-
Notifications
You must be signed in to change notification settings - Fork 6
Expand file tree
/
Copy pathAVE-2026-00003.json
More file actions
142 lines (142 loc) · 4.85 KB
/
Copy pathAVE-2026-00003.json
File metadata and controls
142 lines (142 loc) · 4.85 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
{
"ave_id": "AVE-2026-00003",
"schema_version": "1.1.0",
"component_type": "skill",
"title": "Credential exfiltration via agent instruction",
"attack_class": "Data Exfiltration - Credential Theft",
"description": "A skill file instructs the agent to read environment variables, configuration files, or credential stores and transmit their contents to an external destination. The agent follows these instructions as part of normal task execution, treating the credential collection as a legitimate step.",
"affected_platforms": [
"claude-code",
"cursor",
"codex",
"any-agent-with-env-access"
],
"affected_registries": [
"clawhub.io",
"smithery.ai",
"skills.sh"
],
"aivss_score": 6.8,
"cvss_base_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N",
"owasp_asi": ["ASI01"],
"owasp_mcp": [
"MCP01"
],
"nist_ai_rmf": [
"MAP-1.5",
"MEASURE-2.5",
"MANAGE-1.3"
],
"mitre_atlas": [
"AML.T0048"
],
"behavioral_fingerprint": "Component instructs agent to read and transmit environment variables, API keys, or other credentials to an external destination.",
"behavioral_vector": [
"credential-read",
"data-exfil",
"env-access"
],
"provenance_vector": {
"entry_class": "content",
"payload_surface": "skill instruction body: environment/credential read + external send",
"escalation": "instruction_to_capability"
},
"trifecta_profile": {
"requires": [
"private_data",
"external_comms"
]
},
"mitigation": {
"strategy": [
"least_privilege",
"sever_egress"
],
"enforcement_point": "runtime_proxy",
"trifecta_control": "break_external_comms"
},
"mutation_count": 12,
"detection_methodology": "1. Static scan: search for patterns matching this attack class in component content.\n2. Semantic analysis: an LLM-based reviewer flags behavioral directives in component content.\n3. Behavioral sandbox: monitor agent behavior during initialization for unexpected actions.",
"indicators_of_compromise": [
"Component references os.environ, process.env, or similar environment access APIs",
"Component instructs agent to read .env files, config files, or credential stores",
"Component includes instructions to send or transmit data to an external URL or API",
"Outbound network request containing credential-shaped data observed after skill execution"
],
"aivss": {
"cvss_base": 8.5,
"aarf": {
"autonomy": 1,
"tool_use": 1,
"multi_agent": 0,
"non_determinism": 0.5,
"self_modification": 0,
"dynamic_identity": 0,
"persistent_memory": 0,
"natural_language_input": 1,
"data_access": 1,
"external_dependencies": 0.5
},
"aars": 5,
"thm": 1,
"mitigation_factor": 1,
"aivss_score": 6.8,
"aivss_severity": "MEDIUM",
"spec_version": "0.8",
"notes": "AARF scores reflect typical skill deployment in agentic workflows. See SPEC.md for factor definitions."
},
"remediation": "1. Remove the component immediately.\n2. Rotate all environment variables and API keys accessible to the agent.\n3. Review outbound network logs for credential-shaped data.\n4. Audit all tool calls and external requests made during the exposure window.",
"status": "active",
"kill_switch_active": false,
"researcher": "Saray Chak",
"researcher_url": "https://bawbel.io",
"published": "2026-04-01T09:00:00Z",
"last_updated": "2026-08-23T00:00:00Z",
"references": [
{
"tag": "CWE-522",
"text": "CWE-522: Insufficiently Protected Credentials \u2014 MITRE Common Weakness Enumeration",
"url": "https://cwe.mitre.org/data/definitions/522.html"
},
{
"tag": "MITRE ATT&CK T1552",
"text": "MITRE ATT&CK \u2014 T1552: Unsecured Credentials",
"url": "https://attack.mitre.org/techniques/T1552/"
},
{
"tag": "OWASP LLM Sensitive Info",
"text": "OWASP Top 10 for LLM Applications \u2014 Sensitive Information Disclosure",
"url": "https://owasp.org/www-project-top-10-for-large-language-model-applications/"
},
{
"tag": "AVE Registry",
"text": "AVE-2026-00003 \u2014 AVE behavioral vulnerability registry",
"url": "https://github.com/aveproject/ave/blob/main/records/AVE-2026-00003.json"
}
],
"severity": "MEDIUM",
"evidence_kind_default": "multi_engine",
"detection_stage": "static_detection",
"detection_layer": "content",
"confidence_baseline": 0.83,
"evidence_basis_engines": [
"pattern",
"semgrep",
"yara"
],
"derivable_into": [],
"framework_sources": {
"owasp_mcp": {
"commit": "165fe0f78ef104459237b4a8e0f6e78db9b02391",
"read_date": "2026-09-05"
},
"mitre_atlas": {
"pin_status": "unknown",
"read_date": "2026-08-09"
},
"owasp_asi": {
"version": "2026",
"read_date": "2026-08-23"
}
}
}