The frameworks are the attack surface: nearly a dozen flaws found in major agent stacks
Researchers have disclosed nearly a dozen flaws, several critical, in the agent frameworks enterprises use to build applications. The argument attached is sharper than the vulnerabilities: prompt injection gets the attention while the frameworks that grant agents their tools, credentials and network access get very little.
It is the right place to look. A prompt injection is only as dangerous as what the agent can subsequently do, and what it can do is decided entirely by the framework — which tools are registered, which credentials are in scope, whether the sandbox is real. Injection is the entry; the framework is the blast radius.
Frameworks in this category are also unusually young. Most were written in the last eighteen months, by small teams, under intense feature pressure, in an ecosystem where being first to support a capability matters more commercially than being careful about it. That is a recognisable set of conditions and it has produced predictable results before.
The through-line to the sandbox escape is worth naming. In that case the containment failed at the tooling layer too — a package installer with more connectivity than intended. Not the model. The scaffolding around it.
The Register — Prompt injection isn't the bug, AI agent frameworks are → · MDPI Information — Prompt injection attacks in LLMs and AI agent systems: vulnerabilities, attack vectors and defence mechanisms → · arXiv — Authorization propagation in multi-agent AI systems: identity governance as infrastructure →