AI Agent Frameworks Exposed to Critical Security Flaws, Researchers Warn
Researchers from Check Point have identified critical security vulnerabilities in AI agent frameworks used by enterprises to build applications. These flaws, discovered in frameworks such as LangChain, LangGraph, CrewAI, AutoGen, Microsoft Agent Framework, and Google ADK, extend beyond prompt injection issues. The vulnerabilities allow attacker-controlled content to influence trusted framework logic, posing significant security risks. The researchers disclosed 11 vulnerabilities, including a critical deserialization bug in Microsoft Agent Framework that could lead to remote code execution. Microsoft has addressed the issue, while Google has partially fixed a similar flaw in its ADK framework.