Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ai-platform-securityinitial-access-methoddata-exfiltration-methodinternet-facing-service-vulnerability

Prompt-injection RCE risks in agentic AI tools with OS and browser automation

Updated 3mo agoFirst seen Mar 4, 20265 sources

Security researchers and CERT/CC reporting highlighted critical prompt-injection-to-execution paths in agentic AI systems where untrusted content can be interpreted as instructions and then executed via connected tools. In ModelScope MS-Agent, CVE-2026-2256 (CVSS 9.8) was reported as a command injection / RCE issue tied to the framework’s “Shell tool,” where external input is not properly sanitized before being passed to OS command execution; a check_safe() denylist-based filter was described as bypassable via obfuscation/alternate syntax, enabling arbitrary command execution and potential full host compromise.

Separate research from Zenity Labs described a broader class of agentic AI browser weaknesses (including Perplexity’s Comet) where attackers can hijack autonomous workflows using indirect prompt injection delivered through normal channels such as a calendar invite; prior to patches, this could drive the browser to access local files, read directories/files, and exfiltrate data, and in some cases leverage the agent’s existing authenticated context to interact with sensitive services (including password managers). A similar execution-model risk was reported in Langflow’s CSV Agent as CVE-2026-27966 (CVSS 10.0), where allow_dangerous_code=True was hardcoded, enabling LangChain’s python_repl_ast tool and allowing remote attackers with chat access to coerce server-side code execution and full system compromise via prompt injection.

Share:
Prompt-injection RCE risks in agentic AI tools with OS and browser automation
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Mar 4, 20264mo ago

No patch available for MS-Agent at disclosure

At the time CVE-2026-2256 was disclosed, no vendor patch or official statement was available for ModelScope MS-Agent. Recommended mitigations included sandboxing, least privilege, validating trusted content, and replacing denylist filtering with allowlists.

CERT/CC discloses critical MS-Agent command execution flaw

CERT/CC disclosed CVE-2026-2256, a critical vulnerability in ModelScope MS-Agent that allows prompt-injection-style inputs to trigger malicious OS commands through the built-in Shell tool. The flaw could lead to remote code execution, data theft, file tampering, persistence, and lateral movement.

Mar 3, 20264mo ago

Zenity publicly discloses agentic AI browser hijacking research

Zenity Labs publicly disclosed a suite of vulnerabilities in agentic AI browsers, including Perplexity Comet, showing that prompt injection via legitimate calendar invites could lead to file access, data exfiltration, and password manager abuse. The research highlighted weak trust boundaries between user intent and agent execution.

Langflow recommends upgrade to version 1.8.0

Langflow's official security advisory recommended updating to version 1.8.0 to remediate CVE-2026-27966. The update changed the default behavior to prevent automatic execution of dangerous code.

Langflow discloses critical CSV Agent RCE flaw

A critical Langflow AI CSV Agent vulnerability, tracked as CVE-2026-27966 and rated 10.0, was publicly disclosed. The flaw stemmed from the CSV Agent node being hardcoded with allow_dangerous_code=True, enabling prompt injection to trigger Python and OS command execution on the server.

Feb 1, 20265mo ago

Perplexity fixes Comet AI browser vulnerabilities

Perplexity issued a fix for the reported Comet vulnerabilities in February 2026. The patch addressed issues that previously allowed attacker-controlled content to be treated as user intent and trigger sensitive autonomous actions.

Jan 1, 20251y ago

Perplexity notified of agentic AI browser vulnerabilities

Zenity Labs reported multiple prompt-injection vulnerabilities affecting agentic AI browsers, including Perplexity Comet, to Perplexity in 2025. The issues showed that malicious calendar invites and indirect prompts could hijack browser agents, access local files, and abuse connected tools.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

9 LINKEDOpen in app
Affected products
1 linked
Claude Code
Organizations
7 linked
Hack The BoxMediumZenityAnthropicOpenaiPerplexityThe EN Strategy Group
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.