Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Semantic Kernel’s two critical remote-code-execution advisories describe different flaws, not one vulnerability affecting every deployment. CVE-2026-26030 concerns a particular Python Search Plugin and In-Memory Vector Store filter setup; CVE-2026-25592 centers on a .NET plugin function that could write a sandbox file to a host path. Check the SDK, component, configuration, and package version for each application separately.

Am I affected?

Use this comparison to identify which path to investigate. The affected-version thresholds come from the Microsoft Semantic Kernel GitHub advisories; the exploit conditions and fixes are described in Microsoft Security Research’s May 7, 2026 article.

Advisory SDK and component Documented exposure condition Unsafe operation Package threshold Severity
CVE-2026-26030 Python; semantic-kernel on pip A prompt-injection vector can influence tool inputs, and the Search Plugin uses the default In-Memory Vector Store filter functionality. Model-controlled filter input is interpolated into a Python lambda evaluated with eval(), creating a route to host command execution. Versions below 1.39.4 are affected; 1.39.4 is the patched release. GitHub advisory rating: Critical, CVSS 9.9.
CVE-2026-25592 Primarily .NET; Microsoft.SemanticKernel.Plugins.Core and its SessionsPythonPlugin The plugin exposes DownloadFileAsync to AI function calling in the described sandbox-to-host file-transfer setup. A sandbox file could be written to a chosen host path. In the illustrated chain, that file-write primitive could lead to code execution; the helper does not itself execute code in every environment. For .NET, versions below 1.71.0 are affected; upgrade to 1.71.0 or later. GitHub advisory rating: Critical, CVSS 9.9.

The CVE-2026-25592 advisory also lists the Python package range below 1.39.3, patched in 1.39.3. Treat that as a separate package-specific advisory detail; it does not replace the Python 1.39.4 threshold for CVE-2026-26030.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How can a prompt injection execute code on an agent host?

A prompt injection supplies attacker influence, but the flaw is at the boundary where framework code trusts model-controlled input. Microsoft Security Research describes the common lesson this way: “The vulnerability lies in how the framework and tools trust the parsed data.” Neither advisory means that any prompt injection, or every Semantic Kernel application, automatically enables host execution.

CVE-2026-26030: Python filter evaluation

In Microsoft’s hotel-search example, an agent invokes a Search Plugin backed by an In-Memory Vector Store. The filter is formed as a Python lambda using a value passed through model tool arguments, then evaluated. A validator was present, but its blacklist and structural checks could be bypassed using Python’s flexible object and AST mechanisms. With the documented prompt-injection vector and this specific plugin/backend configuration, a crafted filter could reach arbitrary command execution on the host running the agent.

The patched implementation adds layered checks: an AST node allowlist, a function-call allowlist, restrictions on dangerous attributes, and limits on bare identifier names. The GitHub advisory identifies CWE-94, code injection. As a workaround, it advises against using InMemoryVectorStore in production.

CVE-2026-25592: .NET plugin file write

SessionsPythonPlugin was intended to transfer files between an isolated Azure Container Apps dynamic session and the host agent. In the vulnerable .NET SDK, DownloadFileAsync was exposed as a kernel function available to AI function calling. Injected instructions could therefore steer the model to use a sandbox file as input and a dangerous host location as its destination, undermining the isolation boundary.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The fix removes the [KernelFunction] exposure so the model cannot call DownloadFileAsync, and validates host paths for programmatic calls. The advisory’s workaround is an invocation filter that checks DownloadFileAsync or UploadFileAsync arguments and allowlists localFilePath. Microsoft’s article emphasizes canonicalizing paths and restricting writes to allowed directories. The GitHub advisory classifies this issue as CWE-22, path traversal.

What should I check in each deployment?

  1. Inventory packages and SDKs. For every deployed application, identify whether it uses the Python or .NET SDK and record the exact Semantic Kernel package version, including transitive dependencies where applicable. A project dependency listing or package manager inspection should cover deployed builds, not just a developer’s local environment.
  2. Review the Python configuration. Determine whether the Search Plugin is backed by the default In-Memory Vector Store filter functionality. Then assess whether untrusted or attacker-influenced content can affect tool inputs. An application using Python Semantic Kernel without this documented setup should not be labeled exposed to CVE-2026-26030 on that basis alone.
  3. Review .NET plugin use. Search application registrations and plugin setup for SessionsPythonPlugin and determine whether the affected Core package is deployed. Pay particular attention to whether AI function calling can reach file-transfer functionality.
  4. Patch by package. Upgrade Python deployments exposed to CVE-2026-26030 to semantic-kernel 1.39.4 or later. Upgrade the affected .NET package to Microsoft.SemanticKernel.Plugins.Core 1.71.0 or later. Do not assume that updating one language SDK fixes the other flaw.
  5. Apply the .NET workaround if an upgrade is pending. Use an invocation filter to validate the relevant file-transfer arguments and allowlist host paths. For the Python issue, the advisory’s stated workaround is to avoid InMemoryVectorStore in production; do not treat a generic prompt filter as a substitute for the package fix.

How do I check whether it was exploited before patching?

Microsoft’s retrospective guidance is to first establish the vulnerable deployment interval for each affected application, then review endpoint telemetry for activity associated with the agent host. Focus the investigation on:

  • Unexpected child processes launched by the agent host.
  • Unusual outbound network connections from that host.
  • Persistence artifacts created while the vulnerable code was deployed.

If telemetry is suspicious, treat the host as potentially compromised: inspect it, rotate tokens and credentials that were accessible to the agent, and determine which data and systems the host could reach. A review that finds no suspicious indicators does not prove that exploitation did not occur; the cited guidance provides hunting leads, not a guarantee that every attack would be detectable.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is the engineering lesson for agent tools?

Validate arguments at the tool boundary rather than relying on model intent or a blacklist alone. A filter expression must be constrained to a deliberately small, safe language before evaluation; a file operation must enforce canonical paths and an explicit allowed-directory policy. The fixes here are not interchangeable: one constrains Python expression structure, while the other removes AI access to a file-transfer helper and validates host paths.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft Learn’s general prompt-injection guidance says inserted prompt content should be treated as unsafe by default. That principle helps frame the threat, but it is not a replacement for applying the package-specific fixes above.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.