# Vulnerability Assessment


📂 ai-red-teaming

## AI RED TEAMING TECHNIQUES

# Vulnerability Assessment

CVE analysis and security testing of AI systems and frameworks

## Available Techniques

### MCP DNS Rebinding Attack

Critical vulnerability (CVE-2025-49596) in Anthropic's Model Context Protocol allowing remote code execution via DNS rebinding attacks.

#### KEY FEATURES

- •
DNS rebinding exploitation

- •
Localhost port targeting

- •
Authentication bypass

#### PRIMARY DEFENSES

- •
Session token implementation

- •
Origin and Host header validation

- •
CSRF protection mechanisms

#### KEY RISKS

### AI Framework CVE Scanning

Systematic identification and assessment of known CVEs in AI/ML frameworks, libraries, and dependencies used in AI systems.

#### KEY FEATURES

- •
Automated vulnerability scanning

- •
Dependency tree analysis

- •
CVSS score assessment

#### PRIMARY DEFENSES

- •
Regular dependency updates

- •
Automated vulnerability scanning

- •
Software composition analysis (SCA)

#### KEY RISKS

### LLM API Security Testing

Comprehensive security testing of LLM APIs for authentication bypasses, injection vulnerabilities, and access control issues.

#### KEY FEATURES

- •
Authentication mechanism testing

- •
API endpoint enumeration

- •
Rate limiting validation

#### PRIMARY DEFENSES

- •
Strong authentication mechanisms

- •
Proper authorization checks

- •
Input validation and sanitization

#### KEY RISKS

### AI Model Backdoor Detection

Detection and analysis of backdoor vulnerabilities in AI models that activate malicious behavior when specific triggers are encountered.

#### KEY FEATURES

- •
Trigger pattern analysis

- •
Model behavior monitoring

- •
Statistical anomaly detection

#### PRIMARY DEFENSES

- •
Model provenance verification

- •
Behavioral analysis during training

- •
Statistical testing for anomalies

#### KEY RISKS

### Ethical Guidelines for Vulnerability Assessment

When working with vulnerability assessment techniques, always follow these ethical guidelines:

- • Only test on systems you own or have explicit written permission to test

- • Focus on building better defenses, not conducting attacks

- • Follow responsible disclosure practices for any vulnerabilities found

- • Document and report findings to improve security for everyone

- • Consider the potential impact on users and society

- • Ensure compliance with all applicable laws and regulations

FROM THE ENGINEER BEHIND THIS CATALOG

## Get your agent system red-teamed

The attacks documented here work on production agent systems every day. Have yours tested before someone else does: prompt injection, jailbreaks, tool misuse and data exfiltration, with every finding written up next to its fix.

€750 instead of €1,500, one week, written report and walkthrough call, until 30 September

## AI Red Teaming

## AI Red Teaming Techniques
