Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 29 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
135 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Sin puntuar | — | — | Modelscope AgentscopeAI | 2/10/2026 | 2/10/2026 | agentscope v1.0.20 contains code injection in execute_shell_command (src/agentscope/tool/_coding/_shell.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution. | |
| Aplazada | Crítica (9.8) | 0.33% | — | Modelscope AgentscopeAI | 30/9/2026 | 1/10/2026 | In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python code in the service environment. In the validated path, RealtimeAgent._acting forwards the model-produced tool call to… | |
| Aplazada | Alta (8.1) | 0.22% | — | Modelscope AgentscopeAI | 30/9/2026 | 2/10/2026 | modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert_text_file. | |
| Aplazada | Alta (8.1) | 0.32% | — | Modelscope AgentscopeAI | 30/9/2026 | 1/10/2026 | modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file. | |
| Aplazada | Media (6.5) | 0.21% | — | WSP MCP AI Agents ConnectorAI | 23/9/2026 | 23/9/2026 | Contributor Broken Access Control in WSP MCP – AI Agents Connector <= 2.7.0 versions. | |
| Aplazada | Alta (8.7) | 1.3% | — | Atomic-agents-stackAI | 15/9/2026 | 24/9/2026 | atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths. Attackers can bypass path containment checks by including '../' segments in requests to the… | |
| Aplazada | Crítica (9.2) | 0.32% | — | Atomic-agents-stackAI | 15/9/2026 | 24/9/2026 | atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses. Attackers can inject arbitrary command and argument values that are spawned as local subprocesses by MCPClientPool to achieve code… | |
| Aplazada | Alta (7.1) | 0.48% | — | Atomic-agents-stackAI | 15/9/2026 | 24/9/2026 | atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zero cost for unknown models not in the pricing table. Attackers can configure deployments with unknown model identifiers to bypass daily cost caps and exceed budget limits in parallel batch operations. | |
| Aplazada | Alta (8.3) | 0.22% | — | PraisonaiagentsAIPraisonaiAI | 15/9/2026 | 16/9/2026 | PraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 until 1.6.59 and PraisonAI 3.10.0 until 4.6.59, ToolsMCPServer.run_sse() in src/praisonai-agents/praisonaiagents/mcp/mcp_server.py mounts SseServerTransport on the legacy /sse and /messages/ endpoints without default Host, Origin, or authentication… | |
| Aplazada | Alta (8.1) | 0.46% | — | PraisonaiagentsAI | 14/9/2026 | 15/9/2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/email_tools.py interpolates LLM-controlled from_addr, subject, and query values directly into quoted IMAP SEARCH criteria. Embedded quote, backslash, newline, or null characters can escape the intended… | |
| Aplazada | Media (4.3) | 0.25% | — | PraisonaiagentsAI | 14/9/2026 | 16/9/2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the SSE server in src/praisonai-agents/praisonaiagents/server/server.py does not consult ServerConfig.auth_token before handling /publish, /events, or /info requests. A network client that can reach the server can broadcast arbitrary events to… | |
| Aplazada | Alta (8.5) | 0.38% | — | PraisonaiagentsAI | 14/9/2026 | 15/9/2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_blocked, which checks literal host encodings but does not resolve DNS names before scrape_page, crawl, extract_links, extract_text, or URL-mention fetches connect. An attacker-controlled hostname… | |
| Aplazada | Crítica (9.8) | 0.60% | — | PraisonaiAIPraisonaiagentsAI | 14/9/2026 | 15/9/2026 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthenticated POST /api/v1/runs Jobs API accepts attacker-controlled agent_yaml, and the approve field can mark execute_command as YAML-approved before @require_approval checks critical tools. This chain allows a… | |
| Aplazada | Crítica (9.8) | 0.90% | — | PraisonaiagentsAI | 14/9/2026 | 15/9/2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and launch_tools_mcp_server bind to 0.0.0.0 and create /sse and /messages/ routes without invoking the available SecurityConfig authentication, origin-validation, or DNS-rebinding controls. Any reachable client can list… | |
| Aplazada | Media (6.5) | 0.56% | — | PraisonaiagentsAI | 14/9/2026 | 16/9/2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, execute_code sandbox mode permits runtime assembly of blocklisted dunder names and allows str.format or str.format_map to resolve dotted fields through C-level attribute access that bypasses _safe_getattr. This exposes class, qualified-name,… | |
| Aplazada | Media (6.5) | 0.43% | — | PraisonaiagentsAI | 14/9/2026 | 15/9/2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, SpiderTools.scrape_page validates only the initial URL and lets requests.Session.get follow redirects automatically, so a public-looking URL can redirect to a loopback, private, link-local, or metadata address without revalidation. The… | |
| Aplazada | Alta (7.5) | 0.53% | — | PraisonaiagentsAI | 14/9/2026 | 30/9/2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, MentionsParser._process_file_mention accepts file-mention values and falls back from workspace-relative resolution to Path(file_path) without traversal, symlink, or workspace-boundary validation. Prompt input from users, bots, or workflows can… | |
| Pendiente de análisis | Media (5.1) | 0.44% | — | Amazon Aws-agents-for-devsecopsAI | 10/9/2026 | 10/9/2026 | A missing S3 bucket ownership verification in the AWS Security Agent plugin in Amazon aws-agents-for-devsecops before 1.1.0 might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that archive, via a pre-registered storage… | |
| Aplazada | Media (5.5) | 0.54% | — | Xlang OpenagentsAI | 7/9/2026 | 8/9/2026 | A vulnerability was found in openagents-org openagents up to 0.8.19/0.9.3.post20. Impacted is the function test_default_model of the file sdk/src/openagents/sdk/transports/http.py. Performing a manipulation of the argument base_url results in server-side request forgery. The attack may be initiated remotely. The… | |
| Aplazada | Alta (8.7) | 0.55% | — | Modelscope AgentscopeAI | 4/9/2026 | 23/9/2026 | AgentScope through 2.0.7.post1 contains a path traversal vulnerability in LocalWorkspace.add_skill that copies arbitrary server directories into the agent workspace via an unconfined source path parameter. Attackers can supply any directory path in the skill_path request parameter to copy files into the skills… | |
| Pendiente de análisis | Crítica (9.2) | 0.57% | — | Amazon Strands Agents ToolsAI | 25/8/2026 | 26/8/2026 | Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute arbitrary Python code on the agent's host by bypassing the human consent gate, via a crafted prompt that forwards non_interactive_mode as a keyword argument… | |
| Aplazada | Media (6.1) | 0.17% | — | PraisonaiagentsAI | 25/8/2026 | 9/9/2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, ast_grep_rewrite lacks the @require_approval decorator used by sibling mutation tools. With dry_run=False, an agent-controlled call can pass --update-all and a broad path to rewrite matching files without the expected authorization gate. This… | |
| Aplazada | Alta (8.2) | 0.49% | — | PraisonaiagentsAI | 25/8/2026 | 9/9/2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, AgentServer exposes ServerConfig.auth_token but AgentServer._create_app does not check it on any route. A remote caller can subscribe, publish, and perform other actions without a valid bearer token or X-Auth-Token even when authentication is… | |
| Aplazada | Alta (7.1) | 0.48% | — | PraisonaiagentsAI | 25/8/2026 | 9/9/2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the FileMemory constructor joins unsanitized user_id into self.user_path. A caller supplying ../ or path separators can escape the memory directory and write JSON data to arbitrary process-writable locations. The fix sanitizes user_id before… | |
| Aplazada | Alta (8.5) | 0.36% | — | PraisonaiagentsAI | 25/8/2026 | 9/9/2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, spider_tools._host_is_blocked() does not resolve ordinary hostnames before scrape_page fetches them. A hostname such as 127.0.0.1.nip.io passes validation and resolves to loopback, permitting internal HTTP access. The fix uses socket.getaddrinfo… |