Security Audit Reveals 87 Real Vulnerabilities Across Major AI Agent Frameworks
A security audit of over 10 AI agent frameworks using the Correctover CCS scanner uncovered 1,730 findings across 12 codebases, including 87 confirmed production vulnerabilities in actively deployed code. Researchers identified eight critical test areas, with tool authorization enforcement and command injection rated as the most severe risks. A key finding was that most frameworks, including the official MCP Python SDK, define read-only permission flags for tools but never actually enforce them at runtime, leaving all tools effectively writable. The MCP Python SDK alone had 43 instances of this flaw, with additional cases found in Microsoft's AutoGen and Semantic Kernel, FastMCP, Dify, and Griptape. The vulnerability in the MCP Python SDK has been reported to maintainers via HackerOne with a CVSS score of 7.5, and parallel disclosures have been submitted to Microsoft for its affected products.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in