Mar 24, 2026 •
Vulnerability
|
#LLM Vulnerabilities
#Remote Code Execution
#AI Red Teaming
Novee has introduced an AI Red Teaming platform to proactively identify security vulnerabilities in LLM-powered applications. Their research recently uncovered ...
Read Analysis →
Mar 19, 2026 •
Vulnerability
|
#Remote Code Execution
#Pickle Deserialization
#Cross-Tenant Isolation
Wiz Research identified critical isolation vulnerabilities in Hugging Face's AI-as-a-Service platform, allowing remote code execution and potential cross-t...
Read Analysis →
Feb 12, 2026 •
Vulnerability
|
#Remote Code Execution
#Prompt Injection
#Supply Chain Poisoning
The OpenClaw open-source AI agent project rapidly exposed at least three high-risk Remote Code Execution (RCE) vulnerabilities, allowing attackers to perform hi...
Read Analysis →
Feb 03, 2026 •
Vulnerability
|
#Remote Code Execution
#Command Injection
#Prompt Injection
The OpenClaw AI bot farm is plagued by critical security flaws, including a one-click remote code execution vulnerability and two command injection vulnerabilit...
Read Analysis →
Feb 03, 2026 •
Vulnerability
|
#DockerDash
#Meta-Context Injection
#Remote Code Execution
A critical vulnerability, codenamed DockerDash, in Docker's Ask Gordon AI assistant allowed remote code execution and data exfiltration. This "Meta-Co...
Read Analysis →
Feb 03, 2026 •
Vulnerability
|
#CVE-2026-25253
#Remote Code Execution
#Token Exfiltration
A critical token exfiltration vulnerability, tracked as CVE-2026-25253, was discovered in the OpenClaw (Moltbot/Clawdbot) AI assistant. This one-click remote co...
Read Analysis →
Feb 02, 2026 •
Vulnerability
|
#OpenClaw
#Remote Code Execution
#AI Coding Assistants
The OpenClaw vulnerability in AI coding assistants allows single-click Remote Code Execution (RCE) by exploiting the trust relationship between developers and A...
Read Analysis →
Feb 02, 2026 •
Vulnerability
|
#CVE-2026-25253
#Remote Code Execution
#Cross-Site WebSocket Hijacking
A high-severity vulnerability, tracked as CVE-2026-25253, in OpenClaw allows one-click remote code execution (RCE) via a crafted malicious link. This exploit le...
Read Analysis →
Jan 27, 2026 •
Vulnerability
|
#Authentication Bypass
#Remote Code Execution
#API Key Exposure
Cybersecurity experts have identified a critical authentication bypass vulnerability in the Clawdbot AI assistant, stemming from improperly configured reverse p...
Read Analysis →
Jan 13, 2026 •
Vulnerability
|
#Remote Code Execution
#AI/ML
#Library Vulnerability
This article details potential Remote Code Execution (RCE) vulnerabilities arising from the use of modern AI/ML formats and libraries. It investigates how these...
Read Analysis →
Dec 29, 2025 •
Vulnerability
|
#Prompt Injection
#AI Supply Chain Poisoning
#Remote Code Execution
Prompt injection is a prevalent AI-specific vulnerability where Large Language Models (LLMs) misinterpret external data as executable instructions, bypassing in...
Read Analysis →
Dec 06, 2025 •
Vulnerability
|
#Prompt Injection
#Remote Code Execution
#AI IDEs
Security researcher Ari Marzouk disclosed "IDEsaster," a collection of over 30 vulnerabilities, with 24 assigned CVEs, affecting various AI-powered In...
Read Analysis →
Nov 03, 2025 •
Vulnerability
|
#CVE-2024-12366
#Remote Code Execution
#Agentic AI
The article details a Remote Code Execution (RCE) vulnerability, tracked as CVE-2024-12366, affecting agentic AI systems that execute LLM-generated code without...
Read Analysis →
Oct 09, 2025 •
Vulnerability
|
#Indirect Prompt Injection
#Remote Code Execution
#Agentic AI
Attackers can achieve remote code execution (RCE) on developer machines by leveraging indirect prompt injection against agentic AI developer tools. This is acco...
Read Analysis →
Oct 08, 2025 •
Vulnerability
|
#OWASP LLM01:2025
#OWASP LLM07:2025
#Remote Code Execution
An attack chain on an AI chatbot demonstrated how indirect prompt injection (OWASP LLM01:2025) and system prompt leakage (OWASP LLM07:2025) can be leveraged. Th...
Read Analysis →
Oct 08, 2025 •
Vulnerability
|
#Indirect Prompt Injection
#Command Injection
#Remote Code Execution
An advanced attack chain exploits an LLM chatbot through indirect prompt injection (OWASP LLM01:2025) to achieve system prompt leakage and abuse excessive agenc...
Read Analysis →
Oct 02, 2025 •
Vulnerability
|
#Prompt Injection
#Remote Code Execution
#Retrieval-Augmented Generation (RAG)
LLM-based applications are susceptible to remote code execution (RCE) vulnerabilities when executing LLM-generated code via functions like `exec` or `eval` with...
Read Analysis →
Oct 02, 2025 •
Vulnerability
|
#Remote Code Execution
#Prompt Injection
#Retrieval-Augmented Generation
The NVIDIA AI Red Team identifies critical vulnerabilities in LLM applications, including remote code execution (RCE) via prompt injection when executing unsand...
Read Analysis →
Oct 02, 2025 •
Vulnerability
|
#Remote Code Execution
#Prompt Injection
#Retrieval-Augmented Generation
The NVIDIA AI Red Team highlights critical vulnerabilities in LLM-based applications, most notably Remote Code Execution (RCE) via prompt injection when LLM-gen...
Read Analysis →
Aug 21, 2025 •
Vulnerability
|
#SQL Injection
#Remote Code Execution
#LLM-based AI
AI coding tools like Claude Code integrate security features to identify common vulnerabilities such as SQL injection, XSS, RCE, and SSRF during development wor...
Read Analysis →
Aug 17, 2025 •
Vulnerability
|
#Remote Code Execution
#Prompt Injection
#Coding Agents
The article details advanced prompt injection and watering hole techniques that exploit LLM-based coding agents, leveraging their ability to interpret malicious...
Read Analysis →
Aug 17, 2025 •
Vulnerability
|
#Prompt Injection
#Remote Code Execution
#ASCII Smuggling
The article highlights critical security vulnerabilities in LLMs integrated with coding agents, primarily exploiting advanced prompt injection techniques. Attac...
Read Analysis →
Aug 17, 2025 •
Vulnerability
|
#Prompt Injection
#Remote Code Execution
#ASCII Smuggling
The article highlights novel prompt injection techniques, such as ASCII Smuggling and hidden instructions in public code repositories, designed to be impercepti...
Read Analysis →
Aug 06, 2025 •
Vulnerability
|
#CVE-2025-49596
#Remote Code Execution
#Malicious OAuth Proxying
The article details critical security vulnerabilities within Model Context Protocol (MCP) deployments, including a remote code execution exploit (CVE-2025-49596...
Read Analysis →
Jul 01, 2025 •
Vulnerability
|
#CVE-2025-49596
#Remote Code Execution
#0.0.0.0 Day
A critical remote code execution (RCE) vulnerability, CVE-2025-49596 (CVSS 9.4), has been identified in Anthropic's Model Context Protocol (MCP) Inspector,...
Read Analysis →
May 01, 2025 •
Vulnerability
|
#Prompt injection
#Remote Code Execution
#AI Agent
AI agentic applications face significant security threats, including prompt injection, tool misuse, and unsecured code interpreters, which can result in informa...
Read Analysis →