Researchers disclose 11 security flaws in LangChain, CrewAI, AutoGen, Microsoft Agent Framework, and Google ADK

Researchers say multiple popular AI agent frameworks used to build enterprise apps contained serious security flaws that could let attacker-controlled content escape normal data handling and affect trusted app logic. Check Point disclosed 11 vulnerabilities across LangChain, LangGraph, CrewAI, AutoGen, Microsoft Agent Framework, and Google ADK, including a critical insecure deserialization issue in Microsoft Agent Framework that could lead to remote code execution when untrusted checkpoint data is loaded after prompt injection; Microsoft says it fixed the issue but did not assign a CVE because the framework was not generally available.
Why it matters: Organizations experimenting with AI agents may be exposing email, files, databases, and internal workflows to older software-security bugs dressed up as AI issues. Teams using these frameworks should review vendor advisories, update affected components, and treat untrusted model inputs and saved agent state as potentially hostile.

Sources

Prompt injection isn't the bug, AI agent frameworks are
2026.08.05 100% relevant
This article establishes a concrete vulnerability-disclosure story centered on 11 flaws across specific AI agent frameworks, including a Microsoft Agent Framework remote-code-execution bug and additional issues in Google ADK and other widely used frameworks.
← Back to all stories