CVE MEDIUM CVE-2026-47395

PraisonAI CLI automatically resolves @url mentions in prompt text and

CVSS 5.5 PraisonAI View details
CVE MEDIUM CVE-2026-40117

requires critical-level approval, read_skill_file has neither protection. An agent influenced by prompt injection can exfiltrate sensitive files without triggering any approval prompt

CVSS 6.2 praisonaiagents View details
CVE MEDIUM CVE-2026-46341

Apify Model Context Protocol (MCP) server: Domain Allowlist Bypass in

CVSS 6.1 @apify/actors-mcp-server View details
CVE MEDIUM CVE-2026-40152

PraisonAIAgents: Path Traversal via Unvalidated Glob Pattern in list_files

CVSS 5.3 praisonaiagents View details

PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent

CVSS 5.5 praisonaiagents View details
CVE MEDIUM CVE-2026-22551

from AI responses, triggering HTTP requests to arbitrary external URLs without restriction. Combined with prompt injection in a malicious workspace, an attacker could induce the AI agent to construct image

@theia/ai-ide View details
CVE MEDIUM CVE-2026-34451

prefix check that did not append a trailing path separator. A model steered by prompt injection could supply a crafted path that resolved to a sibling directory sharing the memory

@anthropic-ai/sdk View details
CVE MEDIUM CVE-2026-40112

PraisonAI is a multi-agent teams system. Prior to 4.5.128

CVSS 5.4 praisonai View details
CVE MEDIUM CVE-2026-35651

OpenClaw versions 2026.2.13 through 2026.3.24 contain an ANSI escape sequence injection vulnerability in approval prompts that allows attackers to spoof terminal output. Untrusted tool metadata can carry ANSI control sequences

CVSS 4.3 openclaw View details
CVE MEDIUM CVE-2026-45387

Open WebUI: Sharing models for others to use (read permission

CVSS 4.3 open-webui View details

TaskWeaver has Protection Mechanism Failure and Server-Side Request Forgery

CVSS 6.5 agentos-taskweaver View details
CVE MEDIUM CVE-2026-40151

PraisonAI: Unauthenticated Information Disclosure of Agent Instructions via /api/agents in

CVSS 5.3 PraisonAI View details
CVE MEDIUM CVE-2026-43901

wireshark-mcp vulnerable to arbitrary file write via export_objects

CVSS 6.8 wireshark-mcp View details

OpenClaw: Webchat audio embedding could read local files without local

OpenClaw: Agent gateway config mutations could change protected operator settings

CVE MEDIUM CVE-2026-39398

openclaw-claude-bridge: sandbox is not effective - `--allowed-tools ""` does

claude-code View details
CVE MEDIUM CVE-2024-11896

Text Prompter – Unlimited chatgpt text prompts for openai tasks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'text_prompter' shortcode in all versions

CVE MEDIUM CVE-2026-54009

Open WebUI: Cross-user file disclosure via /api/chat/completions image_url

CVSS 6.5 open-webui View details
CVE MEDIUM CVE-2026-44222

vLLM Vulnerable to Remote DoS via Special-Token Placeholders

CVSS 6.5 vllm View details
CVE MEDIUM CVE-2026-55249

@rtk-ai/rtk-rewrite transparently rewrites shell commands executed via OpenClaw

CVSS 6.3 openclaw View details
Page 1 of 2 Next