Security researchers have highlighted the risks associated with 'Excessive Agency' vulnerabilities in Large Language Models (LLMs), where granting AI systems excessive permissions or autonomy can enable attackers to exploit internal APIs, invoke unauthorized plugins, or perform unintended actions such as SSRF attacks and unauthorized interactions with business applications. These vulnerabilities arise when LLMs are given more control than necessary, often without sufficient human oversight or intervention mechanisms, leading to critical and high-severity security risks in environments where AI agents are integrated with sensitive systems.
In response to the unique challenges posed by agentic AI, the Open Worldwide Application Security Project (OWASP) has introduced the AI Vulnerability Scoring System (AIVSS), a new framework designed to assess and manage vulnerabilities specific to AI and agentic systems. Unlike traditional models such as CVSS, AIVSS accounts for the non-deterministic and dynamic nature of AI, including issues like ephemeral identities and the need for privilege management in autonomous agents. The AIVSS provides structured risk assessment guides and a scoring tool to help organizations quantify and address AI-specific security risks that are not adequately covered by existing vulnerability frameworks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
An Infosec Writeups article described the OWASP LLM06 'Excessive Agency' issue, explaining how over-privileged LLMs and insecure plugin access can be abused to trigger unauthorized actions such as API calls, data access, account changes, or emails. The piece also outlined mitigations including least privilege, isolation of sensitive functions, human oversight, and monitoring of LLM-initiated actions.
At OWASP Global AppSec, a new scoring system for AI vulnerabilities was unveiled, marking a development in how AI security issues may be assessed and prioritized. The reference does not provide further implementation details or a more specific event date.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
infosecwriteups.com
Open sourceinfosecwriteups.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.