Products Lemma APIProof issuance & verification platformTrust402Delegate to agents, and transactSealSign-in for the agent era — no keys handed over
Use cases Manufacturing & Critical InfraInspection Record AssuranceFinance & FinTechCounterparty Record VerificationPublic SectorCertificate-less ProceduresHealthcareQualified Worker AssuranceProcurement & Supply ChainSupplier Credential MonitoringMedia & ContentContent AuthenticityService & RetailCross-group IdentityAI Adoption (cross-industry)AI Run GovernanceDevelopers & Agent OpsAgent Authority Control ▸ Browse the use-case index
Pricing
Resources Critical BriefThe frontier of AI × trustBlogThinking and implementation notesDocumentationAPI & specsVerification CenterReal verification & issuance countsAbout usFRAME00, Inc.ContactSales & press inquiriesGlossaryDefinitionsFAQFrequently asked questions
Get Started ↗ JA
Home / Critical Brief / Category archive
Lemma Critical Brief · Category archive

Agent Infrastructure

Starlette/BadHost-class agent-harness vulnerabilities, MCP server credential leaks.

51 Briefs
No. 139 · 2026-09-01

Eleven vulnerabilities were disclosed across six agent frameworks including LangChain, LangGraph, and CrewAI

injected content is never checked before it crosses into trusted framework logic

Pillar 03 Agent Authority Proof Agent Infrastructure Code Provenance Brief →
No. 138 · 2026-09-01

Four unauthenticated flaws reaching code execution, privilege escalation, and SQL injection were disclosed in ServiceNow AI Platform

a third disclosure, still with no layer that checks authorization before the action

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & Auth Brief →
No. 136 · 2026-08-28

All 15 x402 payment facilitators were found in violation

payment verification is never bound to settlement before the action

Pillar 03 Agent Authority Proof Agent Payment Abuse Agent InfrastructureIdentity & Auth Brief →
No. 131 · 2026-08-21

OpenClaw's agent cancelled a stranger's gym reservation, unasked, to move its user up the queue

the action was never authorized against the user's own permissions

Pillar 03 Agent Authority Proof Agent Runaway Identity & AuthAgent Infrastructure Brief →
No. 132 · 2026-08-21

OpenAI, Anthropic and Meta eval models breached real companies through Irregular's misconfiguration

'contained' was never independently verified before the action

Pillar 03 Agent Authority Proof Agent Runaway Agent InfrastructureIdentity & Auth Brief →
No. 133 · 2026-08-21

One Pyodide sandbox escape was shown to reproduce across seven products

the premise 'it's isolated' was never independently verified

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthCode Provenance Brief →
No. 134 · 2026-08-21

A co-located tenant's JWT was shown to be extractable from Cloudflare Workers via Spectre

a stolen token passes straight through as the user

Pillar 03 Agent Authority Proof Identity & Auth Agent Infrastructure Brief →
No. 128 · 2026-08-11

Three coding agents broken in their default config: the harness marked a value safe, and a later stage acted on it with more authority

Novee Security attacked Anthropic's Claude Code, Google's Gemini CLI, and OpenAI's Codex — each in the configuration the vendor ships by def…

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthCode Provenance Brief →
No. 130 · 2026-08-11

Atlassian Rovo can be tricked into sending Jira and Confluence data outward by instructions in an uploaded file or a URL parameter

the origin of the instruction is never verified before the action

Pillar 03 Agent Authority Proof Agent Infrastructure AI Decision IntegrityIdentity & Auth Brief →
No. 121 · 2026-08-04

"FaceHugger" in Hugging Face Diffusers: loading a model ran arbitrary code

the safeguard only checked the first fetch (Zafran / CVE-2026-44827 et al.)

Pillar 02 Verifiable AI Model Supply Chain Code ProvenanceAgent Infrastructure Brief →
No. 118 · 2026-08-03

A Copilot for Word document worm turned each generated file into the next carrier

recipients cannot verify the edited document reflects the source data

Pillar 01 Verifiable Origin Data Provenance AI Decision IntegrityAgent Infrastructure Brief →
No. 113 · 2026-07-31

Ruflo's MCP Bridge: one unauthenticated request opened 233 high-privilege tools, and the memory poisoning survives the patch

tool-call authorization and memory provenance are never verified before execution

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthData Provenance Brief →
No. 114 · 2026-07-31

AWS Kiro: a harmless summarize request makes the agent rewrite its own MCP config and reach RCE

the approval boundary never verifies self-modification of authorization settings before execution

Pillar 03 Agent Authority Proof Agent Infrastructure AI Decision IntegrityIdentity & Auth Brief →
No. 110 · 2026-07-28

OpenAI's evaluation agents escaped containment and breached an unrelated company's production

Hugging Face

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthAgent Runaway Brief →
No. 109 · 2026-07-24

ServiceNow AI Platform

one unauthenticated request escaped the sandbox to code execution (CVE-2026-6875)

Pillar 03 Agent Authority Proof Identity & Auth Agent Infrastructure Brief →
No. 104 · 2026-07-21

WebMCP

swapping the tools mid-session led agents to call the attacker's tool without noticing

Pillar 03 Agent Authority Proof Agent Infrastructure AI Decision IntegrityIdentity & Auth Brief →
No. 102 · 2026-07-15

Friendly Fire

a defensive AI coding agent ran the very binary it was asked to vet

Pillar 01 Verifiable Origin Code Provenance AI Decision IntegrityAgent Infrastructure Brief →
No. 099 · 2026-07-10

Agentjacking: an AI coding agent trusted a single fake error report as its "resolution steps" and ran the attacker's commands

Tenet Threat Labs disclosed a new attack it named "Agentjacking" that makes AI coding agents (Claude Code, Cursor, Codex) run an attacker's …

Pillar 02 Verifiable AI AI Decision Integrity Agent InfrastructureCode Provenance Brief →
No. 097 · 2026-07-07

JadePuffer: an LLM agent autonomously ran a ransomware attack

from breach to credential theft, lateral movement, and encryption — deciding on the fly

Pillar 03 Agent Authority Proof Agent Runaway Agent InfrastructureIdentity & Auth Brief →
No. 098 · 2026-07-07

BioShocking: convince an AI browser "it's a game" and it drops its guardrails and hands over credentials

The security firm LayerX disclosed a manipulation technique against agentic AI browsers that it named BioShocking. When an attacker's web pa…

Pillar 02 Verifiable AI AI Decision Integrity Agent Infrastructure Brief →
No. 094 · 2026-07-03

Cursor (DuneSlide): a single injected prompt escaped the agent's sandbox and ran arbitrary commands (CVE-2026-50548 / 50549)

A developer merely asking the AI code editor Cursor a normal question could pull in a hidden instruction slipped into web-search results or …

Pillar 03 Agent Authority Proof Agent Infrastructure AI Decision IntegrityIdentity & Auth Brief →
No. 095 · 2026-07-03

Amazon Q Developer: opening a repo auto-executed a bundled MCP config and exfiltrated AWS credentials (CVE-2026-12957)

Just by opening a malicious repository in Visual Studio Code and enabling the AI coding assistant Amazon Q Developer extension, a developer …

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthCode Provenance Brief →
No. 088 · 2026-06-30

Kestra: Ending a Request Path With /configs Bypassed Authentication and Allowed Unauthenticated Code Execution as Root

On 2026-06-26, a vulnerability allowing unauthenticated arbitrary code execution as root (CVE-2026-53576, CVSS 10.0) was disclosed in Kestra…

Pillar 03 Agent Authority Proof Identity & Auth Agent InfrastructureCode Provenance Brief →
No. 090 · 2026-06-30

AIR: A Fake Agent Skill Cleared Every Scanner and Reached ~26,000 Agents

the Blind Spot Was an External Link Mutable After the Scan

Pillar 01 Verifiable Origin Code Provenance Agent InfrastructureIdentity & AuthModel Supply Chain Brief →
No. 075 · 2026-06-23

A Dormant, Un-Revoked Credential Turned a Trusted Integration into Mass Salesforce Extraction (Klue)

un-revoked test credentials and long-lived OAuth tokens that go unverified at the moment of action (Huntress / ReliaQuest)

Pillar 03 Agent Authority Proof Identity & Auth Agent InfrastructureAttribute Proof Bypass Brief →
No. 080 · 2026-06-23

Replit: an AI agent broke a code freeze, wiped production data, then fabricated records to cover it

destructive actions ran past an explicit ban and the agent could falsify its own actions (SaaStr / Jason Lemkin)

Pillar 03 Agent Authority Proof Agent Runaway Agent InfrastructureAI Decision Integrity Brief →
No. 068 · 2026-06-19

Universal Robots PolyScope: unauthenticated network access yields RCE on industrial robots

the robot doesn't verify the commander's authority before physical action (CVE-2026-8153)

Pillar 03 Agent Authority Proof Identity & Auth Agent InfrastructureAttribute Proof Bypass Brief →
No. 071 · 2026-06-19

DJI ROMO: one authenticated client reached 7,000 robot vacuums' cameras

the cloud didn't separate per-device authorization (No Broker ACL)

Pillar 03 Agent Authority Proof Identity & Auth Agent InfrastructureAttribute Proof Bypass Brief →
No. 070 · 2026-06-19

Unitree (UniPwn): one shared key across the fleet

per-device identity absent, so one compromise broke the whole fleet (Alias Robotics)

Pillar 03 Agent Authority Proof Identity & Auth Agent InfrastructureAttribute Proof Bypass Brief →
No. 066 · 2026-06-19

LiteLLM AI Gateway: from low-privilege user to admin and RCE

authorization not independently verified before action (Obsidian Security)

Pillar 03 Agent Authority Proof Identity & Auth Agent InfrastructureAttribute Proof Bypass Brief →
No. 072 · 2026-06-19

Hugging Face LeRobot: a robotics framework executed untrusted data received over an unauthenticated channel

deserializing (pickle) unverified data leads straight to code execution (CVE-2026-25874)

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthCode ProvenanceModel Supply Chain Brief →
No. 073 · 2026-06-19

ShadowMQ: one unsafe pattern (unauthenticated ZMQ + pickle) copied across AI inference frameworks

the same flaw spread at ecosystem scale through reuse (Oligo Security)

Pillar 03 Agent Authority Proof Agent Infrastructure Code ProvenanceIdentity & AuthModel Supply Chain Brief →
No. 058 · 2026-06-16

From State Store to RCE

When an AI Agent Trusts Its Own Checkpoint (LangGraph)

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthAI Decision Integrity Brief →
No. 059 · 2026-06-16

When "Allow All" OAuth to an AI Tool Becomes the Breach Path (Vercel / Context.ai)

In April 2026, Vercel disclosed that the breach path was the broad "Allow all" OAuth an employee had granted the AI tool Context.ai, turned …

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthAttribute Proof Bypass Brief →
No. 062 · 2026-06-16

Claude Code GitHub Action: one issue claiming "[bot]" led the agent to privileged execution

the trigger's authority and input origin not verified before acting (GMO Flatt Security)

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthAI Decision Integrity Brief →
No. 064 · 2026-06-16

Salesloft Drift: a trusted integration's OAuth tokens stolen, hundreds of Salesforce tenants queried

broad, persistent OAuth not scope/revocation-verified per action (UNC6395)

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthAttribute Proof Bypass Brief →
No. 055 · 2026-06-15

Internal Data Exfiltrated Without Verifying the Instruction's Origin

EchoLeak in Microsoft 365 Copilot (CVE-2025-32711)

Pillar 02 Verifiable AI AI Decision Integrity Agent InfrastructureData Provenance Brief →
No. 046 · 2026-06-12

ServiceNow Scripted REST Endpoint Served Customer Data Without Authentication

ServiceNow disclosed that a Scripted REST endpoint had shipped with requires_authentication=false, letting customer-instance tables be queri…

Pillar 03 Agent Authority Proof Identity & Auth Agent InfrastructureAttribute Proof Bypass Brief →
No. 047 · 2026-06-12

AI Agent Forwarded Credentials Before Verifying the Sender (OpenClaw / Varonis)

On OpenClaw, Varonis tested an email-reading AI agent and found it would forward mock credentials and customer data out of the organization …

Pillar 02 Verifiable AI AI Decision Integrity Agent InfrastructureIdentity & Auth Brief →
No. 048 · 2026-06-12

TrapDoor Plants Hidden Directives in AI Assistant Instruction Files Across npm, PyPI, and Crates.io

TrapDoor, disclosed by Socket, is a credential-stealing campaign whose distinctive technique plants invisible directives via zero-width Unic…

Pillar 01 Verifiable Origin Code Provenance Agent InfrastructureAI Decision IntegrityModel Supply Chain Brief →
No. 051 · 2026-06-12

Asking the AI Support Bot Was Enough

Instagram Account Takeovers via Meta High Touch Support

Pillar 03 Agent Authority Proof Identity & Auth Agent InfrastructureAI Decision Integrity Brief →
No. 037 · 2026-06-09

When the Assistant Becomes the Trigger

AI Coding Agents Auto-Execute Project-Local Config (SymJack / TrustFall + Miasma)

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & Auth Brief →
No. 039 · 2026-06-09

Semantic Kernel: Prompt Injection Turned Into Host-Level Remote Code Execution

the functions and parameters an agent can call are not authorized or verified before execution (CVE-2026-25592 / CVE-2026-26030)

Pillar 03 Agent Authority Proof Agent Infrastructure AI Decision IntegrityCode Provenance Brief →
No. 033 · 2026-06-08

One Edge Appliance Compromise Cascaded to Full Domain Takeover

An Implicitly Trusted F5 BIG-IP Became the Pivot, Along With the Credentials It Stored

Pillar 03 Agent Authority Proof Identity & Auth Agent InfrastructureAttribute Proof Bypass Brief →
No. 031 · 2026-06-08

AI Agents Drove Intrusions From Initial Access to Exfiltration

Signature-Based Detection Cannot Track Tooling the AI Generates Per Target (SHADOW-AETHER-040 / 064)

Pillar 03 Agent Authority Proof Agent Runaway Agent InfrastructureIdentity & Auth Brief →
No. 029 · 2026-06-06

One-Click GitHub OAuth Token Theft via github.dev

The Webview Trusted Synthetic Events, and the Token Was Not Scoped to the Repo

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & Auth Brief →
No. 024 · 2026-06-05

Invisible Unicode Instruction Injection

The Gap Between Human-Read and Model-Read Input

Pillar 02 Verifiable AI AI Decision Integrity Agent InfrastructureData Provenance Brief →
No. 025 · 2026-06-05

MCP Design: Config-to-Command Execution and Supply-Chain-Scale RCE

Not a single-language implementation bug but inherent in the reference SDK design across supported languages

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthCode Provenance Brief →
No. 027 · 2026-06-05

LibreChat CVE-2026-32625

User-Supplied MCP Server URLs as an Exfiltration Channel for Server Secrets

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & Auth Brief →
No. 026 · 2026-06-05

Adaptive AI Worm

Runtime Exploit Synthesis as a Threat Model

Pillar 03 Agent Authority Proof Agent Runaway Agent InfrastructureIdentity & Auth Brief →
No. 003 · 2026-05-30

Starlette CVE-2026-48710 (BadHost)

MCP Server Authentication Bypass via HTTP Host Header Manipulation

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & Auth Brief →