-
Notifications
You must be signed in to change notification settings - Fork 6
Expand file tree
/
Copy pathAVE-2026-00013.json
More file actions
144 lines (144 loc) · 5.13 KB
/
Copy pathAVE-2026-00013.json
File metadata and controls
144 lines (144 loc) · 5.13 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
{
"ave_id": "AVE-2026-00013",
"schema_version": "1.1.0",
"component_type": "skill",
"title": "Personal data exfiltration via PII collection and transmission in agentic component",
"attack_class": "Data Exfiltration - PII Theft",
"description": "An agentic component instructs the agent to collect personally identifiable information (PII) - names, email addresses, phone numbers, physical addresses, SSNs, passport numbers, credit card numbers - and transmit them to an external endpoint. This enables identity theft, financial fraud, and regulatory violations (GDPR, CCPA) affecting the users whose data the agent has access to.",
"affected_platforms": [
"claude-code",
"cursor",
"codex",
"windsurf",
"any-agent-with-data-access"
],
"affected_registries": [
"clawhub.io",
"agentskills.io",
"github.com/topics/agent-skills"
],
"aivss_score": 6.5,
"cvss_base_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:L",
"owasp_asi": ["ASI01"],
"nist_ai_rmf": [
"MAP-1.5",
"MEASURE-2.5",
"MANAGE-1.3"
],
"mitre_atlas": [
"AML.T0048"
],
"behavioral_fingerprint": "Component instructs the agent to collect PII fields (name, email, phone, address, SSN, passport, credit card) and transmit or store them externally.",
"behavioral_vector": [
"pii-collection",
"data-exfil",
"covert-transmission"
],
"provenance_vector": {
"entry_class": "content",
"payload_surface": "skill instruction body: PII-collection + transmission directive",
"escalation": "instruction_to_capability"
},
"trifecta_profile": {
"requires": [
"private_data",
"external_comms"
]
},
"mitigation": {
"strategy": [
"least_privilege",
"sever_egress"
],
"enforcement_point": "runtime_proxy",
"trifecta_control": "break_external_comms"
},
"mutation_count": 103,
"detection_methodology": "1. Static scan: search for combined patterns of PII field collection (name, email, phone, address, SSN, credit card) with data transmission instructions (send, post, upload, transmit). 2. Semantic analysis: detect instructions directing data collection about individuals combined with exfiltration intent.",
"indicators_of_compromise": [
"Component instructs collection of name, email, phone, address, or financial data",
"Component combines PII collection with instructions to send/transmit the data",
"Outbound HTTP requests observed containing personally identifiable information",
"Agent accesses contact or user data beyond the scope of the stated task"
],
"remediation": "1. Remove the component immediately. 2. Identify what PII may have been accessed and transmitted. 3. Notify affected users per applicable data protection regulations (GDPR, CCPA). 4. Report the attacker endpoint to relevant authorities. 5. Implement data access controls - agents should not have broad access to PII stores.",
"status": "active",
"kill_switch_active": true,
"researcher": "Saray Chak",
"researcher_url": "https://bawbel.io",
"published": "2026-04-20T09:00:00Z",
"last_updated": "2026-08-23T00:00:00Z",
"references": [
{
"tag": "CWE-359",
"text": "CWE-359: Exposure of Private Personal Information to an Unauthorized Actor \u2014 MITRE Common Weakness Enumeration",
"url": "https://cwe.mitre.org/data/definitions/359.html"
},
{
"tag": "CWE-200",
"text": "CWE-200: Exposure of Sensitive Information to an Unauthorized Actor",
"url": "https://cwe.mitre.org/data/definitions/200.html"
},
{
"tag": "OWASP LLM Sensitive Info",
"text": "OWASP Top 10 for LLM Applications \u2014 Sensitive Information Disclosure",
"url": "https://owasp.org/www-project-top-10-for-large-language-model-applications/"
},
{
"tag": "AVE Registry",
"text": "AVE-2026-00013 \u2014 AVE behavioral vulnerability registry",
"url": "https://github.com/aveproject/ave/blob/main/records/AVE-2026-00013.json"
}
],
"aivss": {
"cvss_base": 8,
"aarf": {
"autonomy": 1,
"tool_use": 1,
"multi_agent": 0,
"non_determinism": 0.5,
"self_modification": 0,
"dynamic_identity": 0,
"persistent_memory": 0,
"natural_language_input": 1,
"data_access": 1,
"external_dependencies": 0.5
},
"aars": 5,
"thm": 1,
"mitigation_factor": 1,
"aivss_score": 6.5,
"aivss_severity": "MEDIUM",
"spec_version": "0.8",
"notes": "PII collection + exfil. Confirmed in Smithery sbb-mcp and strale findings."
},
"owasp_mcp": [
"MCP05",
"MCP06"
],
"severity": "MEDIUM",
"evidence_kind_default": "multi_engine",
"detection_stage": "static_detection",
"detection_layer": "content",
"confidence_baseline": 0.83,
"evidence_basis_engines": [
"pattern",
"semgrep",
"yara"
],
"derivable_into": [],
"framework_sources": {
"owasp_mcp": {
"commit": "165fe0f78ef104459237b4a8e0f6e78db9b02391",
"read_date": "2026-09-05"
},
"mitre_atlas": {
"pin_status": "unknown",
"read_date": "2026-08-09"
},
"owasp_asi": {
"version": "2026",
"read_date": "2026-08-23"
}
}
}