YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0006

Incident record

OWL's document tool fetched whatever URL a prompt injection handed it

Severity
High
Status
Proof-of-concept
Type
Prompt Injection
Target
camel-ai/owl DocumentProcessingToolkit
Actor
researcher
CVE
CVE-2026-85675

What happened

The extract_document_content tool fetches caller-supplied URLs with no scheme, host or IP filtering, so an indirect prompt injection can make the server fetch internal resources or cloud metadata and return the response into the agent's context. Scored CVSS 3.1 7.5; the cited issue remained open at the 10 September check. A released fix was not established from that report.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026