Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 499 threats

kubernetesopenshiftacmprivilege-escalationcommand-injectionsql-injectionrcepostgresagent-relevant

A critical injection vulnerability in Red Hat Advanced Cluster Management's acm-search-v2-rhel9 component allows authenticated users, including hub administrators or Search Custom Resource editors, to execute arbitrary shell commands and SQL statements. The flaw stems from improper validation of the WORK_MEM string in the Search CR before it is embedded in a bash script and SQL query, enabling code execution within the privileged postgres pod.

macOSauthentication-bypassscreen-sharingremote-accessCISA-KEVagent-relevant

CVE-2026-65400 is an improper authentication vulnerability in Apple macOS that allows a network-based attacker to authenticate to Screen Sharing without valid credentials. The flaw has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. Organizations running macOS with Screen Sharing enabled face an urgent risk of unauthorized remote access.

CISA-KEVRCEwindowsIKEIPsecVPNnetwork-servicedouble-freeagent-relevant

CVE-2026-33824 is a double free vulnerability in Microsoft's Internet Key Exchange (IKE) Service Extensions that can be exploited remotely to achieve code execution. It has been added to CISA's Known Exploited Vulnerabilities catalog with a short remediation window, indicating active or imminent exploitation in the wild.

MCPprompt-injectioncredential-exfiltrationdestructive-payloadtool-poisoningsupply-chaincoding-agentASI01 · Goal HijackingAML.T0051AML.T0053Surface: Tool LayerPropagation: Single Hop

Context7 (through version 2.1.2) contains a critical prompt injection vulnerability in its Custom AI Instructions feature, served via its MCP server, that lets attackers plant malicious instructions which connected coding agents automatically execute. During a routine library documentation lookup, an unsuspecting agent can be hijacked to exfiltrate credentials from environment files and delete files on the victim's machine.

argument-injectiongitmcp-toolauto-approved-toolarbitrary-file-writeprompt-injectionssh-key-overwritecodewhaleASI05 · Unsafe Code ExecutionAML.T0051AML.T0053Surface: Tool LayerPropagation: Single Hop

CodeWhale's git_show tool passes an LLM-controlled 'rev' parameter directly into git's command line without sanitization, allowing a value like '--output=~/.ssh/authorized_keys' to be interpreted as a git flag rather than a revision. Because the tool is auto-approved and marketed as read-only, a malicious repository combined with prompt injection can trick the agent into silently overwriting sensitive files with attacker-controlled content, effectively achieving persistence or account takeover at the user's privilege level. This is a critical, easily exploitable vulnerability with a working fix already available in version 0.8.64.

wordpressrceunauthenticatedfile-uploadplugin-vulnerabilityforminatorcms

A critical unauthenticated remote code execution vulnerability (CVE-2026-15748) has been disclosed in Forminator Forms, a WordPress plugin installed on over 600,000 sites. The flaw allows attackers to upload malicious PHP files without authentication, potentially leading to full site compromise. Given the plugin's massive install base, this represents a high-priority patching target for WordPress site operators.

gitlabgraphqlvulnerabilityunauthenticatedrcesupply-chainagent-relevantci-cdsource-code-management

GitLab disclosed a critical flaw (CVE-2026-19478, CVSS 9.4) in its GraphQL API affecting both Community Edition and Enterprise Edition, allowing unauthenticated attackers to remotely modify or delete public projects and user data. Organizations running self-managed GitLab instances are urged to patch immediately to prevent destructive attacks against source code repositories.

CISAKEVcode-injectionrayagent-relevantML-infrastructurefederal-mandate

CISA added CVE-2025-62593, a code injection vulnerability in Ray-Project Ray, to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. Federal agencies are required under BOD 26-04 to remediate this vulnerability on a prioritized basis due to its potential to grant full control of affected assets.

routerauthentication-bypassunpatchedpublic-exploitIoTnetwork-infrastructureno-vendor-response

A critical authentication bypass vulnerability exists in the httpcon_check_session_url function of EFM ipTIME A3004T routers (firmware 14.19.0), allowing remote attackers to circumvent session validation without credentials. A working exploit is publicly available and the vendor has not responded to disclosure, leaving affected devices permanently exposed.

routerfirmwarebuffer-overflowrceiotunpatchedpublic-exploitedimax

A critical unauthenticated remote code execution vulnerability exists in Edimax EW-7478APC routers running firmware 1.04, caused by a stack-based buffer overflow in the formWanTcpipSetup CGI handler. Public exploit code is available and the vendor has not responded to disclosure, meaning no patch is expected. Organizations using this device on network edges face significant risk of full device compromise and pivoting into internal networks.

wordpressplugin-vulnerabilityprivilege-escalationauthorization-bypasscve-2026-18432

The Frontend Admin by DynamiApps WordPress plugin (versions up to 3.29.9) contains a critical privilege escalation vulnerability caused by a flawed authorization check that can be bypassed with a non-numeric user ID value. Attackers, in some configurations even unauthenticated, can exploit this to gain administrator access by hijacking the default admin account's password or email. Given the 9.8 CVSS score and low exploitation complexity, this vulnerability poses a severe risk to any WordPress site running the affected plugin.

wordpressplugin-vulnerabilityunauthenticated-rcefile-uploadcmsweb-application-security

The ProSolution WP Client WordPress plugin (versions up to 2.0.10) contains a critical unauthenticated arbitrary file upload vulnerability that allows remote attackers to achieve remote code execution. A publicly exposed nonce combined with insufficient filename validation lets attackers bypass access controls and upload executable files directly to the server.

routeriotauthentication-bypassunauthenticated-accesspublic-exploitnetwork-perimeter

A critical improper authentication vulnerability has been identified in the httpd component of Tenda AC10 routers running firmware 16.03.10.09_multi_TDE01, specifically within the R7WebsSecurityHandler function. The flaw allows a remote, unauthenticated attacker to bypass authentication controls, and a public exploit is already available, significantly raising the likelihood of active exploitation.

agent-relevantraycode-injectionrceml-infrastructuredistributed-computingbrowser-exploitCISA-KEV

CVE-2025-62593 is a code injection vulnerability in Ray-Project Ray, a widely used distributed computing framework for scaling AI/ML and Python workloads, that can lead to remote code execution. The flaw is exploitable via Firefox and Safari when developers interact with Ray's tooling, and it has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.

SSRFMLflowwebhookmetadata-serviceredirect-bypassunauthenticatedcloud-credentialsagent-platformASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: Single Hop

An unauthenticated SSRF vulnerability exists in MLflow's webhook test endpoint that allows attackers to bypass URL validation using HTTP redirects. Attackers can craft a webhook pointing to a benign-looking URL that redirects to internal services or cloud metadata endpoints, then retrieve the response including sensitive credentials. This affects any AI agent or ML pipeline built on vulnerable MLflow versions, exposing cloud infrastructure secrets.

authentication-bypassfail-openmemosprivilege-escalationapi-key-managementunauthenticated-accessinternal-service-spoofingASI02 · Tool MisuseSurface: Tool LayerPropagation: Single Hop

MemOS, a memory operating system for LLM agents, contains a critical authentication bypass where an unset internal-service secret causes the system to treat any unauthenticated request as a trusted internal caller with full privileges. This allows remote attackers to mint admin API keys, generate master keys, and access all data and memory endpoints without credentials. The flaw is trivially exploitable and results in complete compromise of the memory layer underlying dependent AI agents.

siyuanpdf-annotationrceelectronnode-jsstored-xssagent-relevantknowledge-managementrag-pipeline

SiYuan, an open-source Electron-based note-taking and knowledge management application, fails to sanitize annotation fields written via the setFileAnnotation endpoint prior to v3.7.4. This allows an attacker to embed malicious markup that executes as script with full Node.js privileges when a victim opens an annotated PDF, enabling complete host compromise.

wordpressplugin-vulnerabilityfile-deletionrceunauthenticatedcms-security

The Link Library plugin for WordPress (versions up to 7.9.4) contains an arbitrary file deletion vulnerability caused by insufficient path validation in the ll_delete_link_fields function. When the 'Delete local file on link deletion' option is enabled, unauthenticated attackers can submit malicious links that, once deleted by an administrator during routine moderation, trigger deletion of critical files such as wp-config.php, potentially leading to full remote code execution.

wordpressplugin-vulnerabilityprivilege-escalationauthorization-bypasscmsweb-application-security

The Pods – Custom Content Types and Fields WordPress plugin (versions up to 3.3.9) contains a critical authorization bypass flaw that allows unauthenticated attackers to escalate privileges to Administrator or reset any user's password, including the site owner's. This enables complete site takeover and has been assigned a CVSS score of 9.8.

wordpressplugin-vulnerabilityaccount-takeoverunauthenticatedprivilege-escalationweb-application

The TrueBooker WordPress plugin (versions up to 1.2.6) contains a critical account takeover vulnerability due to an insecure AJAX handler that allows unauthenticated attackers to change any user's email address, including administrators. Attackers can chain this with WordPress's native password reset flow to fully hijack accounts, including full site administrator access.