result, an attacker can execute arbitrary Python and OS commands on the server via prompt injection, leading to full Remote Code Execution (RCE). Version 1.8.0 fixes the issue

CVSS 9.8 langflow View details
CVE CRITICAL CVE-2025-46059

langchain-ai v0.3.51 was discovered to contain an indirect prompt injection vulnerability in the GmailToolkit component. This vulnerability allows attackers to execute arbitrary code and compromise the application

CVE CRITICAL CVE-2026-25879

Langroid has Prompt to SQL Injection, Leading

CVSS 9.8 langroid View details
CVE CRITICAL CVE-2023-32785

Langchain SQL Injection vulnerability

CVSS 9.8 langchain View details

npm PraisonAI AgentOS exposes unauthenticated agent listing and invocation

CVSS 9.4 praisonai View details
CVE CRITICAL CVE-2026-47392

PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak

CVSS 9.9 PraisonAI View details
Page 1 of 2 Next