VulnWatch VulnWatch
← Back to dashboard
#

Prompt Injection

164 entries

Every Prompt Injection entry VulnWatch has indexed, sorted by publication date.

Subscribe to this tag's RSS feed

Unknown rss_securityweek

AIUC Raises $40 Million to Certify Enterprise AI Agents

The company provides a standard for AI systems, testing them against risks such as jailbreaks, prompt injections, and unauthorized actions. The post AIUC Raises $40 Million to Certify Enterprise AI Ag...

Prompt Injection Agentic / MCP prompt injection jailbreak ai agent
6 days ago
High github

@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS

### Summary @zereight/mcp-gitlab exposes GitLab to an LLM agent while relying on read-only mode, a project allow-list, and transport auth as its safety controls. Five defects defeat those controls. Un...

Prompt Injection Agentic / MCP prompt injection replicate llm agent llm
8.1
CVSS
6 days ago
High nvd

CVE-2026-53957: Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to @contentful/mcp-ser

Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to @contentful/mcp-server 1.7.19 and @contentful/mcp-tools 0.4.5, export_space and import_space in pac...

Prompt Injection Agentic / MCP model context protocol prompt injection mcp server llm
7.7
CVSS
1 week ago
High github

functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import

## MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import ### Summary The `set_functype_version` MCP tool in `functype-mcp-server` accepts an unconstrained `versi...

Prompt Injection Remote Code Execution Agentic / MCP prompt injection indirect prompt mcp server llm agent llm
7.8
CVSS
1 week ago
Low nvd

CVE-2026-85704: A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This i

A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function getJailbreak of the file server/config.py of the compo...

2.9
CVSS
2 weeks ago
Medium nvd

CVE-2026-85703: A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected by this iss

A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected by this issue is the function getJailbreak of the file server/backend.py of the component J...

5.5
CVSS
2 weeks ago
High github

CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)

### Maintainer resolution The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac...

Prompt Injection Remote Code Execution prompt injection deepseek llm
7.8
CVSS
2 weeks ago
High github

CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval

### Maintainer resolution The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05...

Prompt Injection prompt injection deepseek
7.4
CVSS
2 weeks ago
High github

CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval

### Maintainer resolution The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05...

9.3
CVSS
2 weeks ago
High github

CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)

### Maintainer resolution The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac...

Prompt Injection Auth Bypass prompt injection deepseek llm
7.0
CVSS
2 weeks ago
Critical nvd

CVE-2026-85694: LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that eval

LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers c...

Prompt Injection Remote Code Execution prompt injection indirect prompt
9.2
CVSS
2 weeks ago
High nvd

CVE-2026-85675: OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content too

OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content tool that fetches caller-supplied URLs with no scheme, host, or IP filtering. Attac...

Prompt Injection SSRF prompt injection
8.7
CVSS
2 weeks ago
Medium github

CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning

## Summary The response cache derives its key from an ambiguous string serialization of the request parameters. `canonicalizeParams` joins sorted `${key}=${value}` pairs with `&` and does not escape...

Prompt Injection Agentic / MCP prompt injection indirect prompt mcp server
6.5
CVSS
2 weeks ago
Medium github

CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`)

## Summary The `ckan_get_mqa_quality` and `ckan_get_mqa_quality_details` tools restrict their `server_url` argument to `dati.gov.it` via a regular expression. The regex is anchored only at the start...

Prompt Injection SSRF Agentic / MCP indirect prompt mcp server agentic
5.3
CVSS
2 weeks ago
High nvd

CVE-2026-79745: MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate end

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, the built-in p...

Prompt Injection Agentic / MCP prompt injection mcp server llm
7.1
CVSS
3 weeks ago
High nvd

CVE-2026-82217: In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agent Mode" file-change tools (writeFileContent

In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agent Mode" file-change tools (writeFileContent, suggestFileContent, and the replacement and state helpers) resolved a model-su...

Prompt Injection prompt injection indirect prompt
8.8
CVSS
3 weeks ago
Medium nvd

CVE-2026-82233: SiYuan before v3.8.1 contains a path traversal vulnerability in the asset.upload MCP tool that accepts arbitrary absolut

SiYuan before v3.8.1 contains a path traversal vulnerability in the asset.upload MCP tool that accepts arbitrary absolute file paths without workspace boundary validation. Attackers can induce the AI...

Prompt Injection Agentic / MCP prompt injection ai agent
6.9
CVSS
3 weeks ago
Unknown nvd

CVE-2026-37003: Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection. The PythonTools and Sh

Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection. The PythonTools and ShellTools components pass unsanitized, LLM-generated arguments directly to execut...

3 weeks ago
Unknown rss_thehackernews

Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers

Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate dat...

Prompt Injection Agentic / MCP prompt injection agentic
3 weeks ago
High nvd

CVE-2026-55557: browse-mcp is a Playwright-based headless-browser MCP server for MCP-capable agents. Prior to 0.8.2, browser_download wr

browse-mcp is a Playwright-based headless-browser MCP server for MCP-capable agents. Prior to 0.8.2, browser_download writes a fetched response body to join(save_dir, filename) without validating the...

Prompt Injection Agentic / MCP prompt injection indirect prompt mcp server
8.6
CVSS
4 weeks ago
High github

browse-mcp has an arbitrary file write via unconfined download and state paths

### Impact `browser_download` wrote a fetched file to `join(save_dir, filename)` with no validation of `save_dir`, and `browser_save_state` / `browser_load_state` honored an explicit `path` unchanged....

Prompt Injection Agentic / MCP prompt injection indirect prompt
0.0
CVSS
4 weeks ago
High github

mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist

mcp-shell` at commit `17ac0eef5c9a5a42b8fb132d3d034973d55a5433` has two issues that together mean neither the default deploy path nor the recommended "secure mode" delivers the restriction they're mar...

0.0
CVSS
4 weeks ago
High github

PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server

### Summary The PraisonAI MCP server exposes an HTTP-stream transport (praisonai mcp serve --transport http-stream) that binds to localhost and, by default, has no API key. Its only access control fo...

7.6
CVSS
4 weeks ago
High github

PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks

### Summary PraisonAI's `praisonai.code` tool wrappers (exported as `CODE_TOOLS` for agents) expose a `workspace` setting that the module itself treats as a path-traversal **security boundary** — `rea...

Prompt Injection prompt injection indirect prompt
7.1
CVSS
4 weeks ago
High github

praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)

The web_crawl tool performs its SSRF check only on the initial URL: it resolves the hostname once with socket.gethostbyname and rejects private/loopback/link-local results. It then passes the URL to a...

Prompt Injection SSRF prompt injection indirect prompt
7.5
CVSS
4 weeks ago