Microsoft Security disclosed on May 8, 2026 two critical remote code execution vulnerabilities in Microsoft Semantic Kernel, an open-source AI agent framework with over 27,000 GitHub stars. CVE-2026-25592 and CVE-2026-26030 allowed attackers to achieve unauthorized code execution through prompt injection attacks exploiting the framework's In-Memory Vector Store filter function. Microsoft fixed both vulnerabilities in version 1.39.4 or higher.
AI agent security risks
- ▪If an attacker can control the parameters passed into AI agent plugins via prompt injection, the agent may be driven to perform actions beyond its intended use
Semantic Kernel vulnerabilities
- ▪The article about Microsoft Semantic Kernel vulnerabilities was published on May 8, 2026
- ▪CVE-2026-25592 and CVE-2026-26030 could allow an attacker to achieve unauthorized code execution by leveraging injection attacks specifically targeted at agents built within Microsoft Semantic Kernel
- ▪CVE-2026-25592 and CVE-2026-26030 in Microsoft Semantic Kernel have been fixed
- ▪Microsoft Semantic Kernel is an open-source framework for building AI agents and integrating AI models into applications with over 27,000 stars on GitHub
- ▪Two critical vulnerabilities identified in Microsoft Semantic Kernel are CVE-2026-25592 and CVE-2026-26030
CVE-2026-26030 exploitation mechanics
- ▪The default filter function in Microsoft Semantic Kernel's In-Memory Vector Store is implemented as a Python lambda expression executed using eval()
- ▪CVE-2026-25592 allows an attacker to bypass a cloud-hosted sandbox, write a malicious payload directly to the host device's Windows Startup folder, and achieve full remote code execution with a single prompt
- ▪CVE-2026-26030 enables an attacker to achieve remote code execution from a prompt when both required conditions are met
- ▪CVE-2026-26030 exploitation requires the attacker to have a prompt injection vector allowing influence over the agent's inputs
- ▪CVE-2026-26030 exploitation requires the targeted agent to have the Search Plugin backed by In-Memory Vector Store functionality using the default configuration
- ▪The vulnerability in Microsoft Semantic Kernel's default filter function is that kwargs[param.name] is AI model-controlled and not sanitized
Blocklist bypass technique
- ▪The Microsoft Semantic Kernel validator scans every element in the code for dangerous identifiers and attributes including eval, exec, open, and __import__
- ▪The exploit payload bypassed the Microsoft Semantic Kernel blocklist because it used attributes not in the blocklist including __name__, load_module, system, and BuiltinImporter
- ▪The Microsoft Semantic Kernel validator only allows lambda expressions and rejects full code blocks such as import statements or class definitions
- ▪Microsoft Semantic Kernel implemented a validator that parses the filter string into an Abstract Syntax Tree before execution to prevent remote code execution risk
Patching guidance
- ▪Upgrading the Python semantic-kernel dependency to version 1.39.4 or higher mitigates the CVE-2026-26030 risk
- ▪The vulnerable window for CVE-2026-26030 is from the moment a vulnerable Semantic Kernel Python version was deployed until the moment version 1.39.4 or later was installed
- ▪An agent is vulnerable to CVE-2026-26030 if it uses the Python package semantic-kernel and is running a framework version prior to 1.39.4
- ▪The Microsoft Semantic Kernel team implemented a fix for CVE-2026-26030 using four layers of protection including AST node-type allowlist, function call allowlist, dangerous attributes blocklist, and name node restriction
Story comments
Loading comments…