Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 491 threats

mcpinsecure-defaultshell-execcommand-injectionrcestdiollm-tool-abuseASI05 · Unsafe Code ExecutionAML.T0053AML.T0011Surface: Tool LayerPropagation: Single Hop

mcp-shell, an MCP server that exposes shell command execution to LLM agents, ships with security disabled by default and the documented installation steps never enable it. As a result, any LLM or agent connected to a default deployment can run arbitrary OS commands as the mcp-shell process user, giving effectively unrestricted remote code execution through a trusted tool interface. The issue is fixed in version 0.6.0.

sympyparse_exprrcetool-verificationmulti-tenantself-signupapi-key-abusellm-verification-infraASI05 · Unsafe Code ExecutionAML.T0011AML.T0053Surface: Tool LayerPropagation: Single Hop

QWED, an infrastructure component used to verify LLM/agent tool outputs and math expressions before production execution, passes untrusted expressions directly to SymPy's parse_expr() without restricting namespaces, allowing arbitrary Python code execution in the API server. Because signup and API key issuance are open by default, any external attacker can register a tenant, obtain a valid API key, and trigger remote code execution via the math verification endpoints, fully compromising the server and other tenants in shared deployments.

MCPpath-traversalarbitrary-file-writeindirect-prompt-injectionbrowser-automationplaywrightorigin-fence-bypassrceASI05 · Unsafe Code ExecutionAML.T0051AML.T0053Surface: Tool LayerPropagation: Single Hop

browse-mcp, an MCP server that gives agents headless-browser capabilities, fails to validate caller-controlled save paths in its browser_download, browser_save_state, and browser_load_state tools, allowing arbitrary file writes anywhere the process can reach. An attacker who controls a webpage the agent visits can use indirect prompt injection to steer the agent into writing attacker-controlled content to sensitive locations like ~/.bashrc or cron files, potentially achieving full host code execution. A separate flaw in the force_fetch fallback also bypasses the configured origin allowlist entirely.

network-deviceauthorization-bypasssyslogremote-exploitedge-deviceDrayTek

Multiple DrayTek VigorSwitch models are affected by a set of unauthorized operation vulnerabilities in syslog-related functions caused by missing authorization checks. A remote, unauthenticated attacker can send crafted requests to modify device configuration, restart services, alter startup configuration, or clear logs, potentially leading to persistent network manipulation, denial of service, or evidence destruction.

network-appliancecommand-injectionpre-authrceedge-devicecritical-infrastructure

A critical pre-authentication command injection vulnerability affects multiple DrayTek VigorSwitch models, allowing remote attackers to execute arbitrary commands with root privileges without any credentials. Given the CVSS score of 9.8 and the device's role as network infrastructure, this flaw poses an immediate risk of full network compromise. Organizations using DrayTek switches at network edges should treat this as an urgent patching priority.

authentication-bypassprivilege-escalationnetwork-device-managementrconfigunauthenticated-rce-pathagent-relevant

rConfig versions 8.0.0 before 8.2.13 contain a critical authentication bypass flaw allowing unauthenticated attackers to self-register accounts that are automatically granted full Administrator privileges. This grants access to stored network device credentials, user data, and API tokens, effectively giving attackers full control over managed network infrastructure.

router-exploitrceunauthenticatedfirmware-vulnerabilityiotnetwork-infrastructurebuffer-overflow

A critical unauthenticated remote code execution vulnerability affects Netis NC63 router firmware through V3.0.0.3327, allowing attackers to gain root access via a crafted HTTP request to the device's web management interface. The vulnerability requires no authentication and no user interaction, making it highly exploitable for mass scanning and botnet recruitment. With a CVSS score of 9.8, this represents a severe risk to any network-edge device running the vulnerable firmware.

iotrouterauthentication-bypassunpatchedpublic-exploitnetwork-infrastructure

A critical authentication bypass vulnerability exists in EFM ipTIME T24000M routers (up to firmware 14.20.0) affecting the httpcon_check_session_url function within the Session Validation Handler. The flaw allows remote attackers to bypass authentication without credentials, and a public exploit is already available. The vendor has not responded to disclosure attempts, leaving affected devices unpatched and exposed.

oraclehttp-serverweblogicaccess-controlkevcisaexploited-in-the-wildagent-relevant

CVE-2026-21962 is an actively exploited improper access control vulnerability in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in that allows unauthorized creation, deletion, or modification of critical data, as well as unauthorized full access to server-accessible data. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog with a short remediation window, indicating active in-the-wild exploitation and high urgency for patching.

entra-ididentityazure-admicrosoftcvss-10privilege-escalationagent-relevant

Microsoft patched a maximum-severity (CVSS 10.0) vulnerability in Entra ID, its cloud identity and access management platform, that could allow remote code execution or full identity compromise. Microsoft initially flagged the flaw as exploited in the wild but later corrected this to confirm no active exploitation occurred prior to disclosure. The vulnerability's severity stems from Entra ID's central role in authentication for Microsoft 365, Azure, and third-party enterprise applications.

gitlabcode-injectionactive-exploitationunauthenticatedci-cdsource-code-managementagent-relevant

A critical unauthenticated code injection vulnerability in GitLab (CVE-2026-19478, CVSS 9.4) is being actively exploited in the wild within days of public disclosure. The flaw allows attackers to modify or delete publicly accessible GitLab projects and rewrite repository data without authentication, posing severe risk to source code integrity and CI/CD pipeline trust.

prototype-pollutionnodejsnpmsupply-chainexceljsagent-relevantRAGjson-parsing

A critical prototype pollution vulnerability exists in exceljs-hardened versions prior to 5.0.0, where the deepMerge helper fails to sanitize dangerous keys (__proto__, constructor, prototype) when merging cell note objects. Attackers can craft malicious spreadsheet or JSON input to pollute Object.prototype, potentially leading to remote code execution, denial of service, or security bypass in downstream application logic.

xsssanitizer-bypasshtml-parsingmarkdownsupply-chainnodejs-libraryrag-pipelineagent-relevant

justhtml versions up to 1.11.0 fail to escape angle brackets when converting parsed HTML to Markdown via to_markdown(), allowing untrusted HTML content (including entity-decoded text and content from RCDATA/RAWTEXT elements like <title>, <textarea>, <noscript>) to be emitted as raw, executable HTML in Markdown output. This creates a sanitizer bypass that can lead to stored or reflected cross-site scripting when the resulting Markdown is later rendered as HTML. The vulnerability is fixed in version 1.12.0.

xsshtml-sanitizationlibrary-vulnerabilityweb-securityinput-validationagent-relevantrag-pipelinellm-tooling

justhtml versions before 1.16.0 contain multiple sanitization bypass flaws that can allow malicious script/style content to survive HTML sanitization, potentially enabling cross-site scripting. The issues mainly affect advanced usage patterns such as reused/mutated policy objects, programmatic DOM input, and custom SVG/MathML-preserving policies rather than the default sanitize=True parsing path.

buffer-overflowrouteriotweb-managementremote-code-executionpublic-exploit

A critical stack-based buffer overflow vulnerability affects the Web Management interface of Comfast CF-N1-S wireless routers version 2.6.0.1, exploitable remotely via the NTP timezone configuration endpoint. The exploit code is publicly available, significantly increasing the likelihood of active exploitation, and successful attacks could allow full device compromise.

cisconetwork-managementcrossworksecure-workloadcvss-10patch-tuesdaynetwork-infrastructure

Cisco has released patches addressing nine vulnerabilities across its Crosswork platforms and Secure Workload software, five of which carry the maximum CVSS score of 10.0. These flaws affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning regardless of device configuration, posing significant risk to network orchestration infrastructure.

wordpressplugin-vulnerabilityphp-object-injectionunauthenticateddeserializationpop-chainweb-application-security

The WS Form LITE WordPress plugin (versions up to 1.10.80) contains a PHP Object Injection vulnerability caused by insecure deserialization of untrusted form submission meta values. While no exploitable POP (Property-Oriented Programming) chain exists within the plugin itself, the presence of a vulnerable POP chain in any other installed plugin or theme could enable unauthenticated attackers to achieve file deletion, data exfiltration, or remote code execution.

iotrouterbuffer-overflowremote-code-executiontrendnetcgiunauthenticatedpublic-exploit

A critical stack-based buffer overflow vulnerability exists in TRENDnet TEW-821DAP routers (firmware 2.2.01b05) within the NTP Timezone Configuration Handler's uci_safe_get function. The flaw is remotely exploitable without authentication via manipulated CGI parameters, and a public exploit is already available, making immediate exploitation likely.

wordpressssrfplugin-vulnerabilityaccount-takeovermailguncve-2026-78003unauthenticated

The Mailgun for WordPress plugin (versions up to 2.2.0) contains an unauthenticated SSRF vulnerability caused by insufficient input validation in the add_list() function. Attackers can leverage this flaw to make authenticated requests to any Mailgun API endpoint using the site's stored API key, enabling creation of email-forwarding rules that intercept password reset emails and result in full administrator account takeover.

IBMAIXPowerVMVIOSprivilege-escalationRCEunixcritical-infrastructure

A critical vulnerability (CVE-2026-17145) affects IBM AIX versions 7.2 and 7.3, as well as IBM PowerVM VIOS 4.1, allowing a remote, unauthenticated attacker to execute arbitrary code due to improper privilege management. With a CVSS score of 9.8, this flaw poses severe risk to enterprises running IBM Power systems, potentially enabling full system compromise. Organizations using these platforms for critical workloads, including hosted virtualized environments, should prioritize patching.