-
Notifications
You must be signed in to change notification settings - Fork 6
Expand file tree
/
Copy pathAVE-2026-00012.json
More file actions
141 lines (141 loc) · 4.9 KB
/
Copy pathAVE-2026-00012.json
File metadata and controls
141 lines (141 loc) · 4.9 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
{
"ave_id": "AVE-2026-00012",
"schema_version": "1.1.0",
"component_type": "skill",
"title": "Capability escalation via false permission grant in agentic component",
"attack_class": "Privilege Escalation - Permission Grant",
"description": "An agentic component falsely asserts that the agent has been granted elevated permissions - 'you now have permission to', 'you are now allowed to access' - convincing the agent to perform actions it would otherwise refuse. This exploits the agent's tendency to defer to authority claims within its instruction context.",
"affected_platforms": [
"claude-code",
"cursor",
"codex",
"windsurf",
"any-skill-compatible-agent"
],
"affected_registries": [
"clawhub.io",
"agentskills.io",
"github.com/topics/agent-skills"
],
"aivss_score": 4.5,
"cvss_base_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L",
"owasp_asi": ["ASI01"],
"nist_ai_rmf": [
"MAP-1.5",
"MEASURE-2.5",
"MANAGE-1.3"
],
"mitre_atlas": [
"AML.T0051"
],
"behavioral_fingerprint": "Component asserts that elevated permissions have been granted to the agent, claiming authority to override normal operational boundaries.",
"behavioral_vector": [
"false-permission-grant",
"privilege-escalation",
"authority-claim"
],
"provenance_vector": {
"entry_class": "content",
"payload_surface": "skill instruction body: false permission-grant claim",
"escalation": "instruction_to_capability"
},
"trifecta_profile": {
"requires": [
"untrusted_content"
]
},
"mitigation": {
"strategy": [
"verify_identity",
"deny_by_default"
],
"enforcement_point": "agent_framework",
"trifecta_control": "break_untrusted_content"
},
"mutation_count": 92,
"detection_methodology": "1. Static scan: search for false permission grants (you now have permission, you are now allowed to, your restrictions have been lifted, you have been granted access). 2. Semantic analysis: detect instructions claiming to grant the agent elevated capabilities or override existing restrictions.",
"indicators_of_compromise": [
"Component contains 'you now have permission to' or 'you are now allowed to'",
"Component claims the agent's restrictions have been lifted",
"Component asserts special access has been granted by a developer or operator",
"Agent performs previously refused actions after component installation"
],
"remediation": "1. Remove the component. 2. Permissions must come from the system prompt, never from component files. 3. Implement permission hierarchy - component instructions cannot escalate beyond system prompt boundaries. 4. Review agent actions for privilege escalation attempts.",
"status": "active",
"kill_switch_active": true,
"researcher": "Saray Chak",
"researcher_url": "https://bawbel.io",
"published": "2026-04-20T09:00:00Z",
"last_updated": "2026-08-26T00:00:00Z",
"references": [
{
"tag": "CWE-269",
"text": "CWE-269: Improper Privilege Management \u2014 MITRE Common Weakness Enumeration",
"url": "https://cwe.mitre.org/data/definitions/269.html"
},
{
"tag": "MITRE ATT&CK T1548",
"text": "MITRE ATT&CK \u2014 T1548: Abuse Elevation Control Mechanism",
"url": "https://attack.mitre.org/techniques/T1548/"
},
{
"tag": "OWASP LLM Excessive Agency",
"text": "OWASP Top 10 for LLM Applications \u2014 Excessive Agency",
"url": "https://owasp.org/www-project-top-10-for-large-language-model-applications/"
},
{
"tag": "AVE Registry",
"text": "AVE-2026-00012 \u2014 AVE behavioral vulnerability registry",
"url": "https://github.com/aveproject/ave/blob/main/records/AVE-2026-00012.json"
}
],
"aivss": {
"cvss_base": 7.8,
"aarf": {
"autonomy": 1,
"tool_use": 1,
"multi_agent": 0.5,
"non_determinism": 0.5,
"self_modification": 0.5,
"dynamic_identity": 1,
"persistent_memory": 0.5,
"natural_language_input": 1,
"data_access": 0.5,
"external_dependencies": 0
},
"aars": 6.5,
"thm": 0.75,
"mitigation_factor": 0.83,
"aivss_score": 4.5,
"aivss_severity": "MEDIUM",
"spec_version": "0.8",
"notes": "Claims elevated permissions. Dynamic identity is primary vector."
},
"owasp_mcp": [
"MCP07"
],
"severity": "MEDIUM",
"evidence_kind_default": "tool_description_pattern",
"detection_stage": "static_detection",
"detection_layer": "content",
"confidence_baseline": 0.65,
"evidence_basis_engines": [
"pattern",
"semgrep"
],
"derivable_into": [],
"framework_sources": {
"owasp_mcp": {
"commit": "165fe0f78ef104459237b4a8e0f6e78db9b02391",
"read_date": "2026-09-05"
},
"mitre_atlas": {
"pin_status": "unknown",
"read_date": "2026-08-09"
},
"owasp_asi": {
"version": "2026",
"read_date": "2026-08-23"
}
}
}