Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 491 threats

ICSVPNprivilege-escalationCRLF-injectionCWE-93CWE-306remote-code-execution

IXON VPN Client versions before 1.4.7 contain a critical CRLF injection vulnerability that allows an unauthenticated local attacker to inject configuration directives consumed by a privileged subprocess, resulting in remote code execution as root or SYSTEM. The flaw persists silently across restarts with no visible behavioral change, making detection difficult. IXON has released a patched client and blocks connections from vulnerable versions at the cloud/API level as a compensating control.

command-injectionrcezeroxpopplerdocument-processingocragent-relevantsupply-chain-risk

zerox 1.1.20, a document-to-markdown/OCR conversion library commonly integrated into AI ingestion and RAG pipelines, contains a critical OS command injection vulnerability in its file download and temporary file handling logic. An attacker can craft a malicious document URL whose derived file extension contains shell command substitution syntax, resulting in arbitrary command execution on the host before any document processing occurs.

webhookssrfauthentication-bypassagent-relevantunauthenticated-accessapi-vulnerability

xiaobei versions through 5.5.2 contain a critical vulnerability where webhook endpoints lack authentication or signature validation, allowing unauthenticated attackers to inject arbitrary messages directly into the agent pipeline. Combined with unvalidated media URL fetching, this enables server-side request forgery (SSRF) attacks against internal services, potentially exposing internal network infrastructure to external attackers.

MCPpath-traversalarbitrary-file-readarbitrary-file-writeLLM-tool-usesupply-chainagent-relevant

excel-mcp-server version 0.1.8, a Model Context Protocol (MCP) server used to give AI agents Excel file manipulation capabilities, fails to restrict file access to a designated directory when running in stdio mode without EXCEL_FILES_PATH configured. This allows an attacker-controlled or malicious tool call to read or write arbitrary files accessible to the server process, enabling data exfiltration, config tampering, or code/config injection on the host.

wordpressplugin-vulnerabilitylfiunauthenticatedrceweb-application-security

The Divi Ajax Filter plugin for WordPress (versions up to 5.1.2) contains an unauthenticated Local File Inclusion vulnerability via the 'custom_loop_template' parameter, allowing attackers to include and execute arbitrary PHP files on the server. With a CVSS score of 9.8, this flaw can lead to full remote code execution, data exposure, and access control bypass on affected WordPress installations.

buffer-overflowmemory-corruptionrcemarine-roboticsautonomous-systemsparsing-vulnerability

MOOS-IvP, an autonomous marine vehicle behavior and control framework, contains a critical buffer overflow vulnerability in its IvP function parsing logic (CVE-2026-85438). Attackers who can supply crafted BHV_IPF payloads can trigger out-of-bounds writes leading to memory corruption and potential remote code execution. This affects autonomous vehicle control software rather than typical enterprise AI agent stacks, though similar parsing patterns are common in agent tool pipelines.

SSTIjinja2unauthenticatedRCEchatbotprompt-customizationdocsgptASI02 · Tool MisuseAML.T0051Surface: Tool LayerPropagation: Single Hop

DocsGPT's custom prompt feature renders user-supplied prompt text through Jinja templates without sanitization, allowing an unauthenticated attacker to inject template expressions that execute arbitrary code on the server. This is a classic server-side template injection bug rather than a novel agent-specific attack, but because the vulnerable input is an LLM 'system prompt' customization field, it directly links prompt-engineering surfaces to full RCE. Any deployment exposing this custom prompt feature should be considered fully compromised until patched.

indirect-prompt-injectionrceunsafe-evalweb-agentbrowser-automationlavaguellm-output-trustASI01 · Goal HijackingAML.T0051AML.T0053Surface: PlannerPropagation: Single Hop

LaVague, an LLM-driven web browsing agent, contains a critical flaw where Python code extracted from LLM-generated markdown is executed without validation or sandboxing. Because the LLM's output is influenced by untrusted web page content, an attacker who controls a web page can smuggle malicious instructions that get translated into arbitrary code execution on the operator's machine. This is a textbook indirect prompt injection escalating directly to remote code execution.

citrixnetscalerauth-bypassexploited-in-the-wildedge-devicevpnremote-accessagent-relevant

A critical authentication bypass vulnerability in Citrix NetScaler (CVE-2026-19490) is being actively exploited in the wild, as reported by vulnerability intelligence firm Previdian. The flaw allows attackers to bypass authentication controls on NetScaler ADC/Gateway appliances, potentially granting unauthorized access to internal networks and sensitive resources.

icsotethernet-ipcipbuffer-overflowcritical-infrastructurecisa-advisory

A critical stack-based buffer overflow vulnerability affects Pyramid Solutions NetStaX EtherNet/IP Stack products prior to v5.6.1, used across industrial control system (ICS) devices. Exploitation via oversized Class 3 explicit-message requests could cause memory corruption, device crashes, or remote code execution without any CIP error notification, posing significant risk to critical manufacturing, energy, water, and chemical sectors.

MOOSroboticsmiddlewareauthorization-bypassnetwork-redirectionunmanned-systemsagent-relevant

A critical authorization flaw in MOOS essential-moos pShare (through 10.0.1) allows any publisher on the bus to send crafted PSHARE_CMD messages that reconfigure network routes and listeners at runtime. This enables attackers to redirect or duplicate sensitive inter-process communication traffic to attacker-controlled destinations without authentication, posing severe risks to robotics and autonomous system deployments that rely on MOOS for message passing.

authentication-bypassroboticsautonomous-systemsmaritimeunmanned-vehiclesunauthenticated-accessagent-relevant

A critical authentication bypass vulnerability exists in the optional MOOSDB HTTP server component of MOOS core-moos through version 10.4.0, allowing unauthenticated attackers to write arbitrary MOOS variables including actuator and override commands. This could enable remote attackers to hijack control of autonomous vehicles or robotic systems that rely on MOOS-IvP for mission control and coordination.

python-josejwtalgorithm-confusionkey-confusionauthentication-bypasssupply-chainrce-adjacentagent-relevant

python-jose through version 3.5.0 contains an incomplete fix for a prior key-confusion vulnerability (CVE-2024-33663), allowing attackers who possess a service's RSA/EC public key to forge valid HS256-signed JWTs when the verifying application does not explicitly restrict accepted algorithms. This enables full authentication bypass against any system relying on python-jose for JWT verification without strict algorithm allowlisting.

CORS-misconfigurationCSRFwebsocketsocket.iotaipyagent-relevantpythonunauthenticated-accessstate-manipulation

Taipy, a Python framework used to build data and AI application front-ends, ships with a Socket.IO server configuration that combines wildcard CORS origins with credentialed connections enabled. This allows any malicious webpage to establish authenticated WebSocket sessions with a victim's running Taipy application and directly invoke state changes and backend callbacks without CSRF protection, effectively granting remote attackers unauthorized control over application logic and data.

iotrouterbuffer-overflowunauthenticated-rcetotolinknetwork-device

A critical unauthenticated remote buffer overflow vulnerability has been identified in TOTOLINK CP450 4.1.0 routers, exploitable via the topicurl parameter in the /cgi-bin/cstecgi.cgi endpoint. With a CVSS score of 9.9, this flaw allows remote attackers to potentially execute arbitrary code or crash the device without authentication.

cisconexus-9000ios-xrrceunauthenticatednetwork-infrastructureroot-accessagent-relevant

Cisco disclosed a critical unauthenticated remote code execution vulnerability (CVE-2026-20212, CVSS 9.8) affecting 10 Silicon One-based Nexus 9000 switch models, allowing attackers to execute code as root without credentials. Alongside this, Cisco released an IOS XR hardening bundle addressing 7 CVEs, two rated 9.8, with no available workarounds for any affected IOS XR version, making immediate patching the only mitigation.

mozillathunderbirdfirefoxmemory-corruptionbrowser-securityemail-client

A set of internally discovered memory corruption bugs affecting Thunderbird and its ESR branches could potentially be exploited to achieve code execution. Mozilla has patched the issue across Firefox and Thunderbird release and ESR channels, and no public exploitation has been confirmed at this time.

thunderbirdfirefoxmemory-corruptionmozillabrowser-securityemail-client

Internal security research identified multiple memory corruption bugs in Thunderbird 154 that could potentially be exploited by attackers. Mozilla has patched these issues in Thunderbird 155 and Firefox 155, though no public exploitation has been confirmed. The high CVSS score reflects the potential severity if these flaws were weaponized.

browser-vulnerabilityinteger-overflowfirefoxthunderbirdmemory-corruptionrceagent-relevant

A critical integer overflow vulnerability has been identified in the Graphics: ImageLib component of Mozilla Firefox and Thunderbird, carrying a CVSS score of 9.8. The flaw could allow attackers to achieve memory corruption and potentially remote code execution through crafted image content. Mozilla has released patches in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

browser-vulnerabilitysite-isolationfirefoxthunderbirdmozillarce-potentialagent-relevant

A critical site isolation flaw in the DOM Navigation component affects Firefox, Firefox ESR, and Thunderbird, potentially allowing cross-origin data leakage or sandbox bypass. With a CVSS score of 9.8, successful exploitation could let attackers bypass browser security boundaries to access sensitive cross-site data. Mozilla has released patches in Firefox 155, Firefox ESR 153.2, and Thunderbird 155/153.2.