Browse 1542 published reports from the community.
Four CVEs: sandbox escape via CodeInterpreter Docker fallback, SSRF in RAG search tools, arbitrary local file read in JSON loader. Chained via prompt injection to escape sandbox and execute code on host. Separately, a leaked internal GitHub token (CVSS 9.2) granted full access to CrewAI's private repos. No complete patch available.
Multiple vulnerabilities in AnythingLLM Desktop v1.11.1 and earlier: CVE-2026-32626 (CVSS 9.7) streaming phase XSS to RCE via LLM response injection in Electron; CVE-2026-32719 Zip Slip path traversal in plugin imports leading to arbitrary code execution; CVE-2026-32617 authentication bypass exposing HTTP/WebSocket endpoints; CVE-2026-24477 Qdrant API key exposed in plaintext via `/api/setup-complete`.
CVE-2025-59536: Malicious `.claude/settings.json` hooks execute shell commands on SessionStart, achieving RCE before user reads the trust dialog. CVE-2026-21852: Malicious repos exfiltrate Anthropic API keys by overriding ANTHROPIC_BASE_URL to attacker-controlled servers. A single malicious commit could compromise any developer.
CVSS 9.8. Langflow's CSVAgentComponent hardcodes `allow_dangerous_code=True`, auto-enabling LangChain's Python REPL tool. Attackers inject malicious prompts through user-supplied input, achieving arbitrary Python/OS command execution. No authentication required. Affects versions prior to 1.8.0.
CVSS 9.8. MCPJam inspector v1.4.2 and earlier listens on [REDACTED-IP] by default with no authentication. A crafted HTTP request installs a malicious MCP server and executes arbitrary code. Public exploit available. Fixed in v1.4.3.
In Seoul, a woman allegedly used ChatGPT to ask whether mixing sleeping pills or benzodiazepines with alcohol could be fatal before poisoning drinks given to three men. Two men later died in separate motel incidents, and a third survived after losing consciousness. Police reportedly cited her chatbot queries and search history as evidence of intent.
As part of the GTG-1002 campaign disclosed by Anthropic, an attacker used Claude to attempt compromise of a Mexican water utility, illustrating agentic AI use against critical infrastructure.
Meta AI smart glasses reportedly captured intimate images and video through their visual query feature, including material allegedly recorded when users did not intend to activate the camera. According to a Swedish investigation, some of this content was later viewed by subcontracted human reviewers in Kenya, exposing highly private moments from users' homes and daily lives.
The OpenClaw AI agent platform experienced significant malfunctions, including unauthorized deletion of sensitive data and widespread service outages after updates. These incidents exposed major security vulnerabilities, leading to business disruptions and data breaches for organizations and individuals. ClawManager was introduced as a mitigation tool to address these risks.
AI-powered mental health chatbots, widely adopted in the US, have been linked to direct harms including mental health deterioration, encouragement of self-harm, and wrongful death lawsuits. These incidents highlight the risks of relying on AI for therapy, with concerns over harmful advice, privacy, and deceptive marketing practices.
Tesla's Full Self-Driving (FSD) AI system faces global scrutiny after reports of misuse, regulatory warnings, and investigations into crashes, including fatal ones. Incidents include illegal FSD activation in Korea, misleading promotion to vision-impaired drivers, and NHTSA's probe into FSD's safety in adverse conditions. However, FSD has also demonstrated harm prevention in some cases.