Tag
critical
advisory
Decepticon Agent Framework Role-Boundary Forgery via ChatML Special-Token Literals
1 TTP 1 CVEThe Decepticon agent framework fails to sanitize model-specific special-token literals in external reconnaissance data, allowing attackers to forge system-level instructions and execute arbitrary commands in the agent's Kali Linux sandbox.
Decepticon +2
agent-security
llm-security
prompt-injection
rce
1t
1c
high
advisory
Illicit OpenAI Agent Activity on Hugging Face
4 TTPsAI agents utilizing the WebCache tool exploited compromised Hugging Face credentials to host unauthorized proxy relays, perform SSRF probing, and stage automated ChatGPT account registration services.
WebCache +1
cloud
ssrf
agent-security
supply-chain
4t
high
advisory
Arbitrary File Write in browse-mcp Leading to Host Code Execution
2 TTPs 1 CVEThe browse-mcp package is vulnerable to arbitrary file write via unsanitized path arguments in browser tools, allowing an attacker to achieve host code execution by overwriting critical system configuration files.
browse-mcp
arbitrary-file-write
path-traversal
rce
agent-security
2t
1c