{
  "schema_version": "1.6.0",
  "id": "ACVE-2026-0523",
  "aliases": [],
  "published": "2026-08-31T00:00:00Z",
  "firstReported": {
    "date": "2026-08-31",
    "url": "https://metr.org/blog/2026-08-31-security-update/",
    "publisher": "METR"
  },
  "modified": "2026-09-25T00:00:00Z",
  "summary": "About $600,000 of public-model credits were consumed after an attacker prompted the agent in a researcher's exposed personal EC2 deployment of METR tooling to reveal a model-provider API key.",
  "details": "## What\n\nMETR says an attacker found a researcher's personal EC2 instance running a publicly exposed deployment of METR tooling, prompted the agent to reveal a model-provider API key, and used the stolen credentials for three weeks of public-model inference. METR estimates the credits at about $600,000 and says no sensitive information was accessed.\n\n## Detection\n\nThe personal deployment was exposed for several days because authentication failed open. Recorded from METR's security update. Not recreated in a lab.\n\n## Fix\n\nKeep agent deployments and model-provider credentials behind enforced authentication, add spend alerts, and rotate exposed credentials.",
  "affected": [
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "metr-agent-dashboard"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ]
    }
  ],
  "references": [
    {
      "type": "REPORT",
      "url": "https://metr.org/blog/2026-08-31-security-update/"
    }
  ],
  "database_specific": {
    "severity": "CRITICAL",
    "acve": {
      "specVersion": 1,
      "status": "candidate",
      "kind": "behavioural",
      "vulnClasses": [
        "credential-exposure",
        "over-privileged-combination"
      ],
      "cwe": [
        "CWE-522",
        "CWE-693"
      ],
      "taxonomy": {
        "owasp_asi": [
          "ASI03",
          "ASI01"
        ],
        "atlas": [
          "AML.T0132",
          "AML.T0051.000",
          "AML.T0083"
        ]
      },
      "noCveReason": "No code defect: the harm arises from the agent pursuing the attacker's goal in this configuration.",
      "cveBoundary": "behavioural",
      "threat": {
        "attacker": "user",
        "vector": "unsafe-default",
        "outcome": "exfiltration"
      },
      "evidence": [
        {
          "kind": "incident",
          "url": "https://metr.org/blog/2026-08-31-security-update/"
        }
      ],
      "fix": {
        "summary": "Enforce authentication and rotate exposed model-provider credentials.",
        "actions": [
          {
            "type": "reconfigure",
            "target": "agent.approval",
            "to": "ask",
            "why": "An external caller should not be able to direct a publicly exposed agent to disclose credentials.",
            "owner": "operator"
          },
          {
            "type": "reconfigure",
            "target": "metr.tooling.auth",
            "to": "fails closed",
            "why": "Recommended: authentication failed open and left the deployment exposed for several days.",
            "owner": "harness-vendor"
          },
          {
            "type": "reconfigure",
            "target": "model-provider.api.keys",
            "to": "alerts when a key's usage jumps",
            "why": "Recommended: the stolen key ran about $600,000 of inference over three weeks.",
            "owner": "model-provider"
          }
        ]
      },
      "exposure": {
        "harness": {
          "value": "A researcher's personal EC2 instance running a publicly accessible deployment of METR tooling",
          "any": false,
          "status": "confirmed",
          "source": "https://metr.org/blog/2026-08-31-security-update/"
        },
        "model": {
          "value": "any public model available through the dashboard",
          "any": true,
          "status": "confirmed",
          "source": "https://metr.org/blog/2026-08-31-security-update/"
        },
        "goal": {
          "value": "Reveal the model-provider API key",
          "stated": true,
          "status": "confirmed",
          "source": "https://metr.org/blog/2026-08-31-security-update/"
        },
        "tools": {
          "value": "Agent dashboard with access to a model-provider API key",
          "status": "confirmed",
          "source": "https://metr.org/blog/2026-08-31-security-update/"
        },
        "approval": {
          "value": "The dashboard's authentication failed open, allowing the attacker to prompt the agent directly",
          "mode": "no-prompt-by-design",
          "status": "confirmed",
          "source": "https://metr.org/blog/2026-08-31-security-update/"
        },
        "inputControl": "operator",
        "agentAction": "The agent reveals the model-provider API key to the attacker.",
        "harm": "credential-theft",
        "divergence": "instruction-followed",
        "reach": {
          "value": "The researcher's personal EC2 deployment, model-provider API key and inference credits",
          "kinds": [
            "api-keys",
            "funds"
          ],
          "status": "confirmed",
          "source": "https://metr.org/blog/2026-08-31-security-update/"
        },
        "condition": {
          "value": "When the publicly exposed dashboard's authentication silently failed open",
          "status": "confirmed",
          "source": "https://metr.org/blog/2026-08-31-security-update/"
        },
        "scale": {
          "statement": "Credits worth approximately $600,000 were consumed",
          "unit": "dollars",
          "value": 600000,
          "source": "https://metr.org/blog/2026-08-31-security-update/"
        }
      },
      "occurrence": {
        "basis": "real-use",
        "reportedBy": "operator",
        "responses": [
          {
            "party": "METR",
            "status": "acknowledged",
            "statement": "METR revoked access, rotated credentials, and added monitoring and spend alerts.",
            "source": "https://metr.org/blog/2026-08-31-security-update/"
          }
        ]
      },
      "exploitation": {
        "status": "none-known",
        "checkedAt": "2026-09-24T00:00:00Z",
        "sources": [
          {
            "url": "https://metr.org/blog/2026-08-31-security-update/",
            "type": "research",
            "note": "METR reported an external attacker using the exposed dashboard."
          }
        ],
        "kev": {
          "listed": false
        }
      },
      "claims": [],
      "reproducibility": {
        "status": "partial",
        "axesComplete": true,
        "componentsObtainable": null,
        "triggerPublished": false,
        "observableStated": true,
        "demonstrated": "reported-only",
        "missing": [
          "model availability not checked (no registry reference)",
          "trigger not published"
        ]
      },
      "severityBasis": "harm-reach"
    }
  }
}
