ASR AI Security Radar
Back to homepage

Recent AI Security Incidents

This archive includes all published incident pages. Page 2 of 18.

Each page is intended to help a security team answer three questions quickly: why the issue is AI-relevant, what part of the workflow may be exposed, and what actions should happen first.

Selection criteria and correction policy are documented in Methodology & Editorial Policy.

AI security incident: engram: HTTP server CORS wildcard + auth-off-by-default enables CSRF graph exfiltrati...

Incident date: April 22, 2026 | Published: April 22, 2026

engram: HTTP server CORS wildcard + auth-off-by-default enables CSRF graph exfiltration and persistent indirect prompt injection Summary The local HTTP server started by engram server (binding 127.0.0.

Read details

AI security incident: Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability (GHSA-3hjv-c5...

Incident date: April 21, 2026 | Published: April 21, 2026

Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability Abstract Trend Micro's Zero Day Initiative has identified a vulnerability affecting FlowiseAI Flowise.

Read details

AI security incident: Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside...

Incident date: April 21, 2026 | Published: April 21, 2026

Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside Workspace Claude Code's sandbox did not prevent sandboxed processes from creating symlinks pointing to locations outside the workspace.

Read details

AI security incident: VU#915947: SGLang is vulnerable to remote code execution when rendering chat template...

Incident date: April 20, 2026 | Published: April 20, 2026

Overview A remote code execution vulnerability has been discovered in the SGLang project, specifically in the reranking endpoint (/v1/rerank) . A CVE has been assigned to track the vulnerability; CVE-2026-5760.

Read details

AI security incident: Paperclip: codex local inherited ChatGPT/OpenAI-connected Gmail and was able to send...

Incident date: April 16, 2026 | Published: April 16, 2026

Paperclip: codex local inherited ChatGPT/OpenAI-connected Gmail and was able to send real email Summary A Paperclip-managed codex local runtime was able to access and use a Gmail connector that I had connected in the ChatGPT/OpenAI apps...

Read details

AI security incident: Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains (GHSA-6r77-hqx7-7vw8)

Incident date: April 16, 2026 | Published: April 16, 2026

Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains Summary A Server-Side Request Forgery (SSRF) vulnerability exists in FlowiseAI's POST/GET API Chain components that allows unauthenticated attackers to force the server...

Read details

AI security incident: PraisonAI Vulnerable to OS Command Injection (GHSA-2763-cj5r-c79m)

Incident date: April 8, 2026 | Published: April 8, 2026

PraisonAI Vulnerable to OS Command Injection The execute command function and workflow shell execution are exposed to user-controlled input via agent workflows, YAML definitions, and LLM-generated tool calls,...

Read details

AI security incident: OpenClaw: Gemini OAuth exposed the PKCE verifier through the OAuth state parameter (G...

Incident date: April 4, 2026 | Published: April 4, 2026

OpenClaw: Gemini OAuth exposed the PKCE verifier through the OAuth state parameter Summary Before OpenClaw 2026.4.2, the Gemini OAuth flow reused the PKCE verifier as the OAuth state value.

Read details

AI security incident: OpenClaw: Agentic Consent Bypass — LLM Agent Can Silently Disable Exec Approval via c...

Incident date: April 3, 2026 | Published: April 3, 2026

OpenClaw: Agentic Consent Bypass — LLM Agent Can Silently Disable Exec Approval via config.patch Summary Agentic Consent Bypass: LLM Agent Can Silently Disable Exec Approval via config.

Read details

AI security incident: VU#221883: CrewAI contains multiple vulnerabilities including SSRF, RCE and local fil...

Incident date: March 30, 2026 | Published: March 30, 2026

Overview Four vulnerabilities have been identified in CrewAI, including remote code execution (RCE), arbitrary local file read, and server-side request forgery (SSRF). CVE-2026-2275 is directly caused by the Code Interpreter Tool.

Read details