Fetching from the wire…
Public story · 2026-08-09 · high
Two of the 11 bugs paid real bounties, $10,000 from Microsoft and $3,133.70 from Google.
Why now: The Register reported the findings on August 5, turning Check Point's Black Hat 2026 disclosure into a public patch list for all six maintainers.
Check Point researchers found 11 vulnerabilities across six AI agent frameworks, including LangChain, CrewAI and Google's ADK.
Two of the flaws paid bounties, $10,000 from Microsoft and $3,133.70 from Google, for reaching code a normal session never touches.
Yarden Porat and Shahar Tal presented the work at Black Hat 2026. The other three are LangGraph, AutoGen and Microsoft Agent Framework.
The bug classes themselves are ordinary: insecure deserialization, server-side request forgery, path traversal, use-after-free. Check Point argues that's exactly the point, per The Register. Prompt-controlled content crosses into the framework's trusted logic itself.
In Microsoft Agent Framework, one user could plant a payload through prompt injection, then have it fire when a different user reloaded their session. That checkpoint-deserialization bug paid $10,000.
Google ADK shipped with an unauthenticated HTTP API turned on by default that executed arbitrary Python and exposed service-account credentials. That flaw paid $3,133.70.
These are server bugs delivered by an LLM, not new prompt-injection flaws. The fix is input validation the frameworks skipped, not smarter prompt filters. Whether the six maintainers patch the deserialization and SSRF paths, or just ship more injection filters, is the thing to watch.
A related report from the same window found attackers scanning for exposed MCP servers, 49 distinct IPs over 14 days. The framework layer isn't the only piece of the agent stack under active probing.
The Register reported the findings on August 5, turning Check Point's Black Hat 2026 disclosure into a public patch list for all six maintainers.
Each link below shares sources, entities, or timing with this story.
LangChain, LangGraph, CrewAI, AutoGen, Microsoft Agent Framework, and Google ADK, presented at Black Hat (The Register). Insecure deserialization, SSRF, path traversal, use-after-free. That's the point: prompt-controlled content crosses into trusted framework logic, and then i...
Escaped quotes and curly dollar signs planted in sender-name fields fooled six frontier models, beating purpose-built defenses half the time.
A new analysis of AP2 v0.2 found eight high-severity gaps where signed payment mandates don't cover the steps that set up the transaction.
Check Point traced the breach to one operator who used Claude Code for network access and GPT-4.1 to analyze stolen data.
Zero Day Initiative scanned 19,000 servers and put 600 to 1,650 as exploitable, with 42% of vulnerable repos tracing to code AI coding tools wrote.
Tracebit's canary text cut admin escalation from 57% to 5% across five frontier models, but the trick only fools agents built with guardrails.
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.