Subscribe
Vulnerability tracking for RAG systems

What's leaking
from your RAG system?

RAGBleed files, dates, and rates vulnerabilities, data leaks, and failure patterns in retrieval-augmented generation systems — as they're found, not as vendors disclose them.

Case Files

85 filed · 2026
#086 27 Aug 2026 High NemoClaw's Windows-host Ollama path skipped the loopback proxy, and DNS rebinding could poison the model's chat template #087 27 Aug 2026 High CircleCI's MCP server treated a client-supplied Host header as its only authentication check #084 26 Aug 2026 Medium ContextForge's prompt-template renderer evaluated stored templates in a plain, unsandboxed Jinja2 environment #085 26 Aug 2026 High Chainlit's MCP stdio launcher allowlisted the executable name and let every argument through unchecked #082 24 Aug 2026 Medium Open WebUI's inline chat models used another user's knowledge attachment without checking who owned it #083 24 Aug 2026 High Open WebUI's SSRF guard checked a DNS answer once and trusted the HTTP client to get the same one twice #080 22 Aug 2026 High Microsoft Agent Framework ran a planted message as code the moment a session was rewound #081 22 Aug 2026 High Google ADK's hidden development assistant wrote and ran attacker code with no login required #078 21 Aug 2026 Medium Splunk MCP Server's credential store deserialized stolen data straight into command execution #079 21 Aug 2026 Medium Open WebUI's knowledge-sync cleanup checked who owned the folder, not which files it deleted #076 20 Aug 2026 High LangGraph's Postgres and SQLite stores matched memory namespaces across tenant boundaries #077 20 Aug 2026 Medium n8n's MCP Client node sent user-supplied server URLs around the platform's own SSRF guard #074 19 Aug 2026 Medium GitHub MCP Server's lockdown-mode cache let one user's session decide trust for everyone else's #075 19 Aug 2026 High A missing nil check in GitHub MCP Server's autocomplete handler let one unauthenticated request kill the process #072 18 Aug 2026 High A race condition in llama.cpp's idle-unload feature let unauthenticated requests turn freed memory into remote code execution #073 18 Aug 2026 Medium Open WebUI's OAuth token exchange endpoint accepted access tokens issued to any other client on the same identity provider #070 17 Aug 2026 Low ContextForge's gateway-test endpoint checked a URL, then let DNS rebinding swap it before connecting #071 17 Aug 2026 High RAGFlow's citation-prompt renderer fed user-controlled text straight into an unsandboxed Jinja2 template #068 15 Aug 2026 High Verba's WebSocket import endpoint let unauthenticated callers turn document ingestion into SSRF #069 15 Aug 2026 High AWS Kiro's agent could rewrite its own MCP config from hidden webpage text, and reload it without approval #064 13 Aug 2026 High LangGraph's checkpoint SQL injection and its msgpack deserialization bug chained into remote code execution #065 13 Aug 2026 Medium Open WebUI's retrieval status endpoint handed out RAG chunking and embedding config with no authentication #062 11 Aug 2026 Medium Open WebUI's Playwright web loader checked the page it fetched, not what that page fetched next #063 11 Aug 2026 Medium Open WebUI's tool endpoints handed out source code to anyone with read-only access #060 10 Aug 2026 Medium Open WebUI's rebuilt SSRF guard still missed IPv4 addresses hidden inside NAT64 IPv6 prefixes #061 10 Aug 2026 Medium Open WebUI's knowledge-search let any user pin a worker with a catastrophically backtracking regex #058 09 Aug 2026 High AWS, Google, and Vercel agent harnesses executed tool calls the model never authorized #059 09 Aug 2026 High A Linux page-cache bug let Claude Cowork's sandboxed agent read and write the entire host Mac #056 08 Aug 2026 High gemini-mcp-tool piped tool arguments into a shell, and a single quote was enough for remote code execution #057 08 Aug 2026 High LiteLLM concatenated the Bearer token straight into a SQL query, exposing every connected provider's credentials #054 07 Aug 2026 High Paperclip's self-registration and import checks chained into unauthenticated remote code execution #055 07 Aug 2026 High Azure DevOps MCP server let a hidden PR-description comment hijack a reviewer's AI agent across projects #052 06 Aug 2026 High Langflow's auto-login endpoint minted superuser tokens for anyone, and a code-validation endpoint ran them as Python #053 06 Aug 2026 High Flowise fixed a sandbox escape by trusting three modules — one of them carried its own unpatched validation gap #050 05 Aug 2026 High n8n's Chat Trigger WebSocket let unauthenticated attackers hijack live human-in-the-loop conversations #051 05 Aug 2026 High LibreChat expanded environment-variable placeholders in user-supplied MCP server URLs, leaking JWT and database secrets #048 04 Aug 2026 Medium vLLM gated malicious model loading with a single assert statement, and Python's optimizer deletes those #049 04 Aug 2026 Low An integer wraparound in pgvector's parallel HNSW index build let one relation's memory leak into another's #044 03 Aug 2026 High Semantic Kernel's default vector store built filter expressions with eval() #045 03 Aug 2026 High Langflow's file-upload endpoint let a crafted filename write files anywhere the process could reach #046 03 Aug 2026 Medium Dify's Plugin Daemon proxy let an unauthenticated request reach internal endpoints #047 03 Aug 2026 High AnythingLLM's default install left its entire HTTP and WebSocket API unauthenticated #042 01 Aug 2026 High Ruflo's MCP bridge exposed 233 tools over HTTP with no authentication at all #043 01 Aug 2026 High LightLLM's prefill-decode WebSocket endpoints deserialize network input with pickle, and the server refuses to bind to localhost #040 31 Jul 2026 High Langflow's /api/v1/responses endpoint let any authenticated user execute another tenant's flow #041 31 Jul 2026 High Flowise's CSV Agent node let prompt injection produce Python that walked past its own sandbox denylist #038 30 Jul 2026 Medium HashiCorp's Consul MCP server could hand one client's Consul token to another #039 30 Jul 2026 High Qdrant's diagnostic logger endpoint let a low-privilege caller overwrite its own config file #036 29 Jul 2026 High LMDeploy's vision-language image loader turned an image URL into a path to cloud credentials #037 29 Jul 2026 High Milvus registered its full REST API on the metrics port with no authentication at all #034 28 Jul 2026 High A prompt injection into CrewAI's Code Interpreter chained into sandbox escape and host RCE #035 28 Jul 2026 Medium Open WebUI's Ollama proxy checked model access on one endpoint and forgot the other four #032 27 Jul 2026 High A malicious dataset chained two code-execution bugs into a breach of Hugging Face's infrastructure #033 27 Jul 2026 High Sentry's MCP server let a forged error event hijack AI coding agents into running attacker code #030 26 Jul 2026 High Open WebUI's SSRF guard silently failed on IPv6, letting web search fetch cloud metadata #031 26 Jul 2026 Medium ToolHive's own SSRF guards existed — but its MCP auth-discovery code never called them #028 25 Jul 2026 High LiteLLM's MCP test endpoints spawned attacker-supplied commands with no admin check #029 25 Jul 2026 Medium A single crafted regex could hang a vLLM inference worker indefinitely #026 24 Jul 2026 High ChromaDB loaded a model before it checked who was asking #027 24 Jul 2026 High A leading single quote in an Origin header turned Verba into an open proxy #016 17 Jul 2026 High Asana's MCP server let one company's AI agent see another company's projects #012 15 Jul 2026 High LlamaIndex let the model itself carry a SQL injection into the vector store #014 06 Jul 2026 High Kong Konnect's MCP server could be tricked into acting as a confused deputy #008 25 Jun 2026 High Dify's tracing feature let anyone wiretap another tenant's conversations #023 08 Jun 2026 High A two-year-old Redis RCE sat undetected until an AI tool found it #024 22 May 2026 High AutoGPT treated its Redis cache as trusted — poisoning one key bought code execution #010 12 May 2026 Medium FastGPT's SSRF protection could be defeated with a well-timed DNS change #011 12 May 2026 High Open WebUI let any user destroy and repopulate someone else's knowledge base #006 09 May 2026 High FastGPT's agent sandbox shipped with authentication turned off #020 07 May 2026 High Ollama's model loader leaked its entire process memory to anyone who asked #007 26 Apr 2026 High Flowise's public chatflow endpoint returned everything, including credentials #017 20 Apr 2026 High nginx-ui's MCP integration had two doors to the same room — only one of them was locked #005 31 Mar 2026 Medium LangGraph's checkpoint store was queryable through its own filter keys #004 30 Mar 2026 Medium A crafted prompt template can read arbitrary files off the server #025 20 Mar 2026 High sglang's inference transport deserializes network input with pickle — and still does #018 02 Mar 2026 High mcp-atlassian's SSRF and file-write flaws chained into a two-request root shell #022 15 Feb 2026 High A 20-year-old encoding bug in PostgreSQL's pgcrypto gave attackers a path to RCE #021 05 Feb 2026 High vLLM could be handed a malicious video and give up the server #013 31 Jan 2026 High AnythingLLM's setup-status endpoint handed out the vector database's API key #015 22 Jan 2026 High MarkItDown's document-fetching tool could be pointed at cloud credentials instead of a document #009 09 Jan 2026 Medium n8n's webhook file handler could be tricked into serving files meant for an AI chatbot's knowledge base #003 06 Jan 2026 High RAGFlow's shared token generator let a public share link unlock a full account #002 05 Jan 2026 High RAGFlow sandbox escape lets low-privileged users run commands on the host #001 02 Jan 2026 High LangChain serialization flaw lets prompt injection exfiltrate secrets #019 15 Dec 2025 Medium Weaviate's backup restore could be tricked into writing files outside its own directory