Summary
The first subset comprises nine accepted issues whose advisory pages explicitly name Taskflow Agent:
- a Chatwoot SQL-injection report;
- Signal Android attachment exfiltration;
- two Signal unauthorized-delete reports covering iOS and Android;
- Sentry privilege escalation;
- PraisonAI action injection;
- two Zammad access-control and SQL-injection reports; and
- an AFFiNE access-control bypass.
Fourteen additional advisory pages use GitHub Security Lab’s generic AI-agent credit and contain fifteen accepted or fixed reports:
- workflow-injection or privileged-action flaws in ag-Grid, datadog-actions-metrics, PX4-Autopilot, YDB, Harvester, PyMAPDL, FastStream, cross-platform-actions/action, Weaviate, vets-api, and ESPHome docs;
- two separate vulnerable ACL Anthology workflows;
- an OpenLibrary barcode-scanner XSS; and
- an Open WebUI tool-restriction bypass.
Counting boundary
These are public, project-specific security reports with an acceptance or fix trail, so they satisfy Bugflation’s no-CVE rule. They are grouped as one campaign and do not increase the site’s unique-CVE counter. The page count is 23 while the report count is 24 because the ACL Anthology advisory contains two separate GHSL reports.
References
- GitHub Security Lab AI-agent advisory index
- GitHub Taskflow audit methodology
- GitHub Taskflow CodeQL-triage methodology
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.