Ai-agents
This hub aggregates every CVE we track for Ai-agents, a product in the ai ml space. Use it to gauge the current risk picture and drill into individual advisories.
AI / MLon-prem
64
CVEs tracked
4
Critical
22
High
0
In CISA KEV
Severity distribution
MEDIUM37HIGH22CRITICAL4LOW1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
3
5
4
16
9
27
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Ai-agents.
- CVE-2026-18038nextlevelbuilder GoClaw jq Handler tools_invoke.go ExecTool.Execute information disclosure4.3
- CVE-2026-17531unitedbyai droidclaw Unsigned Scheduled Callback goals.ts authorization5.0
- CVE-2026-16199nextlevelbuilder GoClaw credentialed_exec.go ExecTool.Execute improper authorization6.3
- CVE-2026-16198Sipeed PicoClaw First Run Setup access_control.go authentication bypass5.6
- CVE-2026-16197Sipeed PicoClaw Group Message feishu_64.go handleMessageReceive authorization6.3
- CVE-2026-16196Sipeed PicoClaw web_fetch web.go isPrivateOrRestrictedIP server-side request forgery6.3
- CVE-2026-16195Sipeed PicoClaw Group Message wecom.go dispatchIncoming authorization6.3
- CVE-2026-16124nextlevelbuilder GoClaw web_fetch web_shared.go isPrivateIP server-side request forgery6.3
- CVE-2026-16123nextlevelbuilder GoClaw Invoke Endpoint tools_invoke.go ToolsInvokeHandler.ServeHTTP authorization6.3
- CVE-2026-16122nextlevelbuilder GoClaw exec_approval.go matchesAllowlist authorization4.3
- CVE-2026-16121nextlevelbuilder GoClaw exec_approval.go isSafeBin improper authorization6.3
- CVE-2026-16120nextlevelbuilder GoClaw exec_approval.go extractBin name resolution6.3
- CVE-2026-16119nextlevelbuilder GoClaw WebSocket Approval Endpoint exec_approval.go RequestApproval authorization6.3
- CVE-2026-16085Sipeed PicoClaw context.go NewContextBuilder inclusion of functionality from untrusted control sphere5.3
- CVE-2026-16084Sipeed PicoClaw web.go web_fetch server-side request forgery7.3
Product normalization is registry-driven with AI assist and human review. How it works