Live AI Security Brief for August 3, 2026: Agents, Prompt Injection, and Model Risk

Live AI Security Brief for August 3, 2026: Agents, Prompt Injection, and Model Risk

Verified AI security news and advisories covering agent frameworks, prompt injection, tool access, sandboxing, model evaluation, and sensitive data boundaries.

Agent and model risk

AI security incidents increasingly cross the boundary between model output and real tools. The key review is not only what a model can say, but what its agent harness, connectors, credentials, network access, and execution environment allow it to do.

For August 3, 2026, the lead development is CVE-2026-55255: Langflow cross-user flow authorization bypass. Start by confirming where Langflow Langflow before 1.9.1 is deployed, who owns it, and whether the affected path is reachable. The remaining items below add the product-specific context needed to turn the headline into an owned security decision.

AI security developments

CVE-2026-55255: Langflow cross-user flow authorization bypass

NIST NVD and CISA KEV | July 7, 2026 | Known Exploited | CVSS 8.4 | Langflow Langflow before 1.9.1

Before version 1.9.1, an authenticated attacker could specify another user's flow ID and execute that flow. The CNA rates the issue 8.4 High, and CISA lists active exploitation.

Why it matters: Langflow Langflow before 1.9.1 can combine untrusted text with connectors, stored credentials, and tool permissions. The meaningful risk is what the surrounding agent is allowed to read, change, or send.

What to verify: Test with hostile input in an isolated environment, inspect connector scopes and retained context, require approval for sensitive actions, and confirm that tool calls are logged and attributable.

CISA remediation date: 2026-07-10. Apply the current Langflow fix and follow CISA KEV remediation guidance.

Operational focus: Inventory tool permissions, connector access, stored credentials, and network reach available to the agent.

Open the original NIST NVD and CISA KEV record

CVE-2026-67357: ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP…

NIST National Vulnerability Database | August 2, 2026 | HIGH | CVSS 7.7

ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can retrieve the cluster token and use it with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate root and achieve full server compromise.

Why it matters: CVE-2026-67357 may reveal information that enables follow-on access even when it does not directly execute code. Tokens, configuration, keys, and internal topology deserve separate review.

What to verify: Determine what data the affected path could return, inspect access logs, revoke exposed credentials, reduce response detail where possible, and confirm the patch closes the same request path.

Operational focus: Treat repository text, retrieved documents, web pages, and user prompts as untrusted input.

Open the original NIST National Vulnerability Database record

CVE-2026-68578: ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the…

NIST National Vulnerability Database | August 2, 2026 | HIGH | CVSS 7.7

ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema mutations, and execute arbitrary JavaScript code via the query tool.

Why it matters: CVE-2026-68578 should be evaluated as part of the complete model, agent, data, connector, and tool-permission system.

What to verify: Separate confirmed applicability from broad advisory language, assign the remediation decision, and keep any exception visible with an expiry date.

Operational focus: Require approvals and durable logs before an agent changes data or invokes sensitive tools.

Continue reading the full briefing.

Corrections and tips

Need to add context to this briefing?

Send corrections, security tips, source updates, or collaboration notes through the contact page so the editorial team can review them properly.

Contact InfoSecNexus