Prompt Injection Isn't the Bug, AI Agent Frameworks Are
The Register, Wednesday, August 5th, 2026
Researchers found 11 vulnerabilities in major AI agent frameworks that go well beyond prompt injection.
Check Point researchers found critical flaws in enterprise AI frameworks including LangChain, LangGraph, and CrewAI.
The vulnerabilities let attacker-controlled content cross into trusted framework logic, enabling code execution and data theft.
Rather than novel attack classes, the bugs are old vulnerability types, including deserialization issues, SSRF, and path traversal, reappearing across multiple frameworks. Researchers received $17,133.70 in bug bounties, with Microsoft paying $10,000 for a checkpoint deserialization flaw and Google paying $3,133.70 for an authentication bypass.