Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 1522 threats

defensive-researchprivilege-separationprompt-injection-mitigationagent-architecturecontext-isolationSWE-benchAgentDojoDecodingTrust-AgentASI01 · Goal HijackingAML.T0051Surface: PlannerPropagation: None

This item is a defensive research paper proposing 'Twin Agent,' an architecture that splits an LLM agent into an untrusted-context-inspecting 'Explore Agent' and a privileged 'Safe Agent' to mitigate prompt injection attacks. It does not describe an active exploit, vulnerability, or attack technique; it is a mitigation proposal evaluated on standard agent security benchmarks. Severity is set to low because no genuine threat is described here, only a countermeasure.

researchpentestingreconnaissanceindirect-prompt-injectionagent-profilingred-team-toolingbenchmarkASI01 · Goal HijackingAML.T0043AML.T0051Surface: PlannerPropagation: None

This is an academic research paper describing a defensive/offensive-research framework (KYA) that automates reconnaissance of AI agents to build target profiles and craft stronger indirect prompt injection attacks. It is not an active exploit or in-the-wild threat, but it formalizes a methodology that could be repurposed by attackers to more efficiently discover and exploit agent weaknesses. Severity is medium because it is a dual-use research contribution rather than a confirmed live attack campaign.

n8nprototype-pollutionsandbox-escapevm-sandboxworkflow-automationdenial-of-serviceexpression-engineASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: Single Hop

An authenticated n8n user can craft a workflow expression that escapes the VM expression engine's sandbox by abusing array-element access to reach a host built-in object, then pollute its prototype in the main process. This causes a denial of service affecting the entire n8n instance, impacting both self-hosted and cloud deployments. n8n has patched the issue and users should upgrade immediately.

path-traversalsandbox-escapen8ncomputer-usefile-searcharbitrary-file-readai-agent-toolASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: Single Hop

The @n8n/computer-use file-search tool used by AI agent workflows in n8n failed to properly confine search patterns to a designated base directory, allowing crafted inputs to escape the sandbox and read arbitrary files accessible to the daemon's OS user. This affects any deployment where an untrusted actor or agent-driven input could influence the search query, resulting in local file disclosure outside the intended scope. The issue has been patched in n8n 2.31.5 and 2.32.1.

n8nworkflow-automationpermission-bypassexternal-secretsexpression-injectionauthorization-flawagent-workflow-platformASI04 · Agentic Supply ChainSurface: Tool LayerPropagation: None

A validation/runtime mismatch in n8n's workflow automation platform lets an authenticated user without the `externalSecret:list` permission smuggle external secret references into credential fields that bypass static checks but still resolve at execution time. This allows unauthorized users to indirectly exfiltrate secret values they should not have access to, undermining the platform's Advanced Permissions model. Severity is moderate since it requires authenticated access with credential-editing rights and a specific configuration (external secrets provider plus Advanced Permissions enabled).

n8nsql-injectionworkflow-automationwebhookunsanitized-inputlegacy-nodemysqlASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: Single Hop

A legacy MySQL node in the n8n workflow automation platform builds raw SQL queries by directly interpolating expression-evaluated values instead of using parameterized queries. When such a workflow is triggered by an externally reachable input like a webhook, an attacker can inject SQL to read, modify, or delete data via the configured database credentials.

n8nsecrets-managementprivilege-escalationworkflow-automationaccess-controlexternal-secretsASI04 · Agentic Supply ChainSurface: Tool LayerPropagation: None

A vulnerability in n8n allows authenticated users with only project editor access to read plaintext external secrets by referencing them directly in node expressions, bypassing the intended secrets access permission model. This affects instances that have the external secrets feature configured, potentially exposing sensitive credentials to users who should not have access to them. The issue has been patched in n8n 2.27.4 and 2.28.1.

n8nworkflow-automationauthorization-bypassidormulti-tenantfolder-permissionsASI08 · Cascading FailuresSurface: Tool LayerPropagation: None

A logic flaw in n8n's workflow automation platform allows an authenticated user to craft a request that associates their newly created workflow with a folder belonging to a different, unauthorized project. The workflow itself stays private to the attacker's project and no cross-project data is exposed, limiting the impact to a database-level integrity issue in folder structure. This is a traditional web application IDOR/authorization bug rather than an AI-agent-specific exploit, though n8n is increasingly used to orchestrate AI agent workflows.

n8ndenial-of-servicedisk-exhaustionworkflow-automationquota-bypassauthenticated-abuseASI08 · Cascading FailuresSurface: Tool LayerPropagation: None

An authenticated n8n user can repeatedly abuse the data-table file upload endpoint to bypass per-request quota checks, causing temporary files to accumulate on disk faster than cleanup can remove them. This can exhaust host disk space, leading to a denial-of-service condition affecting the n8n instance and potentially other services on the same host. This is a genuine, moderate-severity resource exhaustion flaw rather than a novel agentic-AI attack, but it is directly relevant to n8n's growing role as an orchestration layer for AI agent workflows.

residential-proxyiotsmart-tvwebosproxywareprivacyconsumer-device-abuse

Researchers found that over 42% of apps on LG's webOS smart TV store secretly embed residential proxy SDKs, allowing unknown third parties to route their internet traffic through consumers' TVs without clear consent. LG has announced it will ban apps that turn smart TVs into always-on residential proxy nodes. This practice exposes users' home IP addresses and bandwidth to potentially malicious or anonymized traffic routed by unknown actors.

browser-extensionadobe-acrobatwhatsapp-webcross-origindata-exposurechrome-extensionprivacy

A now-patched vulnerability chain in the Adobe Acrobat Chrome extension, dubbed HermeticReader by Guardio Labs and tracked as CVE-2026-48294, could allow malicious websites to silently read a user's WhatsApp Web data. The extension, installed by over 314 million users, contained a flaw that broke cross-origin isolation, enabling covert hijacking of session data without user interaction.

linuxprivilege-escalationubuntusnaplpeagent-relevant

A high-severity local privilege escalation vulnerability in Ubuntu's snap-confine component allows an unprivileged local user to gain full root access on default Ubuntu Desktop installations. The flaw affects Ubuntu Desktop 24.04, 25.10, and 26.04 out of the box, making it a significant risk for any multi-user or shared Linux host.

bug-bountypolicy-changegithubvulnerability-disclosureindustry-news

GitHub announced it will cut public bug bounty payouts by at least half across all severity levels starting July 27, 2026, while introducing a permanent invite-only VIP tier that retains higher payouts of $30,000 or more. Reports already submitted or in GitHub's triage queue before that date will honor the previous payout structure.

ransomwareextortionsupply-chainthird-party-riskmanufacturingrail-industryEverest-gang

Swiss rail vehicle manufacturer Stadler Rail was targeted by the Everest ransomware gang, which breached a data exchange platform shared with one of its suppliers and demanded a $12.3 million ransom. Stadler rejected the demand, indicating the attack likely originated through a third-party or supplier-connected system rather than Stadler's core infrastructure.

data-breachgovernmentespionagesouth-koreacredential-theftdiplomatic-targeting

South Korea's Ministry of Foreign Affairs disclosed that attackers breached the National Diplomatic Academy's online education system, maintaining unauthorized access for approximately ten months. The compromise resulted in theft of personal information belonging to current and former MFA employees, including overseas diplomats, raising concerns about follow-on espionage and social engineering targeting diplomatic personnel.

data-breachfraudfintechidentity-theftPII-exposure

Upbound Group, the parent company of fintech lease-to-own provider Acima, disclosed that attackers who stole customer data from its systems used that information to fraudulently generate $13 million in Acima lease agreements. The incident highlights how stolen PII and account data can be weaponized for downstream financial fraud beyond the initial breach.

ICSOTPAN-OSSiemensRUGGEDCOMcommand-injectionprivilege-escalationXSScritical-infrastructure

Siemens RUGGEDCOM APE1808 devices running Palo Alto Networks Virtual NGFW are affected by three vulnerabilities disclosed upstream in PAN-OS, including stored XSS, missing authorization leading to privilege escalation, and OS command injection allowing root-level code execution. Exploitation requires authenticated administrative access, which limits attack surface but still poses significant risk in industrial control system environments if management interfaces are exposed or misconfigured. Siemens recommends contacting customer support for patches and following standard ICS network isolation best practices.

icsscadasiemensprivilege-escalationunquoted-search-pathvulnerability-disclosure

Multiple Siemens industrial and engineering software products bundling the IAM Client SDK are affected by an untrusted/unquoted search path vulnerability that could allow an authenticated local attacker to escalate privileges. Siemens has released patched versions for most affected products and recommends updating as soon as possible, with fixes pending for remaining products.

CISAKEVCheck PointSmartConsoleSharePointdeserializationauthentication-bypassactive-exploitationfederal-agenciesagent-relevant

CISA has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog: an improper authentication flaw in Check Point SmartConsole (CVE-2026-16232) and a deserialization of untrusted data vulnerability in Microsoft SharePoint (CVE-2026-50522). Both are confirmed to be exploited in the wild, prompting mandatory remediation timelines for FCEB agencies under BOD 26-04 and a strong recommendation for all organizations to patch immediately.

oracleunauthenticated-rcenetwork-exploitablecvss-9.8testing-infrastructure

A critical unauthenticated remote code execution vulnerability affects Oracle Application Testing Suite version 13.3.0.1, allowing attackers with mere network access to fully compromise the system without any credentials or user interaction. The flaw carries a maximum-impact CVSS score of 9.8, threatening confidentiality, integrity, and availability, and is trivially exploitable, making it a high-priority patching target.