Semantic Kernel Prompt-to-RCE
When Agent Tooling Turns Language into Shell Access
Microsoft Defender Security Research published a case study showing how two vulnerabilities in Microsoft Semantic Kernel convert prompt injection from a content-integrity problem into a host-level execution risk. Both CVEs were responsibly disclosed and fixed before publication. The central lesson: the model is not the vulnerable component — the risk emerges when agent frameworks treat language-derived parameters as trusted input to system-level operations.
"Once an AI model is wired to tools, prompt injection creates a thin line between being just a content security problem and becoming a code execution primitive."
— Microsoft Security Blog
Technical Breakdown
The root cause was unsafe trust at the agent-to-tool boundary.
CVE-2026-26030 Root Cause
A hotel-search agent translated user intent into a city parameter that flowed into a Python lambda filter assembled through string interpolation and then evaluated — creating an injection sink when the model-controlled value was not safely constrained.
Why Blocklists Failed
The framework attempted to reduce risk through validation that parsed the filter expression and blocked dangerous identifiers. If an attacker can influence the expression shape, alternative syntax or runtime behavior may bypass the filter and reintroduce execution capabilities.
CVE-2026-25592 Root Cause
The SessionsPythonPlugin in the .NET SDK — arguments to DownloadFileAsync or UploadFileAsync were not validated against an allow-listed localFilePath.
Demonstrated Impact
Microsoft demonstrated that a single prompt could launch calc.exe on the host running the agent — representing the ability to execute arbitrary commands under the permissions of the agent runtime.
Attack Path
Initial Influence
Attacker introduces prompt-controlled content into an agent workflow — via user messages, retrieved documents, or tool outputs.
Treat prompts, retrieved docs, tool outputs, and user messages as untrusted data regardless of source.
Tool Selection
Attacker causes the model to choose a plugin with system impact — a search plugin backed by an in-memory vector store, or a file operations plugin.
Require explicit authorization for high-risk tool classes. Not every agent needs file, shell, or database access.
Parameter Injection
Attacker shapes tool parameters so they become code, paths, or commands — exploiting string interpolation in filter expressions or unvalidated file path arguments.
Validate with allow-lists and typed schemas rather than blocklists. Blocklists are fragile in dynamic languages.
Host Impact
Achieves RCE or arbitrary file write on the agent host, under the permissions of the agent runtime process.
Run agent tooling in a sandbox with minimum privileges. RCE impact is limited when the agent process cannot reach sensitive files or credentials.
CVE Details
In-Memory Vector Store RCE
A Python lambda filter in the Semantic Kernel In-Memory Vector Store connector was assembled via string interpolation using model-controlled parameters. The validation blocklist could be bypassed using alternative syntax, allowing prompt-controlled input to reach an eval() sink.
SessionsPythonPlugin File Write
Arguments to DownloadFileAsync and UploadFileAsync in the SessionsPythonPlugin (.NET SDK) were not validated against an allow-listed localFilePath, allowing prompt-controlled input to specify arbitrary write destinations on the host filesystem.
Impact
The impact extends beyond Semantic Kernel because this SDK is representative of a wider AI-agent design pattern. Agent frameworks sit between probabilistic model outputs and deterministic system capabilities. When that layer accepts language-derived parameters without strict validation, an attacker may move from prompt control to file write, data exfiltration, or remote code execution.
Exposed Environments
- Agents with broad local privileges
- Access to internal data stores
- Sensitive plugin access
- Developer workstations
Use Cases at Risk
- Internal automation services
- Customer-support agents
- Enterprise copilots
- Multi-agent orchestration systems
Broader Lesson
- Prompt injection → execution primitive
- Blocklists weak for dynamic execution
- Agent runtimes need sandboxing
- Least privilege limits blast radius
Defensive Tutorial
0–24 Hours
Inventory all Semantic Kernel deployments. Identify use of the affected In-Memory Vector Store connector or SessionsPythonPlugin. Upgrade packages to fixed versions immediately. Review agent logs for unusual tool invocations, unexpected file paths, unexpected Python execution behavior, or prompts containing code syntax.
1–7 Days
Convert tool inputs from flexible strings into typed, allow-listed schemas. File operations should enforce a narrow allow-list of directories and filenames. Filters should use query-builder APIs or safe expression interpreters rather than dynamic language evaluation. Add policy gates around privileged tool classes.
Long-Term Governance
Define a formal agent threat model that captures prompt injection, tool misuse, model-context poisoning, and plugin supply-chain risk. Require sandboxing for agent runtimes, least privilege for tool credentials, secure-by-default plugin templates, and continuous testing of indirect prompt-injection scenarios.
Defensive Checklist
Patches CVE-2026-26030. Apply to all environments using the In-Memory Vector Store connector — including development and staging instances.
Patches CVE-2026-25592. Apply to all environments using the SessionsPythonPlugin in the .NET SDK.
Search logs for unexpected file paths, unexpected Python execution behavior, or prompts containing code syntax, shell commands, or path traversal patterns.
Convert all tool inputs from flexible strings into typed, allow-listed schemas. Blocklists are insufficient for dynamic language evaluation paths.
Require explicit authorization for tools with file system, shell, database, or network access. Not every agent workflow needs every capability.
Run agent processes with the minimum permissions required. RCE impact is contained when the agent runtime cannot reach sensitive files, credentials, or internal systems.
Document prompt injection paths, tool misuse scenarios, model-context poisoning vectors, and plugin supply-chain risks for every agent deployment in your environment.
Test indirect prompt-injection scenarios continuously — not just at deployment. Include adversarial inputs via retrieved documents, external APIs, and user-supplied content.
All new agent integrations should start from a plugin template that enforces allow-listed inputs, scoped credentials, and audit logging by default — not as an afterthought.
References
[1] Microsoft Security Blog
When prompts become shells: RCE vulnerabilities in AI agent frameworks — May 7, 2026
[2] NVD
CVE-2026-26030 — In-Memory Vector Store RCE
[3] NVD
CVE-2026-25592 — SessionsPythonPlugin File Write