VulnWatch VulnWatch
← Back to dashboard
#

Prompt Injection

164 entries

Every Prompt Injection entry VulnWatch has indexed, sorted by publication date.

Subscribe to this tag's RSS feed

High github

praisonaiagents web_crawl vulnerable to SSRF via redirect-following

### Summary `web_crawl` (an exported, model-callable tool) validates only the INITIAL URL's resolved IP against a private/loopback blocklist, then fetches with `httpx.Client(follow_redirects=True)` an...

Prompt Injection SSRF prompt injection
7.5
CVSS
4 weeks ago
High nvd

CVE-2026-76072: The Continue CLI applies an incomplete denylist as its only barrier to destructive shell commands when running unattende

The Continue CLI applies an incomplete denylist as its only barrier to destructive shell commands when running unattended. In headless mode and auto mode the default policy in extensions/cli/src/permi...

Prompt Injection prompt injection indirect prompt
8.3
CVSS
4 weeks ago
Critical github

Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing

### Summary Xinference used Python's unsafe `eval()` function when parsing Llama3 tool-call output generated by a large language model. Because the model output can be influenced by attacker-controll...

Prompt Injection Remote Code Execution large language model prompt injection transformers openai llama llm
10.0
CVSS
1 month ago
High nvd

CVE-2026-76832: Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to re

Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to read, write, or execute arbitrary files by supplying parent-directory traversal se...

Prompt Injection prompt injection
8.5
CVSS
1 month ago
Medium github

SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)

Ref: https://github.com/ihor-sokoliuk/mcp-searxng/issues/87#issuecomment-4645453694 ### Summary The web_url_read tool fetches a caller-supplied URL server-side and converts it to markdown. An SSRF g...

Prompt Injection SSRF Agentic / MCP prompt injection mcp server llm
6.5
CVSS
1 month ago
High github

Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint

### Summary `export_space` and `import_space` tools in `@contentful/mcp-tools` accept LLM-controlled `host` and `proxy` parameters that are spread directly into the options object passed to `contentf...

Prompt Injection SSRF Agentic / MCP prompt injection mcp server replicate llm
7.7
CVSS
1 month ago
Medium nvd

CVE-2026-75130: Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions

Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents by injecting unsanitized content through the Cust...

Prompt Injection Agentic / MCP prompt injection mcp server
6.4
CVSS
1 month ago
High nvd

CVE-2026-75913: CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the

CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the...

Prompt Injection prompt injection
8.5
CVSS
1 month ago
High nvd

CVE-2026-75858: CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerabi

CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool. The tool's approval_requirement() returns ApprovalReq...

8.5
CVSS
1 month ago
Unknown rss_thehackernews

How MCP Servers Can Expose Enterprise Secrets

MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running. As more org...

Prompt Injection Agentic / MCP model context protocol prompt injection mcp server ai agent
1 month ago
Medium nvd

CVE-2026-21832: HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. I

HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended be...

Prompt Injection prompt injection indirect prompt
4.3
CVSS
1 month ago
Critical nvd

CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via prompt injection. Attackers...

Prompt Injection SSRF prompt injection
9.0
CVSS
1 month ago
Critical nvd

CVE-2026-73032: PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary Jav

PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning malicious code from an LLM endpoint that is passed unsaniti...

9.4
CVSS
1 month ago
Unknown rss_thehackernews

AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory

A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses a standard feature built into almost every ma...

Prompt Injection prompt injection llm
1 month ago
Critical nvd

CVE-2026-67531: FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:ex

FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host Zod schema instances to the script via getTool(), a...

Prompt Injection Remote Code Execution Agentic / MCP model context protocol prompt injection indirect prompt
9.3
CVSS
1 month ago
Critical nvd

CVE-2026-70477: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt inject

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with...

Prompt Injection large language model prompt injection llm
9.5
CVSS
1 month ago
Critical github

Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability

-- ABSTRACT ------------------------------------- Trend Micro's Zero Day Initiative has identified a vulnerability affecting the following products: Flowise - Flowise -- VULNERABILITY DETAILS ------...

0.0
CVSS
1 month ago
High github

Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API

#### Summary The `POST /api/v1/prediction/:id` endpoint — which is unauthenticated (whitelisted in `WHITELIST_URLS`) — accepts an `overrideConfig` object in the request body. This object is unconditi...

Prompt Injection prompt injection llm
0.0
CVSS
1 month ago
High nvd

CVE-2026-18733: A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors

A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands on the agent's host via a crafte...

Prompt Injection prompt injection
7.5
CVSS
1 month ago
High nvd

CVE-2026-18655: Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.

Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated actor (vi...

Prompt Injection Agentic / MCP prompt injection mcp server
7.1
CVSS
1 month ago
Critical nvd

CVE-2026-17351: The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_qu

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statemen...

9.4
CVSS
1 month ago
Medium github

@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification

### Summary A template injection vulnerability in the `create_workflow_for_notification` tool lets a caller embed Jinja2 expressions that the Dynatrace workflow engine evaluates at runtime, exfiltrati...

4.2
CVSS
1 month ago
Medium github

@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL

### Summary A DQL injection vulnerability in several read tools lets a caller bypass the tools' documented field-scope, time-window, and display caps by injecting DQL pipeline stages through parameter...

4.3
CVSS
1 month ago
Medium nvd

CVE-2026-17534: Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal

Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal denylist in assertSafeFetchTarget, without resolving DNS or re-validating hosts...

Prompt Injection SSRF prompt injection
5.5
CVSS
1 month ago
High github

Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution

Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to worktrees outside the sandbox context, enabling git directory confusion attacks. By exploiting symlink mani...

Prompt Injection prompt injection claude code anthropic claude
0.0
CVSS
1 month ago