Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 408 threats

command-injectionrouteriotrceopenvpnunauthenticatedpublic-exploit

A critical command injection vulnerability exists in the ovpn-client.so plugin of GL.iNet GL-MT3000 routers (up to firmware 4.4.5), reachable via the /cgi-bin/glc endpoint. An attacker can remotely inject OS commands through the Hostname parameter of the get_recommend_config function, potentially achieving full device compromise. The exploit has been publicly disclosed, increasing the likelihood of active exploitation.

authentication-bypassrmmpatch-bypasscisa-kevaccount-takeovern-central

CVE-2026-18577 is an authentication bypass in N-able N-central, a widely deployed remote monitoring and management (RMM) platform, resulting from an incomplete fix for the prior vulnerability CVE-2026-18556. CISA has added this flaw to its Known Exploited Vulnerabilities catalog with an unusually short remediation window, indicating active or imminent exploitation. Successful exploitation allows attackers to bypass authentication entirely and take over accounts within N-central.

adobecampaign-classicrceauthorization-bypassunauthenticatedcritical-vulnerability

Adobe has issued an emergency patch for a maximum-severity flaw (CVSS 10.0) in Campaign Classic, its enterprise marketing automation platform, caused by incorrect authorization checks. The vulnerability allows arbitrary code execution without any user interaction, making it a high-priority target for exploitation once details or a proof-of-concept become public.

arcadedbauthorization-bypassdatabaserce-adjacenttime-seriesagent-relevant

ArcadeDB versions prior to 26.7.2 contain a critical authorization bypass vulnerability affecting HTTP handlers for time series, batch, Prometheus, and Grafana endpoints. Unauthenticated or under-privileged attackers can access and manipulate arbitrary databases by directly invoking these endpoints with crafted database parameters, bypassing intended access controls. Given the CVSS score of 9.8, this vulnerability poses a severe risk of data theft, tampering, and destruction on any exposed ArcadeDB instance.

arcadedbrceprivilege-escalationdatabasejavascript-injectionagent-relevant

ArcadeDB versions prior to 26.7.2 contain a critical authorization flaw allowing any database user to execute arbitrary JavaScript via the SQL DEFINE FUNCTION statement with LANGUAGE js, bypassing intended admin-only scripting restrictions. This effectively grants remote code execution to any actor with database access, regardless of assigned privilege level.

arcadedbrcesandbox-escapejavascript-injectionprivilege-abusedatabaseagent-relevant

ArcadeDB before version 26.7.2 contains a critical flaw in its ScriptTriggerExecutor that improperly whitelists java.lang.* packages, allowing an authenticated user with UPDATE_SCHEMA permission to craft a malicious JavaScript trigger. This trigger can invoke Java.type to access Runtime.getRuntime().exec() or ProcessBuilder, resulting in arbitrary OS command execution when the trigger fires.

authentication-bypassaccount-takeoverscimidentity-managementbetter-authssosupply-chainagent-relevant

A critical authorization bypass in the @better-auth/scim plugin allows an authenticated user to mint a SCIM token that collides with an existing SSO/SAML/OIDC/OAuth provider namespace, granting full read/write/delete access over unrelated user accounts and sessions. This enables account takeover, unauthorized profile/email rewriting, and mass deprovisioning across the identity system. Given the 9.9 CVSS score and low attack complexity, this is highly exploitable in any deployment using SCIM provisioning alongside social/SSO logins.

gitpythonpythonrcecommand-injectionsupply-chaindependency-vulnerabilityagent-relevant

GitPython 3.1.50's protection against dangerous clone options (--upload-pack/-u) can be bypassed by passing the joined short-option form -u<value>, which the default unsafe-option gate fails to detect. Applications that pass attacker-influenced values into Repo.clone_from() with allow_unsafe_options=False are still vulnerable to arbitrary command execution during the clone operation. The issue is fixed in GitPython 3.1.51.

cryptocurrencyhardware-walletweak-rngfirmware-vulnerabilitybitcoin-theftsupply-chain

A March 2021 firmware integration error in Coinkite's Coldcard hardware wallet caused seed generation to rely on a deterministic software pseudorandom number generator (PRNG) instead of proper entropy sources, producing predictable private keys. Attackers exploited this weakness to systematically drain 1,196 Bitcoin addresses, stealing 1,082.65 BTC (~$70.2 million) in just 41 minutes on July 30. Galaxy Research identified the pattern and linked the mass sweep directly to the firmware defect, exposing years of latent risk for affected wallet holders.

railsrubyactive-storagercefile-readweb-frameworkagent-relevant

A critical vulnerability in Ruby on Rails' Active Storage framework allows unauthenticated attackers to read arbitrary files from an affected application, with a potential escalation path to remote code execution. Rails maintainers have released patches, and organizations running unpatched Active Storage implementations should prioritize updates given the severity and ease of exploitation typically associated with such flaws.

shell-injectiongithub-actionsci-cdsupply-chainsecrets-exfiltrationself-hosted-runnerswazuhagent-relevant

A critical shell injection vulnerability in Wazuh's GitHub Actions workflows allows attackers to execute arbitrary commands by submitting malicious pull requests containing crafted VERSION.json files. Because affected variables are directly interpolated into shell run steps, attackers can achieve command execution and exfiltrate sensitive secrets such as GITHUB_TOKEN and AWS credentials, particularly dangerous on self-hosted runners with broader network and credential access.

freerdprdphttp-smugglingcrlf-injectionproxy-abuseremote-desktopagent-relevant

FreeRDP versions up to 3.28.0 fail to sanitize CRLF and control characters in the server-controlled TargetNetAddress field of RDP redirection PDUs. A malicious or compromised RDP server can exploit this to inject arbitrary headers or requests into the client's HTTP proxy CONNECT request, potentially enabling request smuggling, proxy authentication bypass, or lateral request injection against internal infrastructure.

FreeRDPTLScertificate-validationman-in-the-middleRDPagent-relevant

FreeRDP versions up to 3.28.0 contain multiple flaws in their custom TLS certificate identity verification logic, allowing an attacker with a trusted or misissued certificate to impersonate legitimate RDP servers. This weakens TLS server authentication and enables man-in-the-middle attacks against RDP sessions, with a critical CVSS score of 9.8.

wordpressauthentication-bypassplugin-vulnerabilityaccount-takeovercms-securitybroken-access-control

The Single Sign On For TNG WordPress plugin (versions up to 2.0.0) contains a critical authentication bypass vulnerability allowing unauthenticated attackers to reset any account's password, including administrators. Exploitation leads to complete site takeover with no user interaction or prior authentication required.

wordpressplugin-vulnerabilityunauthenticated-rcefile-deletionpath-traversalsite-takeovercms

The FormGent WordPress plugin (versions up to 1.9.2) contains a critical unauthenticated arbitrary file deletion vulnerability caused by a missing capability check on its REST API endpoint. On Linux servers, attackers can bypass path traversal protections to delete wp-config.php, forcing the site into a fresh-install state that enables full site takeover.

rcedeserializationpicklepytorchcomfyuiunauthenticatedagent-relevantai-infrastructuresupply-chain-risk

CVE-2026-68771 is a critical unauthenticated remote code execution vulnerability in ComfyUI v0.23.0, a widely used node-based interface for AI/ML pipelines including Stable Diffusion and generative workflows. Attackers can upload a malicious pickle file and trigger deserialization via the LoadTrainingDataset node, achieving arbitrary code execution as the ComfyUI process user with no authentication required.

agent-relevantrcepythonmachine-learningmodel-loadingsupply-chainhuggingfaceragllm-tooling

A critical logic flaw in the popular sentence-transformers Python library allows attackers to bypass the trust_remote_code=False safety control and achieve arbitrary code execution when a model is loaded from a local path. Because a flawed guard condition treats any existing filesystem path as implicitly trusted, malicious Python files placed inside a model directory (referenced via modules.json) will execute automatically at import time, even when developers believe they have disabled remote code execution.

azurecosmos-dbcloud-vulnerabilitysandbox-escapegremlinprivilege-escalationmulti-tenantcloud-securityagent-relevant

Security researchers at Wiz disclosed a now-patched vulnerability chain in Azure Cosmos DB, dubbed CosmosEscape, that allowed an attacker to escape the Gremlin query sandbox and obtain a platform-wide key granting full read/write access to databases across multiple customer tenants. The flaw originated from a crafted, attacker-controlled Gremlin query that achieved code execution on the underlying host, breaking multi-tenant isolation. Microsoft has remediated the issue; no evidence of in-the-wild exploitation was reported.

teamcityauthentication-bypassrceci-cdsupply-chain-riskagent-relevant

JetBrains disclosed a critical authentication bypass vulnerability in TeamCity On-Premises that can be chained to achieve remote code execution. Given TeamCity's role as a CI/CD server, successful exploitation could allow attackers to compromise build pipelines, inject malicious code, and pivot into connected infrastructure. Organizations running affected instances should patch immediately given the high likelihood of active exploitation attempts.

rceunauthenticateddefault-credentialsh2-databasedockerexposed-consoleagent-relevant

Juggle through version 1.6.0 ships with an exposed and unprotected H2 database web console reachable at /h2-console, secured only by default credentials. Unauthenticated attackers can log in and abuse the H2 CREATE ALIAS technique to invoke Runtime.exec(), achieving arbitrary OS command execution with root privileges on the stock Docker image.