Skip to content

Update LLM06_ExcessiveAgency.md#840

Open
YeranG30 wants to merge 1 commit into
OWASP:mainfrom
YeranG30:main
Open

Update LLM06_ExcessiveAgency.md#840
YeranG30 wants to merge 1 commit into
OWASP:mainfrom
YeranG30:main

Conversation

@YeranG30

@YeranG30 YeranG30 commented Jun 2, 2026

Copy link
Copy Markdown

Adds a real-world attack scenario to LLM06: Excessive Agency demonstrating sandbox escape via application-layer type-check bypass in PraisonAI, an LLM agent framework. CVE-2026-34938 (CVSS 10.0, fixed in v1.5.90).

Add real-world sandbox escape example to LLM06 (CVE-2026-34938)

Key Changes:

  • Added real-world attack scenario to LLM06:2025 Excessive Agency

Adds a real-world attack scenario to LLM06: Excessive Agency demonstrating sandbox escape via application-layer type-check
bypass in PraisonAI, an LLM agent framework. CVE-2026-34938 (CVSS 10.0, fixed in v1.5.90).

Signed-off-by: Yeran Gamage <74067706+YeranG30@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant