Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 499 threats

hard-coded-credentialslangflowagent-frameworkauthentication-bypassdefault-secretscveASI04 · Agentic Supply ChainAML.T0043AML.T0012Surface: Supply ChainPropagation: Single Hop

IBM Langflow, a popular open-source visual builder for LLM/agent workflows, ships with hard-coded credentials (password or cryptographic key) used for inbound authentication, outbound service communication, or internal data encryption. Because these secrets are static and embedded in the codebase across versions 1.0.0-1.10.1, any attacker who knows or extracts them can authenticate as a legitimate component, decrypt protected data, or impersonate trusted internal services. The maximum CVSS score of 9.8 reflects the potential for full compromise of confidentiality, integrity, and availability with low attack complexity and no privileges required.

path-traversalarbitrary-file-writelangflowapirequestcontent-dispositionunsanitized-inputagent-tool-componentssrf-adjacentASI05 · Unsafe Code ExecutionAML.T0010AML.T0048Surface: Tool LayerPropagation: Single Hop

Langflow's APIRequest component, when its 'Save to File' feature is enabled, trusts filenames supplied by an external HTTP server's Content-Disposition header without sanitizing them. A malicious or compromised remote endpoint can inject path traversal sequences to write arbitrary files outside the intended temporary directory, potentially leading to full remote code execution on the host running the agent flow.

langflowprivilege-escalationdatabase-manipulationagent-frameworkrcecve-2026-8635ASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: Single Hop

IBM Langflow versions 1.0.0 through 1.10.0 contain a critical vulnerability allowing any authenticated user to escalate privileges to superuser by directly manipulating the underlying database. This grants attackers full control over the Langflow service, enabling arbitrary system command execution and complete system compromise. Given Langflow's role as an agent orchestration/flow-building platform, this is a severe supply-chain and framework-level risk for any AI agent pipelines built on it.

wordpressrcepublic-exploitcmsweb-applicationpatch-nowagent-relevant

Public exploit code has been released for critical remote code execution vulnerabilities dubbed "wp2shell" affecting WordPress Core, significantly increasing the risk of widespread exploitation. Administrators are urged to patch immediately as attackers can now leverage readily available exploit tooling to compromise unpatched sites.

langflowrceexecunsandboxed-code-executionagent-frameworkauthenticated-rceai-pipeline-builderASI05 · Unsafe Code ExecutionAML.T0011AML.T0053Surface: Tool LayerPropagation: Single Hop

IBM Langflow, an open-source visual builder for AI agent/LLM workflows, contains a critical remote code execution flaw in its code validation API. Any authenticated user can submit Python code that is run directly via exec() with no sandboxing, granting them full control over the server process. Given a 9.9 CVSS score, this is a near-maximum severity issue requiring immediate patching or mitigation.

pickledeserializationrcelangflowagent-frameworkcache-poisoningcve-2026-8476ASI05 · Unsafe Code ExecutionAML.T0010AML.T0011Surface: Tool LayerPropagation: Single Hop

IBM Langflow's disk caching component deserializes cached objects using Python's unsafe pickle.loads() without any validation or authentication. An attacker who can influence cache contents—via crafted workflow inputs, custom components, or API calls—can trigger arbitrary code execution with the privileges of the Langflow server, leading to full system compromise.

xssibmai-hubweb-vulnerabilityagent-relevantinjectionrce-potential

A critical cross-site scripting (XSS) vulnerability affects IBM Engineering AI Hub versions 1.0.0, 1.1.0, and 1.2.0, allowing remote attackers to inject and execute arbitrary scripts through improperly sanitized web page generation. Given the high CVSS score of 9.3, successful exploitation could lead to session hijacking, credential theft, and unauthorized actions performed in the context of authenticated users, including administrators.

sql-injectionweb-applicationunauthenticateddata-breachlaboratory-systems

A critical unauthenticated SQL injection vulnerability affects GisLab Laboratory Management System versions 1.4.03 through 08072026, allowing attackers to manipulate backend database queries. With a CVSS score of 9.8, this vulnerability could enable full database compromise, data exfiltration, or destruction without requiring valid credentials.

authentication-bypasspassword-reset-flawcve-2026-12692enterprise-softwareunauthenticated-access

CVE-2026-12692 is a critical unverified password change vulnerability in Vimesoft Inc.'s Enterprise Video Platform, allowing attackers to bypass authentication by resetting user passwords without proper verification. With a CVSS score of 9.8, this flaw could allow full account takeover, including administrative accounts, with minimal attacker effort. Organizations running affected versions (3.11.0.0 to before 3.25.0) should treat this as an urgent patching priority.

langflowmcpremote-code-executionconfig-validationibmagent-frameworkASI04 · Agentic Supply ChainSurface: Tool LayerPropagation: Single Hop

IBM Langflow versions 1.0.0 through 1.10.0 contain a vulnerability allowing remote code execution due to incomplete validation of MCP server configuration files. An attacker who can supply or modify an MCP server config could execute arbitrary code on the Langflow host, fully compromising the agent runtime and any connected tools or data.

langflowrcedenylist-bypassunauthenticatedagent-componentscodeactagentcsvagentopendsstaragentASI05 · Unsafe Code ExecutionAML.T0011AML.T0053Surface: Tool LayerPropagation: Single Hop

IBM Langflow OSS versions 1.0.0 through 1.10.1 expose a public flow build endpoint that allows unauthenticated remote code execution due to an incomplete security denylist. Attackers can construct flows using code-execution-capable agent components (OpenDsStarAgent, CodeActAgentSmolagents, CSVAgent) that are not blocked by the validation function, achieving arbitrary code execution without any authentication.

wordpressrceunauthenticatedcmsweb-vulnerabilityagent-relevant

A critical unauthenticated remote code execution vulnerability, dubbed wp2shell, was discovered in WordPress core affecting versions 6.9 and 7.0, exploitable via a single anonymous HTTP request even on default installs with no plugins. WordPress released patched versions 6.9.5 and 7.0.2 and pushed forced auto-updates to mitigate mass exploitation. Researcher Adam Kues of Assetnote (Searchlight Cyber) discovered and reported the flaw.

wordpressplugin-vulnerabilityprivilege-escalationunauthenticatedcmsweb-application

The Bricksforge WordPress plugin (versions up to 3.1.8.6) contains a critical privilege escalation flaw in its Pro Forms registration action. Improper validation of the fieldIds parameter allows unauthenticated attackers to whitelist arbitrary form fields, including the administrator role field, enabling full site takeover via crafted registration requests.

langflowtoolguardcode-injectionmcpcross-tenantprivilege-escalationagent-frameworkASI05 · Unsafe Code ExecutionAML.T0051AML.T0053Surface: Tool LayerPropagation: Single Hop

IBM Langflow contains a vulnerability where its ToolGuard security policy fails to validate dynamically generated Python code fields, allowing attackers with flow creation privileges to inject and execute arbitrary code on the backend despite custom component restrictions being disabled. The flaw is worsened by an MCP tool that accepts attacker-controlled user IDs, enabling cross-tenant injection into other users' flows, and can require little to no authentication under common misconfigurations.

langflowauthentication-bypassauto-logincorsprivilege-escalationagent-frameworkdefault-configASI02 · Tool MisuseSurface: Human InterfacePropagation: Single Hop

Langflow, a widely used low-code framework for building AI agent workflows, ships with an AUTO_LOGIN feature enabled by default that issues long-lived superuser bearer tokens to any unauthenticated network requester hitting a specific login endpoint. Combined with permissive CORS settings, this allows a remote attacker with no credentials to obtain full administrative control over the Langflow instance, including any agents, flows, and connected tools/credentials it manages. This is a critical, actively exploitable misconfiguration in a default deployment rather than a subtle logic flaw.

langflowunauthenticated-accessaccount-creationrcemisconfigurationagent-frameworkASI08 · Cascading FailuresSurface: Tool LayerPropagation: Single Hop

IBM Langflow OSS versions 1.0.0-1.10.0 allow unauthenticated attackers to register new user accounts that, under the common NEW_USER_IS_ACTIVE=true configuration, are immediately active without admin approval. This lets attackers authenticate and reach code-execution endpoints, effectively bypassing intended access controls even when AUTO_LOGIN is disabled. Given the critical CVSS score of 9.8, this is a genuine and severe vulnerability requiring urgent patching.

langflowunauthenticated-rceauth-bypassexec-abuseagent-frameworkdefault-deploymentASI01 · Goal HijackingAML.T0011AML.T0048Surface: Tool LayerPropagation: Single Hop

IBM Langflow versions 1.0.0 through 1.10.0 contain a critical vulnerability chain allowing any unauthenticated network attacker to obtain superuser credentials and execute arbitrary code on the server. This affects default deployments of a widely used AI agent-building platform, giving attackers full control of the host and any connected agent workflows, data, or credentials.

MCPGitHub ActionsCI/CDRCEsecrets-exfiltrationpull-requestsupply-chainClaude CodeASI04 · Agentic Supply ChainAML.T0051AML.T0010Surface: Tool LayerPropagation: Single Hop

Claude Code Action, prior to version 1.0.74, checked out attacker-controlled pull request branches and blindly loaded and enabled any MCP servers defined in a PR's .mcp.json file. This allowed an external attacker to open a malicious pull request that, once processed by the Claude Code action, achieved arbitrary code execution on the GitHub Actions runner and exfiltrated CI secrets such as API keys and tokens.

MCPRCEcommand-injectionLiteLLMagent-frameworkunsanitized-inputserver-configASI05 · Unsafe Code ExecutionAML.T0011AML.T0053Surface: Tool LayerPropagation: Single Hop

LiteLLM 1.18.10 allows any user who can submit MCP server configuration JSON to specify arbitrary OS commands and arguments that are executed unvalidated on the host. This gives an attacker remote code execution with the privileges of the LiteLLM process, a critical risk given the 9.8 CVSS score and the ease of exploitation.

MCPcommand-injectionexecSyncagent-orchestrationtool-poisoningRCEagentic-flowASI05 · Unsafe Code ExecutionAML.T0053AML.T0011Surface: Tool LayerPropagation: Single Hop

Agentic-Flow's MCP server tools passed user- and agent-supplied parameters (agent, task, name, language, agentdb) directly into shell commands via execSync() without sanitization, enabling arbitrary OS command execution. Any client, upstream agent, or automated caller able to invoke these MCP tools could achieve full remote code execution at the privilege level of the MCP server process. This is a critical, unauthenticated-adjacent injection flaw affecting core orchestration and swarm tooling.