Tools AI Risk Radar ai-incident-0006
Incident record
OWL's document tool fetched whatever URL a prompt injection handed it
- Severity
- High
- Status
- Proof-of-concept
- Type
- Prompt Injection
- Target
- camel-ai/owl DocumentProcessingToolkit
- Actor
- researcher
- CVE
- CVE-2026-85675
What happened
The extract_document_content tool fetches caller-supplied URLs with no scheme, host or IP filtering, so an indirect prompt injection can make the server fetch internal resources or cloud metadata and return the response into the agent's context. Scored CVSS 3.1 7.5; the cited issue remained open at the 10 September check. A released fix was not established from that report.
Sources
- camel-ai/owl issue 615github.com/camel-ai/owl/issues/615
- NVD, CVE-2026-85675nvd.nist.gov/vuln/detail/CVE-2026-85675
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026