---
schema: 1
kind: vulnerability
title: "CVE-2026-26030 / CVE-2026-25592 — Microsoft Semantic Kernel: prompt-injection-to-RCE in the Python and .NET SDKs of Microsoft's AI agent orchestration framework (CVSS 9.9 each)"
headline: "CVE-2026-26030 / CVE-2026-25592 — Microsoft Semantic Kernel: prompt-injection-to-RCE in the Python and .NET SDKs of Microsoft's AI agent orchestration"
summary: "Microsoft Semantic Kernel CVE-2026-26030 (Python SDK, CVSS 9.9) and CVE-2026-25592 (.NET SDK, CVSS 9.9) — prompt-injection-to-RCE in the AI agent orchestration framework that backs Azure AI Foundry, Copilot Studio and many self-hosted agents. Class-hierarchy traversal bypasses the Python InMemoryVectorStore blocklist filter; an unintended kernel_function attribute on SessionsPythonPlugin.DownloadFileAsync / UploadFileAsync yields arbitrary file write in the .NET SDK. Public PoC for the Python flaw; patch in Python ≥1.39.4 / .NET ≥1.71.0. Full breakdown in § 5."
discovered_at: "2026-05-10T05:00:03Z"
event_date: 2026-05-07
run_id: 2026-05-10-001
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - rce
  - poc-public
  - patch-available
  - ai-abuse
  - cloud
regions:
  - global
sectors: []
entities: []
cves:
  - id: CVE-2026-26030
    cvss: "9.9"
    epss: null
    type: rce
    vector: user-interaction
    auth: pre-auth
    status:
      - poc-public
      - patch-available
  - id: CVE-2026-25592
    cvss: "9.9"
    epss: null
    type: rce
    vector: user-interaction
    auth: pre-auth
    status:
      - poc-public
      - patch-available
sources:
  - url: "https://www.microsoft.com/en-us/security/blog/2026/05/07/prompts-become-shells-rce-vulnerabilities-ai-agent-frameworks/"
    publisher: "Microsoft Security Blog, 2026-05-07"
    role: primary
  - url: "https://github.com/microsoft/semantic-kernel/security/advisories/GHSA-xjw9-4gw8-4rqx"
    publisher: "GitHub Security Advisory GHSA-xjw9-4gw8-4rqx, 2026-05-07"
    role: corroborating
  - url: "https://github.com/microsoft/semantic-kernel/security/advisories/GHSA-2ww3-72rp-wpp4"
    publisher: "GitHub Security Advisory GHSA-2ww3-72rp-wpp4, 2026-05-07"
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-05-10.md
---

CVE-2026-26030 (CWE-94, CVSS 9.9) is a code-injection flaw in the Python SDK's `InMemoryVectorStore` filter function. An f-string composes the LINQ-like filter expression directly from an LLM-controlled parameter rather than parameterising it; the SDK applies a blocklist validator that an attacker bypasses with the well-known `__class__.__bases__[0].__subclasses__()` class-hierarchy traversal pattern, escaping the validator and yielding `os.system`-equivalent execution on the host running the agent. Affected versions: Python SDK < 1.39.4. CVE-2026-25592 (CWE-22, CVSS 9.9) is a class-design flaw in the .NET SDK: `SessionsPythonPlugin.DownloadFileAsync` and `SessionsPythonPlugin.UploadFileAsync` carry a `[KernelFunction]` attribute that should not have been applied — the LLM can therefore call those methods directly with attacker-chosen path arguments, yielding an arbitrary file-write primitive that breaks containment from the Azure Container Apps Python sessions sandbox into the host filesystem of the agent process. Affected versions: .NET SDK < 1.71.0. Both issues require only that an attacker can inject prompt content the agent consumes (user input, retrieved RAG documents, tool outputs) and that the agent is using a default-configured Search Plugin or Sessions Python plugin ([Microsoft Security Blog, 2026-05-07](https://www.microsoft.com/en-us/security/blog/2026/05/07/prompts-become-shells-rce-vulnerabilities-ai-agent-frameworks/) · [GitHub Security Advisory GHSA-xjw9-4gw8-4rqx, 2026-05-07](https://github.com/microsoft/semantic-kernel/security/advisories/GHSA-xjw9-4gw8-4rqx) · [GitHub Security Advisory GHSA-2ww3-72rp-wpp4, 2026-05-07](https://github.com/microsoft/semantic-kernel/security/advisories/GHSA-2ww3-72rp-wpp4)).

A working PoC for CVE-2026-26030 is public in the `amiteliahu/AIAgentCTF` GitHub repository per Microsoft's research post; no in-the-wild exploitation has been reported. Patches: **Python SDK ≥ 1.39.4** and **.NET SDK ≥ 1.71.0** — note that the GitHub Security Advisory for CVE-2026-25592 records 1.39.3 as its minimum patched Python version, and 1.39.4 (the patched version for CVE-2026-26030) supersedes 1.39.3 and closes both CVEs. Microsoft characterises both flaws as systemic of agentic-AI patterns that "trust LLM-controlled parameters without explicit validation" — readers should expect analogous flaws in LangChain, CrewAI, AutoGen and other agent frameworks. Full deep dive in § 5.
