logo

When prompts become shells: RCE vulnerabilities in AI agent frameworks

ID: 5f6c39d2-6850-5e37-8dd6-bdfa2fcb9359

STIX ID: report--5f6c39d2-6850-5e37-8dd6-bdfa2fcb9359

Feed Name: Microsoft Security

Threat Score
80/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Microsoft Defender Security Research Team, Uri Oren, Amit Eliahu and Dor Edry

...
...

This report details the discovery and responsible disclosure of two critical vulnerabilities in Microsoft Semantic Kernel—an eval-based filter injection in the In-Memory Vector Store (CVE-2026-26030) enabling host RCE via crafted prompts, and an exposed file-download tool in SessionsPythonPlugin (CVE-2026-25592) enabling arbitrary host file writes and sandbox escape. The authors describe exploitation chains, provide proof-of-concept behavior (including spawning calc.exe), recommend immediate upgrades and defense-in-depth mitigations, and supply hunting queries and remediation guidance to detect and respond to potential compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.