# RAXE AI Security — Full Context for LLMs # https://raxe.ai # Generated: 2026-09-05 > This file provides detailed structured context about RAXE for LLM consumption. > For a shorter overview, see https://raxe.ai/llms.txt # RAXE > Runtime detection & evidence for AI agents. Self-hosted visibility across coding agents, > SDKs, gateways, cloud and kernel activity – recorded, sealed as evidence, and verifiable > on demand. Early access (design partner programme). # Last updated: 2026-07-09 ## What RAXE is RAXE records what AI agents actually do – not just what they report. It correlates three views of every agent action into one timeline: what the agent claimed at the RAXE Gateway, what the application saw through the RAXE Sensor SDK, and what the host sensor observed at the kernel (eBPF). Sensitive evidence is sealed by default; revealing it writes its own audit row; the whole evidence ledger is hash-chained and can be verified on demand. RAXE deploys observe-first (observe-and-log). It detects and flags threats with full evidence today; blocking/enforcement is the roadmap, not a shipped capability. Deployment is self-hosted and single-tenant, in the customer's own environment (VPC or on-premises). The product is in early access via a design partner programme. ## Key capabilities (validated) - Kernel-level eBPF host sensor: catches in-process file and secret access (e.g. an agent reading /etc/passwd) that proxies and log files cannot see, pinned to the exact agent session. - One console (RAXE Lineage Lens) for every agent surface: coding agents, in-app SDK calls, gateway LLM traffic, and AWS cloud activity – one triage queue. - Coding-agent coverage: watches Claude Code and OpenCode live with explicit session attribution; Codex sessions supported via ingest with attribution labelled inferred. - AWS lane: live CloudTrail detection of agent activity (e.g. an agent role reading a secret flagged as data exfiltration); AgentCore telemetry. Demo environments use clearly-labelled sample data. - Detection stack (five signals): MITRE ATLAS + OWASP ASI-mapped rules; an ML text scorer; structured tool-call risk analysis (SQL injection, shell injection, path traversal in tool arguments); an agent behaviour graph; and an optional advisory LLM judge (a second opinion that never changes the decision). - Explainable verdicts: threat probability, per-family scores, out-of-distribution signal, nearest known attack patterns. - Evidence integrity: sealed-by-default evidence, audited reveal, tamper-evident hash-chained audit ledger with on-demand verification ("Intact"). - Latency: fast rules answer in single-digit milliseconds; the full multi-signal verdict in roughly 150 ms – all local. - Taxonomy: 13 threat families, 41 techniques, 10 harm types, mapped to MITRE ATLAS and OWASP ASI (Agentic Security Initiative). ## What RAXE does not do (yet) - No blocking/enforcement in production today: RAXE runs observe-and-log; would-block decisions are logged with evidence. Enforcement is on the roadmap. - Single-tenant only (no multi-tenant deployment). - Kubernetes DaemonSet/sidecar deployment is roadmap; validated paths are Docker Compose, systemd host sensor, and the Python SDK. - SOC 2 Type II: programme in progress; RAXE does not claim a completed audit. ## Links - Website: https://raxe.ai - Product Overview: https://raxe.ai/platform - Product Walkthrough (4-min video): https://raxe.ai/platform/walkthrough - Deploy (observe-first install path): https://raxe.ai/deploy - RAXE Gateway: https://raxe.ai/gateway - RAXE Sensor: https://raxe.ai/sensor - RAXE Intelligence: https://raxe.ai/intelligence - Integrations: https://raxe.ai/integrations - Solutions: https://raxe.ai/solutions - How RAXE Compares: https://raxe.ai/compare - Trust & Evidence: https://raxe.ai/trust - Enterprise: https://raxe.ai/enterprise - Pricing (early access): https://raxe.ai/pricing - Developers: https://raxe.ai/developers - Browser Detection Lab (browser-only classifier demo): https://raxe.ai/live-demo - RAXE Labs (research): https://raxe.ai/labs - Threat Intelligence reports: https://raxe.ai/labs/threat-intelligence - Security Advisories: https://raxe.ai/labs/advisories - Research Radar: https://raxe.ai/labs/radar - Cold Validation: https://raxe.ai/labs/cold-validation - Advisory Services: https://raxe.ai/services - Documentation: https://docs.raxe.ai - GitHub: https://github.com/raxe-ai/raxe-ce ## Contact - Book a 30-minute walkthrough: https://calendar.app.google/tpt3UKF3L2yQ53eX8 - Talk to an engineer: https://raxe.ai/contact ## Advisory Details (Machine-Readable) Each advisory contains: vulnerability analysis, attack chain walkthrough, detection signatures (YARA, Sigma, ModSecurity), and remediation guidance. ### RAXE-2026-062: Ollama GGUF Heap Out-of-Bounds Read: Memory Disclosure via /api/create + Exfiltration via /api/push (CVE-2026-7482) - Severity: HIGH (CVSS 8.8) - Stream: Agent Security - Published: 2026-05-11 - URL: https://raxe.ai/labs/advisories/RAXE-2026-062 - CVEs: CVE-2026-7482 - Detection signatures: 0 - Tags: agent-security, authentication-bypass, cve, ollama ### RAXE-2026-061: NVIDIA BioNeMo Framework Deserialization of Untrusted Data Enables Remote Code Execution (CVE-2026-24164) - Severity: CRITICAL (CVSS 9.8) - Stream: Supply Chain - Published: 2026-04-24 - URL: https://raxe.ai/labs/advisories/RAXE-2026-061 - CVEs: CVE-2026-24164 - Detection signatures: 0 - Tags: cve, deserialization, huggingface, langchain, nvidia, rce, supply-chain ### RAXE-2026-060: PraisonAI Post-Cluster Wave: execute_command OS Command Injection + Multi-Backend SQL Injection Incomplete-Fix (CVE-2026-40088, CVE-2026-40315) - Severity: CRITICAL (CVSS 9.6) - Stream: Agent Security - Published: 2026-04-23 - URL: https://raxe.ai/labs/advisories/RAXE-2026-060 - CVEs: CVE-2026-40088, CVE-2026-40315 - Detection signatures: 0 - Tags: agent-security, authentication-bypass, cve, injection, langchain, praisonai, praisonaiagents ### RAXE-2026-059: Claude Code Sandbox Escape via Symlink Following Enables Arbitrary File Write Outside Workspace (CVE-2026-39861) - Severity: CRITICAL - Stream: Agent Security - Published: 2026-04-23 - URL: https://raxe.ai/labs/advisories/RAXE-2026-059 - CVEs: CVE-2026-39861 - Detection signatures: 0 - Tags: agent-security, anthropic-ai-claude-code, cve, injection, path-traversal, prompt-injection, sandbox-escape ### RAXE-2026-058: Flowise CSV Agent Pyodide Sandbox Escape, Third Advisory in the 3.0.13 Wave (CVE-2026-41264) - Severity: CRITICAL (CVSS 9.8) - Stream: Agent Security - Published: 2026-04-23 - URL: https://raxe.ai/labs/advisories/RAXE-2026-058 - CVEs: CVE-2026-41264 - Detection signatures: 0 - Tags: agent-security, authentication-bypass, cve, flowise, flowise-components, prompt-injection, sandbox-escape ### RAXE-2026-057: Claude Code Windows Local Privilege Escalation via Untrusted ProgramData Search Path (CVE-2026-35603) - Severity: HIGH - Stream: Agent Security - Published: 2026-04-20 - URL: https://raxe.ai/labs/advisories/RAXE-2026-057 - CVEs: CVE-2026-35603 - Detection signatures: 0 - Tags: agent-security, anthropic-ai-claude-code, cve, mcp ### RAXE-2026-056: Flowise 3.0.13 Post-Patch Advisory Wave: Airtable_Agent Pyodide Sandbox Escape and Unauthenticated TTS Credential Abuse - Severity: HIGH (CVSS 9.2) - Stream: Agent Security - Published: 2026-04-20 - URL: https://raxe.ai/labs/advisories/RAXE-2026-056 - CVEs: CVE-2026-41265, CVE-2026-41279 - Detection signatures: 0 - Tags: agent-security, authentication-bypass, cve, flowise, flowise-components, prompt-injection, sandbox-escape ### RAXE-2026-055: OpenAI Codex CLI Auto-Loaded MCP Config Enables Command Injection Without Interactive Approval (CVE-2025-61260) - Severity: CRITICAL (CVSS 9.8) - Stream: Agent Security - Published: 2026-04-20 - URL: https://raxe.ai/labs/advisories/RAXE-2026-055 - CVEs: CVE-2025-61260 - Detection signatures: 0 - Tags: agent-security, authentication-bypass, cve, injection, mcp, openai-codex ### RAXE-2026-054: Paperclip Agent Runtime and Tenant Boundary Collapse: Multi-Advisory Disclosure Burst - Severity: CRITICAL (CVSS 10.0) - Stream: Supply Chain - Published: 2026-04-19 - URL: https://raxe.ai/labs/advisories/RAXE-2026-054 - CVEs: CVE-2026-41208, CVE-2026-41679 - Detection signatures: 0 - Tags: authentication-bypass, cve, deserialization, injection, paperclipai, paperclipai-server, paperclipai-shared, paperclipai-ui, rce, supply-chain ### RAXE-2026-053: LiteLLM JWT Authentication Cache Key Collision - Severity: CRITICAL (CVSS 9.1) - Stream: Supply Chain - Published: 2026-04-12 - URL: https://raxe.ai/labs/advisories/RAXE-2026-053 - CVEs: CVE-2026-35030 - Detection signatures: 2 - Tags: authentication-bypass, cve, litellm, supply-chain ### RAXE-2026-052: text-generation-webui Path Traversal to RCE (CVE-2026-35050) - Severity: CRITICAL (CVSS 9.1) - Stream: Supply Chain - Published: 2026-04-12 - URL: https://raxe.ai/labs/advisories/RAXE-2026-052 - CVEs: CVE-2026-35050 - Detection signatures: 2 - Tags: cve, path-traversal, rce, supply-chain, text-generation-webui ### RAXE-2026-051: Anthropic Claude Code CLI and Agent SDK OS Command Injection (CVE-2026-35022) - Severity: CRITICAL (CVSS 9.8) - Stream: Agent Security - Published: 2026-04-12 - URL: https://raxe.ai/labs/advisories/RAXE-2026-051 - CVEs: CVE-2026-35022 - Detection signatures: 3 - Tags: agent-security, anthropic, claude, cve, injection ### RAXE-2026-050: PraisonAI Ecosystem Nine-Vulnerability Cluster - Sandbox Bypass, MCP Command Injection, SQL Injection, Authentication Bypass, and SSRF Across praisonai and praisonaiagents - Severity: CRITICAL (CVSS 10.0) - Stream: Agent Security - Published: 2026-04-05 - URL: https://raxe.ai/labs/advisories/RAXE-2026-050 - CVEs: CVE-2026-34934, CVE-2026-34935, CVE-2026-34936, CVE-2026-34937, CVE-2026-34938, CVE-2026-34952, CVE-2026-34953, CVE-2026-34954, CVE-2026-34955 - Detection signatures: 2 - Tags: agent-security, authentication-bypass, cve, injection, memory-corruption, prompt-injection, sandbox-escape ### RAXE-2026-049: CrewAI Unsafe Fallback and Configuration Behaviours Enable Prompt-Injection-to-RCE, SSRF, and File Read - Severity: CRITICAL (CVSS 9.8) - Stream: S2 - Published: 2026-04-05 - URL: https://raxe.ai/labs/advisories/RAXE-2026-049 - CVEs: CVE-2026-2275, CVE-2026-2285, CVE-2026-2286, CVE-2026-2287 - Detection signatures: 6 - Tags: agent-security, cve, model-loading, prompt-injection, rce, sandbox-escape ### RAXE-2026-048: ONNX Model Deserialization Attribute Injection via setattr() - Severity: HIGH (CVSS 8.6) - Stream: Supply Chain - Published: 2026-04-03 - URL: https://raxe.ai/labs/advisories/RAXE-2026-048 - CVEs: CVE-2026-34445 - Detection signatures: 6 - Tags: cve, deserialization, model-loading, path-traversal, supply-chain ### RAXE-2026-047: FastGPT AI Agent Platform Unauthenticated HTTP Proxy and MCP SSRF - Severity: CRITICAL (CVSS 10.0) - Stream: Agent Security - Published: 2026-04-03 - URL: https://raxe.ai/labs/advisories/RAXE-2026-047 - CVEs: CVE-2026-34162, CVE-2026-34163 - Detection signatures: 4 - Tags: agent-security, authentication-bypass, cve, mcp, redis ### RAXE-2026-046: LangChain Path Traversal in Prompt Loading Enables Arbitrary File Read - Severity: HIGH (CVSS 7.5) - Stream: Agent Security - Published: 2026-04-03 - URL: https://raxe.ai/labs/advisories/RAXE-2026-046 - CVEs: CVE-2026-34070 - Detection signatures: 4 - Tags: agent-security, authentication-bypass, cve, deserialization, langchain, path-traversal ### RAXE-2026-045: Hardening Your Environment Against Software Supply Chain Attacks - Severity: CRITICAL - Stream: Supply Chain - Published: 2026-03-31 - URL: https://raxe.ai/labs/advisories/RAXE-2026-045 - CVEs: CVE-2026-33634 - Detection signatures: 0 - Tags: cve, mcp, supply-chain ### RAXE-2026-044: vLLM Hardcoded trust_remote_code Bypass Enables Remote Code Execution via Malicious Model Repositories (CVE-2026-27893) - Severity: HIGH - Stream: Agent Security - Published: 2026-03-27 - URL: https://raxe.ai/labs/advisories/RAXE-2026-044 - CVEs: CVE-2025-66448, CVE-2026-22807, CVE-2026-27893 - Detection signatures: 6 - Tags: agent-security, cve, huggingface, model-loading, nvidia, pytorch, rce, vllm ### RAXE-2026-043: Langflow Unauthenticated Code Injection RCE via Public Flow Build Endpoint (CVE-2026-33017) - Severity: CRITICAL (CVSS 9.8) - Stream: Agent Security - Published: 2026-03-27 - URL: https://raxe.ai/labs/advisories/RAXE-2026-043 - CVEs: CVE-2025-3248, CVE-2026-27966, CVE-2026-33017 - Detection signatures: 3 - Tags: agent-security, authentication-bypass, cve, injection, langflow, prompt-injection, rce ### RAXE-2026-042: llama.cpp GGUF Integer Overflow Heap Buffer Overflow via Crafted Tensor Dimensions (CVE-2026-33298) - Severity: HIGH - Stream: Supply Chain - Published: 2026-03-26 - URL: https://raxe.ai/labs/advisories/RAXE-2026-042 - CVEs: CVE-2026-33298 - Detection signatures: 0 - Tags: aml-t0010, cve, heap-overflow, huggingface, llama.cpp, model-loading, rce, supply-chain ### RAXE-2026-041: Spring AI Vector Store Filter Injection – JSONPath and SQL Injection Bypass Multi-Tenant Access Controls - Severity: HIGH (CVSS 8.6) - Stream: Agent Security - Published: 2026-03-22 - URL: https://raxe.ai/labs/advisories/RAXE-2026-041 - CVEs: CVE-2026-22729, CVE-2026-22730 - Detection signatures: 1 - Tags: agent-security, cve, org.springframework.ai:spring-ai-mariadb-store, org.springframework.ai:spring-ai-vector-store ### RAXE-2026-040: Claude Code Workspace Trust Dialog Bypass via Repository Settings (CVE-2026-33068) - Severity: HIGH (CVSS 7.7) - Stream: Agent Security - Published: 2026-03-20 - URL: https://raxe.ai/labs/advisories/RAXE-2026-040 - CVEs: CVE-2026-33068 - Detection signatures: 1 - Tags: agent-security, aml-t0010-001, anthropic-ai-claude-code, authentication-bypass, cve ### RAXE-2026-039: ONNX Hub Silent Security Warning Bypass Enables Supply Chain Attacks (CVE-2026-28500) - Severity: CRITICAL (CVSS 9.1) - Stream: S3: Supply Chain - Published: 2026-03-20 - URL: https://raxe.ai/labs/advisories/RAXE-2026-039 - CVEs: CVE-2026-28500 - Detection signatures: 2 - Tags: authentication-bypass, cve, model-loading, onnx, supply-chain ### RAXE-2026-038: AnythingLLM Desktop: Streaming XSS to Remote Code Execution - Severity: CRITICAL (CVSS 9.6) - Stream: S4: Prompt Injection / Input Handling - Published: 2026-03-20 - URL: https://raxe.ai/labs/advisories/RAXE-2026-038 - CVEs: CVE-2026-32626 - Detection signatures: 2 - Tags: anythingllm, authentication-bypass, cve, prompt-injection, rce ### RAXE-2026-037: Graphiti Temporal Knowledge Graph Cypher Injection via Unsanitised Search Filters - Severity: HIGH (CVSS 8.1) - Stream: Agent Security - Published: 2026-03-15 - URL: https://raxe.ai/labs/advisories/RAXE-2026-037 - CVEs: CVE-2026-32247 - Detection signatures: 3 - Tags: agent-security, cve, graphiti-core, injection, mcp, prompt-injection ### RAXE-2026-034: MCP Atlassian SSRF: Unauthenticated Server-Side Request Forgery Enabling Credential Theft and Prompt Injection (CVE-2026-27826) - Severity: HIGH - Stream: S2: Agent Security - Published: 2026-03-12 - URL: https://raxe.ai/labs/advisories/RAXE-2026-034 - CVEs: CVE-2026-27826 - Detection signatures: 4 - Tags: agent-security, authentication-bypass, cve, mcp, mcp-atlassian, prompt-injection ### RAXE-2026-033: Flowise LLM Orchestration Platform Six-Vulnerability Cluster: Missing Authentication, File Upload, Auth Bypass, IDOR, Mass Assignment, and SSRF - Severity: CRITICAL (CVSS 9.8) - Stream: S2: Agent Security - Published: 2026-03-12 - URL: https://raxe.ai/labs/advisories/RAXE-2026-033 - CVEs: CVE-2026-30820, CVE-2026-30821, CVE-2026-30822, CVE-2026-30823, CVE-2026-30824, CVE-2026-31829 - Detection signatures: 7 - Tags: agent-security, aml-t0010-001, authentication-bypass, cve, flowise, nvidia, rce ### RAXE-2026-032: claude-code-ui Triple Command Injection (CVE-2026-31975, CVE-2026-31862, CVE-2026-31861) - Severity: CRITICAL (CVSS 9.8) - Stream: Supply Chain - Published: 2026-03-11 - URL: https://raxe.ai/labs/advisories/RAXE-2026-032 - CVEs: CVE-2026-31861, CVE-2026-31862, CVE-2026-31975 - Detection signatures: 3 - Tags: authentication-bypass, cve, injection, rce, siteboon-claude-code-ui, supply-chain ### RAXE-2026-031: HuggingFace smolagents SSRF via LocalPythonExecutor (CVE-2026-2654) - Severity: CRITICAL (CVSS 9.8) - Stream: Agent Security - Published: 2026-03-11 - URL: https://raxe.ai/labs/advisories/RAXE-2026-031 - CVEs: CVE-2026-2654 - Detection signatures: 4 - Tags: agent-security, authentication-bypass, cve, huggingface, prompt-injection, smolagents ### RAXE-2026-030: MLflow Auth Bypass to RCE via Artifact Path Traversal (CVE-2026-2635 + CVE-2026-2033) - Severity: CRITICAL (CVSS 8.1) - Stream: Agent Security - Published: 2026-03-11 - URL: https://raxe.ai/labs/advisories/RAXE-2026-030 - CVEs: CVE-2024-1594, CVE-2024-3573, CVE-2026-2033, CVE-2026-2635 - Detection signatures: 5 - Tags: agent-security, authentication-bypass, cve, mlflow, path-traversal, rce ### RAXE-2026-028: CVE-2026-28795: OpenChatBI Path Traversal via save_report Tool - Severity: CRITICAL (CVSS 9.8) - Stream: Supply Chain - Published: 2026-03-10 - URL: https://raxe.ai/labs/advisories/RAXE-2026-028 - CVEs: CVE-2026-28795 - Detection signatures: 5 - Tags: authentication-bypass, cve, mcp, openchatbi, path-traversal, rce, supply-chain ### RAXE-2026-026: Ray Dashboard Unauthenticated Job Deletion (CVE-2026-27482) - Severity: MEDIUM (CVSS 6.5) - Stream: Supply Chain - Published: 2026-03-09 - URL: https://raxe.ai/labs/advisories/RAXE-2026-026 - CVEs: CVE-2026-27482 - Detection signatures: 4 - Tags: authentication-bypass, cve, ray, supply-chain ### RAXE-2026-025: LangGraph Checkpoint Redis Query Injection (CVE-2026-27022) - Severity: MEDIUM (CVSS 6.5) - Stream: Supply Chain - Published: 2026-03-09 - URL: https://raxe.ai/labs/advisories/RAXE-2026-025 - CVEs: CVE-2026-27022 - Detection signatures: 4 - Tags: cve, injection, langchain, langchain-langgraph-checkpoint-redis, langgraph, redis, supply-chain ### RAXE-2026-024: NVIDIA NeMo Framework Code Injection (CVE-2025-33236) - Severity: HIGH (CVSS 7.8) - Stream: Supply Chain - Published: 2026-03-09 - URL: https://raxe.ai/labs/advisories/RAXE-2026-024 - CVEs: CVE-2025-33236, CVE-2025-33241, CVE-2025-33243, CVE-2025-33245, CVE-2025-33246, CVE-2025-33249, CVE-2025-33250, CVE-2025-33251, CVE-2025-33252, CVE-2025-33253 - Detection signatures: 7 - Tags: cve, deserialization, huggingface, injection, nemo-toolkit, nvidia, pytorch, rce, supply-chain ### RAXE-2026-023: vLLM RCE via auto_map Dynamic Module Loading (CVE-2026-22807) - Severity: HIGH (CVSS 8.8) - Stream: Adversarial ML - Published: 2026-03-09 - URL: https://raxe.ai/labs/advisories/RAXE-2026-023 - CVEs: CVE-2026-22807 - Detection signatures: 2 - Tags: adversarial-ml, cve, huggingface, injection, model-loading, rce, vllm ### RAXE-2026-022: Claude Code Trusted Domain Validation Bypass (CVE-2026-24052) - Severity: HIGH (CVSS 7.4) - Stream: Agent Security - Published: 2026-03-09 - URL: https://raxe.ai/labs/advisories/RAXE-2026-022 - CVEs: CVE-2026-24052, CVE-2026-27735 - Detection signatures: 5 - Tags: agent-security, anthropic-ai-claude-code, authentication-bypass, cve, mcp, path-traversal, prompt-injection ### RAXE-2026-021: MCP Server git_init Path Traversal via Unrestricted Repository Initialisation (CVE-2025-68143) - Severity: MEDIUM (CVSS 6.5) - Stream: Agent Security - Published: 2026-03-09 - URL: https://raxe.ai/labs/advisories/RAXE-2026-021 - CVEs: CVE-2025-68143, CVE-2026-27735 - Detection signatures: 5 - Tags: agent-security, cve, injection, mcp, mcp-server-git, path-traversal, prompt-injection ### RAXE-2026-020: vLLM Remote Code Execution via Video Processing (CVE-2026-22778) - Severity: CRITICAL (CVSS 9.8) - Stream: Adversarial ML - Published: 2026-03-09 - URL: https://raxe.ai/labs/advisories/RAXE-2026-020 - CVEs: CVE-2026-22778 - Detection signatures: 5 - Tags: adversarial-ml, aslr-bypass, authentication-bypass, cve, heap-overflow, memory-corruption, rce, vllm ### RAXE-2026-019: PyTorch weights_only Unpickler Memory Corruption - Severity: HIGH (CVSS 8.8) - Stream: Supply Chain - Published: 2026-03-09 - URL: https://raxe.ai/labs/advisories/RAXE-2026-019 - CVEs: CVE-2026-24747 - Detection signatures: 4 - Tags: aml-t0010, cve, deserialization, heap-overflow, huggingface, memory-corruption, model-loading, pytorch, rce, supply-chain, torch ### RAXE-2026-018: WeKnora MCP Stdio Command Injection RCE (CVE-2026-30861) - Severity: HIGH (CVSS 8.8) - Stream: Agent Security - Published: 2026-03-08 - URL: https://raxe.ai/labs/advisories/RAXE-2026-018 - CVEs: CVE-2026-30861 - Detection signatures: 4 - Tags: agent-security, cve, github.com-tencent-weknora, injection, mcp, path-traversal, rce ### RAXE-2026-017: LangGraph Checkpoint Unsafe Msgpack Deserialisation (CVE-2026-28277) - Severity: MEDIUM (CVSS 6.8) - Stream: Agent Security - Published: 2026-03-09 - URL: https://raxe.ai/labs/advisories/RAXE-2026-017 - CVEs: CVE-2026-28277 - Detection signatures: 2 - Tags: agent-security, cve, deserialization, langchain, langgraph, langgraph-checkpoint ### RAXE-2026-016: Web-Based Indirect Prompt Injection Against AI Agents: Observed in the Wild - Severity: HIGH - Stream: Prompt Injection - Published: 2026-03-06 - URL: https://raxe.ai/labs/advisories/RAXE-2026-016 - Detection signatures: 3 - Tags: aml-t0051, prompt-injection ### RAXE-2026-015: PickleScan Universal Blocklist Bypass and Stdlib RCE Modules - Severity: CRITICAL (CVSS 9.8) - Stream: Supply Chain - Published: 2026-03-06 - URL: https://raxe.ai/labs/advisories/RAXE-2026-015 - Detection signatures: 3 - Tags: aml-t0010, deserialization, huggingface, model-loading, picklescan, pytorch, rce, supply-chain ### RAXE-2026-014: MCP Server Git Path Traversal via Agentic Tool-Use (CVE-2026-27735) - Severity: MEDIUM (CVSS 6.4) - Stream: Agent Security - Published: 2026-03-04 - URL: https://raxe.ai/labs/advisories/RAXE-2026-014 - CVEs: CVE-2026-27735 - Detection signatures: 4 - Tags: agent-security, cve, mcp, mcp-server-git, path-traversal, prompt-injection ### RAXE-2026-013: Langflow CSV Agent Remote Code Execution via Prompt Injection (CVE-2026-27966) - Severity: CRITICAL (CVSS 9.8) - Stream: Agent Security - Published: 2026-03-04 - URL: https://raxe.ai/labs/advisories/RAXE-2026-013 - CVEs: CVE-2026-27966 - Detection signatures: 3 - Tags: agent-security, authentication-bypass, cve, langchain, langflow, prompt-injection, rce ### RAXE-2026-012: Agenta LLMOps Sandbox Escape and SSTI in Evaluator Pipeline (CVE-2026-27952, CVE-2026-27961) - Severity: CRITICAL (CVSS 9.9) - Stream: Agent Security - Published: 2026-03-04 - URL: https://raxe.ai/labs/advisories/RAXE-2026-012 - CVEs: CVE-2026-27952, CVE-2026-27961 - Detection signatures: 3 - Tags: agent-security, agenta, aml-t0049, cve, injection, llmops, rce, sandbox-escape, ssti Total: 47 advisories, 133 detection signatures, 4 research streams ## Research Radar (Machine-Readable) Periodic digest translating arXiv AI security papers into practitioner-focused summaries with act_now/watch/horizon ratings. ### Research Radar #5 — 2026-04-13 - Papers: 4 - URL: https://raxe.ai/labs/radar/radar-2026-005 - Key signals: - Your LLM API router may be stealing your credentials and rewriting your tool calls. - Skill documentation is the new attack surface, and it bypasses alignment where explicit instructions fail. - Even benign, unmodified skills are exploitable through adversarial prompting. - Paper: Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain (arXiv:2604.08407, act_now) - Paper: Supply-Chain Poisoning Attacks Against LLM Coding Agent Skill Ecosystems (arXiv:2604.03081, act_now) - Paper: SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement (arXiv:2604.04989, watch) - Paper: SelfGrader: Stable Jailbreak Detection for Large Language Models using Token-Level Logits (arXiv:2604.01473, watch) ### Research Radar #4 — 2026-04-05 - Papers: 4 - URL: https://raxe.ai/labs/radar/radar-2026-004 - Key signals: - Your agents are contaminating themselves, and no attacker is required. - MCP server detection is now possible, but the attack surface is worse than expected. - The gap between "safe model" and "safe agent" is quantified: 40-75% of attacks succeed. - Paper: No Attacker Needed: Unintentional Cross-User Contamination in Shared-State LLM Agents (arXiv:2604.01350, act_now) - Paper: From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers (arXiv:2604.01905, act_now) - Paper: ClawSafety: "Safe" LLMs, Unsafe Agents (arXiv:2604.01438, act_now) - Paper: CRaFT: Circuit-Guided Refusal Feature Selection via Cross-Layer Transcoders (arXiv:2604.01604, watch) ### Research Radar #3 — 2026-03-29 - Papers: 4 - URL: https://raxe.ai/labs/radar/radar-2026-003 - Key signals: - AI agents are vulnerable before the attacker even tries. - MCP client security is a lottery, and most developers are losing. - Lightweight LLM judges beat purpose-built guardrails – but ensembling makes them worse. - Paper: Mind Your HEARTBEAT! Claw Background Execution Inherently Enables Silent Memory Pollution (arXiv:2603.23064, act_now) - Paper: Model Context Protocol Threat Modeling and Analyzing Vulnerabilities to Prompt Injection with Tool Poisoning (arXiv:2603.22489, act_now) - Paper: Are AI-assisted Development Tools Immune to Prompt Injection? (arXiv:2603.21642, watch) - Paper: Prompt Attack Detection with LLM-as-a-Judge and Mixture-of-Models (arXiv:2603.25176, watch) ### Research Radar #2 — 2026-03-22 - Papers: 7 - URL: https://raxe.ai/labs/radar/radar-2026-002 - Key signals: - The agent skill supply chain is broken – and automated scanners cannot tell you how. - Single-source telemetry has structural limits that no detection tuning can overcome. - Mechanistic understanding of AI safety failures is catching up to the attacks. - Paper: Malicious Or Not: Adding Repository Context to Agent Skill Classification (arXiv:2603.16572, act_now) - Paper: SynthChain: A Synthetic Benchmark and Forensic Analysis of Advanced and Stealthy Software Supply Chain Attacks (arXiv:2603.16694, act_now) - Paper: Agent Privilege Separation in OpenClaw: A Structural Defense Against Prompt Injection (arXiv:2603.13424, act_now) - Paper: VeriGrey: Greybox Agent Validation (arXiv:2603.17639, act_now) - Paper: REFORGE: Multi-modal Attacks Reveal Vulnerable Concept Unlearning in Image Generation Models (arXiv:2603.16576, watch) - Paper: Understanding and Defending VLM Jailbreaks via Jailbreak-Related Representation Shift (arXiv:2603.17372, watch) - Paper: UniSAFE: A Comprehensive Benchmark for Safety Evaluation of Unified Multimodal Models (arXiv:2603.17476, watch) ### Research Radar #1 — 2026-03-17 - Papers: 3 - URL: https://raxe.ai/labs/radar/radar-2026-001 - Key signals: - Compound AI systems may inherit the full CVE attack surface. - Autonomous agent frameworks need execution-layer security, not just prompt filters. - LLMs automate adversarial attacks against ML classifiers. - Paper: Cascade: Composing Software-Hardware Attack Gadgets for Adversarial Threat Amplification in Compound AI Systems (arXiv:2603.12023v1, act_now) - Paper: Uncovering Security Threats and Architecting Defenses in Autonomous Agents: A Case Study of OpenClaw (arXiv:2603.12644v1, act_now) - Paper: LLM-Driven Feature-Level Adversarial Attacks on Android Malware Detectors (arXiv:2512.21404v1, watch) Total: 5 issues, 22 papers reviewed