Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack
PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked. Attackers can submit single
Prompt injection vulnerability in 1millionbot Millie chatbot that occurs when a user manages to evade chat restrictions using Boolean prompt injection techniques (formulating a question in such a way that
JSONalyzeQueryEngine` in the run-llama/llama_index repository allows for SQL injection via prompt injection. This can lead to arbitrary file creation and Denial-of-Service (DoS) attacks. The vulnerability affects
server CORS wildcard + auth-off-by-default enables CSRF graph exfiltration and persistent indirect prompt injection
Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains
PraisonAIAgents: Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False
mcp-atlassian: Arbitrary file read via missing path validation in
PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web
auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped
AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator
@mobilenext/mobile-mcp: Arbitrary Android Intent Execution via mobile_open_url
Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks
auth-fetch-mcp: SSRF and disk exfiltration via unvalidated auth
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding
Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base
PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters
malicious repository containing prompt template files that, when the workspace was opened in Theia, replaced the AI's system instructions with attacker-controlled content (indirect prompt injection). Combined with other
agent, would cause the agent to follow attacker-controlled instructions (indirect prompt injection). Combined with other AI chat features available in untrusted workspaces, this enabled attack