We maintain AVE (Agentic Vulnerability Enumeration, github.com/aveproject/ave), an open standard for classifying behavioral vulnerabilities in agentic AI components. Several of our classes don't map cleanly onto any current CWE entry, and we'd value the Working
Group's read on whether these represent genuine gaps or existing CWEs we haven't correctly identified.
Two examples to start the conversation, not an exhaustive list:
- AVE-2026-00002 (MCP tool description behavioral injection): a malicious instruction embedded in a tool's declared description, causing model behavior deviation without any explicit tool call triggering it. Distinct from prompt injection via user input.
- AVE-2026-00041 (server-card injection): a server misrepresenting its own declared capabilities to an agent that trusts the declaration.
Genuinely open to being told these already map to something in the CWE corpus and we've missed it; if they're real gaps, happy to help develop the content following the CDR process once there's Working Group consensus on scope.
We maintain AVE (Agentic Vulnerability Enumeration, github.com/aveproject/ave), an open standard for classifying behavioral vulnerabilities in agentic AI components. Several of our classes don't map cleanly onto any current CWE entry, and we'd value the Working
Group's read on whether these represent genuine gaps or existing CWEs we haven't correctly identified.
Two examples to start the conversation, not an exhaustive list:
Genuinely open to being told these already map to something in the CWE corpus and we've missed it; if they're real gaps, happy to help develop the content following the CDR process once there's Working Group consensus on scope.