Fetching from the wire…
Agents2026-09-09 · source-backed
CVE-2026-86996: the "This workflow can be called by" setting was enforced by the Execute Workflow node but not consulted when the same workflow was attached to an Agent as a tool, so any user who could build an Agent could invoke a restricted workflow and read the result. Patched in 2.37.7 and 2.38.2. GHSA-7hgx-277f-7vmg This shape recurs constantly: an authorization check written for the human path is simply absent on the agent path.
Each link below shares sources, entities, or timing with this story.
GHSA-533j-2v4q-mw5h (CVE-2026-55253, CVSS 7.7) covers MongoDBSaver.list() and MongoDBStore.search() accepting a filter without rejecting $-prefixed MongoDB operator keys, letting a caller who controls the filter read checkpoints outside their thread scope. Fixed in langgraph-c...
A novel vulnerability in OpenClaw: the current working directory path was embedded into agent system prompts without sanitization. Control characters in directory names (newlines, Unicode bidi/zero-width markers) break prompt structure and inject attacker instructions. Patched...
CVE-2026-45018 covers Chainlit >=2.4.0rc0 <2.12.0. With features.mcp.enabled = true, POST /mcp accepts a user-controlled fullCommand for stdio transport. validate_mcp_command() checks the executable name against an allowlist and never inspects arguments, so npx -y -c '<command...
GHSA-w8wf-3qvj-6xqf and GHSA-2q7j-2vhx-56g8, both high, published September 3, against @openclaw/feishu. Permission tools and general Feishu tools could ignore per-account disablement, so a lower-trust caller performed actions that should have required a stronger check. First...
CVE-2026-55557 at 8.6 covers a Playwright headless-browser MCP server where browser_download writes a response body to join(save_dir, filename) without validating the caller-supplied save_dir, and the state save/load tools honor caller-controlled paths unchanged. The advisory...
GHSA-2cp2-2r3c-7p7r (CVE-2026-68508, CVSS 7.8) covers hydra.utils.instantiate() resolving and calling whatever _target_ names. Hydra isn't a network service, so you need an app that loads attacker-controlled config, CLI overrides, or model metadata. That last path is the one t...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.