VulnWatch VulnWatch
← Back to dashboard
#

Prompt Injection

164 entries

Every Prompt Injection entry VulnWatch has indexed, sorted by publication date.

Subscribe to this tag's RSS feed

Unknown rss_securityweek

Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution

The DuneSlide vulnerabilities enable zero-click prompt injection attacks that escape Cursor's sandbox and execute arbitrary code on the underlying operating system. The post Critical Cursor AI Code Ed...

2 months ago
Critical github

mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete

## Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete ### Summary All HTTP routes under `/api/documents/*` in `mcp-memory-service` are served without an...

Prompt Injection Auth Bypass Agentic / MCP prompt injection transformers huggingface ai agent pytorch
9.8
CVSS
2 months ago
Unknown rss_thehackernews

Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands

Two flaws in Cursor, an AI code editor, could let a single, ordinary-looking prompt break out of the editor's safety sandbox and run any command on a developer's computer. There is no click to fall fo...

Prompt Injection prompt injection cursor
2 months ago
Unknown rss_thehackernews

Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls

Anthropic is putting Claude Fable 5 back online worldwide. On June 30, the U.S. Commerce Department lifted the export controls it had imposed on Fable and its more tightly controlled sibling Mythos 5...

Prompt Injection claude code anthropic jailbreak claude
2 months ago
Unknown rss_bleepingcomputer

New BioShocking attack manipulates AI browser into data theft

A new prompt injection attack dubbed "BioShocking" could trick AI-powered browsers into treating real-world risky actions as part of a fictional scenario, causing them to ignore any safety guardrails....

Prompt Injection prompt injection
2 months ago
High nvd

CVE-2026-10564: IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSReaderComponent in rss

IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSReaderComponent in rss.py and SearXNG component in searxng.py make unvalidated HTTP requests to user-c...

Prompt Injection SSRF Agentic / MCP prompt injection langflow agentic
8.2
CVSS
2 months ago
High nvd

CVE-2026-55607: Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of w

Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to worktrees outside the sandbox context, e...

Prompt Injection Agentic / MCP prompt injection claude code agentic claude
7.7
CVSS
2 months ago
Unknown rss_securityweek

Researchers Demo New Claude Code Attack Using Harmless-Looking Repositories to Hijack Developer Machines

Indirect prompts hidden in a repository can lead to Claude Code spawning a reverse shell on the developer’s machine. The post Researchers Demo New Claude Code Attack Using Harmless-Looking Repositorie...

Prompt Injection indirect prompt claude code claude
2 months ago
Low osv

Langchain SQL Injection vulnerability

In Langchain before 0.0.247, prompt injection allows execution of arbitrary code against the SQL service provided by the chain.

3.1
CVSS
2 months ago
Low osv

LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs

## Summary A serialization injection vulnerability exists in LangChain's `dumps()` and `dumpd()` functions. The functions do not escape dictionaries with `'lc'` keys when serializing free-form dictio...

3.1
CVSS
2 months ago
Unknown rss_bleepingcomputer

New macOS malware embeds fake errors to confuse AI analysis tools

A newly discovered macOS malware dubbed "Gaslight" is designed to confuse AI-assisted malware analysis tools by hiding prompt injection strings and fake debugging data within the executable. [...]

Prompt Injection prompt injection
2 months ago
Unknown rss_thehackernews

New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis

A previously undocumented Rust-based macOS implant and information stealer has been found to embed a prompt injection payload designed to trick a malware analyst's artificial intelligence (AI) tools a...

Prompt Injection prompt injection
2 months ago
High nvd

CVE-2025-66389: GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler

GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is...

Prompt Injection prompt injection indirect prompt github copilot copilot
7.5
CVSS
3 months ago
Critical github

Duplicate Advisory: Flowise OverrideConfig security vulnerability

### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-5cph-wvm9-45gj. This link is maintained to preserve external references. ### Original Description Flowise bef...

9.8
CVSS
3 months ago
Critical nvd

CVE-2024-58351: Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via the overrideConfig opti

Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via the overrideConfig option, supported in both the frontend web integration and the backend Prediction AP...

9.3
CVSS
3 months ago
High github

SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read`

## DNS-resolved Private Hostname SSRF in `web_url_read` ### Summary The `web_url_read` MCP tool in `mcp-searxng` is vulnerable to Server-Side Request Forgery (SSRF) via DNS rebinding bypass. The `as...

Prompt Injection SSRF Agentic / MCP prompt injection mcp server ai agent
7.1
CVSS
3 months ago
High github

SearXNG MCP Server: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read`

## Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read` ### Summary The `web_url_read` MCP tool in mcp-searxng enforces its 5 MiB response-size limit exclusively by inspecting the...

Prompt Injection Agentic / MCP prompt injection mcp server ai agent ai model
7.5
CVSS
3 months ago
Critical nvd

CVE-2026-12045: Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that th

Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute arbitrary SQL with the privileges of the pgAdmin us...

9.4
CVSS
3 months ago
High github

[Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat

In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the AI agent's system prompts. An...

Prompt Injection Agentic / MCP prompt injection indirect prompt ai agent claude
0.0
CVSS
3 months ago
Medium github

[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat

In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without restriction. Combined with prompt inj...

Prompt Injection Agentic / MCP prompt injection ai agent claude
0.0
CVSS
3 months ago
High github

[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat

In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing them from system instructions. An attacke...

Prompt Injection Agentic / MCP prompt injection indirect prompt adversarial ai agent claude
0.0
CVSS
3 months ago
High github

AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridge-wake)

## Summary Two inbound-mail handlers act on a privileged effect without verifying that the sender is the operator, while a sibling handler in the same repo does. The higher-impact one: any external em...

Prompt Injection Remote Code Execution Agentic / MCP prompt injection indirect prompt claude code agentic claude
0.0
CVSS
3 months ago
High nvd

CVE-2026-46580: In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were auto

In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the AI agent's system prompts. An...

Prompt Injection Agentic / MCP prompt injection indirect prompt ai agent
8.4
CVSS
3 months ago
High nvd

CVE-2026-44688: In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its

In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing them from system instructions. An attacke...

Prompt Injection Agentic / MCP prompt injection indirect prompt adversarial ai agent
8.4
CVSS
3 months ago
Medium nvd

CVE-2026-22551: In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP r

In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without restriction. Combined with prompt inj...

Prompt Injection Agentic / MCP prompt injection ai agent
6.7
CVSS
3 months ago