When prompts become shells: RCE vulnerabilities in AI agent frameworks
ID: 5f6c39d2-6850-5e37-8dd6-bdfa2fcb9359
STIX ID: report--5f6c39d2-6850-5e37-8dd6-bdfa2fcb9359
Feed Name: Microsoft Security
Date Published: 2026-05-07
Date Updated: 2026-05-07
Author: Microsoft Defender Security Research Team, Uri Oren, Amit Eliahu and Dor Edry
This report details the discovery and responsible disclosure of two critical vulnerabilities in Microsoft Semantic Kernel—an eval-based filter injection in the In-Memory Vector Store (CVE-2026-26030) enabling host RCE via crafted prompts, and an exposed file-download tool in SessionsPythonPlugin (CVE-2026-25592) enabling arbitrary host file writes and sandbox escape. The authors describe exploitation chains, provide proof-of-concept behavior (including spawning calc.exe), recommend immediate upgrades and defense-in-depth mitigations, and supply hunting queries and remediation guidance to detect and respond to potential compromises.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
