Source · DiggingBeagle record
When prompts become shells: RCE vulnerabilities in AI agent frameworks
Microsoft's technical write-up of Semantic Kernel vulnerabilities, including the CVE-2026-26030 prompt-injection-to-RCE path and affected configuration.
- Published
- May 7, 2026
- Accessed
- Sep 14, 2026
- Publisher
- Microsoft Defender Security Research Team
- Source type
- primary
- Version
- 2026-05-07
- Rights
- Public web source; citation and short excerpt only.
Each support, contradiction or context label applies to a cited Claim, not to a whole Case.
Source record
Microsoft says CVE-2026-26030 can turn a model-controlled Search Plugin parameter into host code execution when the vulnerable In-Memory Vector Store filter is used.
Claim-level citations (3)
- supportsSemantic Kernel prompt injection reached host code execution: Microsoft reports that CVE-2026-26030 can turn prompt injection into host remote code execution when the agent uses the affected Search Plugin and In-Memory Vector Store filter path.
CVE-2026-26030 section
- supportsSemantic Kernel prompt injection reached host code execution: Microsoft demonstrated an AST-validation bypass that traversed Python class metadata to load os and execute a shell command.
Exploit and validator analysis
- supportsSemantic Kernel prompt injection reached host code execution: Microsoft traces the exploit to model-controlled string interpolation into a Python lambda expression that is executed with eval().
Unsafe string interpolation
Cite this record
DiggingBeagle. “When prompts become shells: RCE vulnerabilities in AI agent frameworks.” Published May 7, 2026 · Accessed Sep 14, 2026. https://diggingbeagle.com/sources/when-prompts-become-shells-rce-vulnerabilities-in-ai-agent-frameworks/
Citation guidance