Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack

CVSS 8.3 flowise-components View details

PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked. Attackers can submit single

CVSS 7.5 praisonai View details

Prompt injection vulnerability in 1millionbot Millie chatbot that occurs when a user manages to evade chat restrictions using Boolean prompt injection techniques (formulating a question in such a way that

JSONalyzeQueryEngine` in the run-llama/llama_index repository allows for SQL injection via prompt injection. This can lead to arbitrary file creation and Denial-of-Service (DoS) attacks. The vulnerability affects

CVSS 7.1 llamaindex View details

server CORS wildcard + auth-off-by-default enables CSRF graph exfiltration and persistent indirect prompt injection

Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains

CVSS 7.1 flowise-components View details

PraisonAIAgents: Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False

CVSS 7.4 praisonaiagents View details

mcp-atlassian: Arbitrary file read via missing path validation in

CVSS 7.7 mcp-atlassian View details

PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web

CVSS 8.8 praisonaiagents View details

auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped

CVSS 7.4 auth-fetch-mcp View details

AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator

@agenticmail/openclaw View details

@mobilenext/mobile-mcp: Arbitrary Android Intent Execution via mobile_open_url

CVSS 8.3 @mobilenext/mobile-mcp View details

Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks

CVSS 7.5 langchain View details

auth-fetch-mcp: SSRF and disk exfiltration via unvalidated auth

CVSS 8.2 auth-fetch-mcp View details

Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding

CVSS 8.3 serena-agent View details

Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base

CVSS 7.5 open-webui View details

PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters

CVSS 8.1 praisonaiagents View details

malicious repository containing prompt template files that, when the workspace was opened in Theia, replaced the AI's system instructions with attacker-controlled content (indirect prompt injection). Combined with other

@theia/ai-editor View details

agent, would cause the agent to follow attacker-controlled instructions (indirect prompt injection). Combined with other AI chat features available in untrusted workspaces, this enabled attack

@theia/ai-ide View details

Open WebUI: Cross-origin postMessage confirmation bypass via action:submit

open-webui View details
Page 1 of 4 Next