CWE-1426Base

Improper Validation of Generative AI Output

Incomplete in the CWE catalog · 3 CVEs mapped

3
CVEs mapped
3.0
Median CVSS
What it is

The product invokes a generative AI/ML

component whose behaviors and outputs cannot be directly

controlled, but the product does not validate or

insufficiently validates the outputs to ensure that they

align with the intended security, content, or privacy

policy.

Recent examples
3.0cvss
CVE-2025-55074

Channel member objects leak read status

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enforce access permissions on the Agents plugin which allows other users to determine when users had read channels via channel member objects

LOWno explanation yet
0%
epss
5.0cvss
CVE-2025-62453

GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability

Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally.

MEDIUMno explanation yet
0%
epss
3.0cvss
CVE-2025-31363

Data exfiltration via AI plugin Jira tool

Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.9 fail to restrict domains the LLM can request to contact upstream which allows an authenticated user to exfiltrate data from an arbitrary server accessible to the victim via performing a prompt injection in the AI plugin's Jira tool.

LOWno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-1426
Abstraction
Base
Structure
Simple
Status
Incomplete
References (5)