Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Incident database

Structured records of AI agent security incidents: what happened, which vendor and agent type, the root cause, and every source we used. Filter, browse, or download as CSV.

Incidents by month, 2026 · 434 total · click a month to filter
Jan 2026: 23 incidents23JanFeb 2026: 26 incidents26FebMar 2026: 46 incidents46MarApr 2026: 46 incidents46AprMay 2026: 52 incidents52MayJun 2026: 51 incidents51JunJul 2026: 45 incidents45JulAug 2026: 82 incidents82AugSep 2026: 63 incidents63SepOct 2026: 0 incidents0OctNov 2026: 0 incidents0NovDec 2026: 0 incidents0Dec
Clear

23 incidents match

Incident dateIncidentVendorAgentRoot causeSeverityStatus
30 Jan 2026Moltbook, a social network for AI agents, exposes its database and agent tokensMoltbookothermisconfigurationresolved
30 Jan 2026Prompt injection via road signs shown to hijack autonomous cars and dronesotherprompt injectionreported
27 Jan 2026Hundreds of malicious skills found on the OpenClaw skill marketplaceOpenClawworkflowsupply chainresolved
24 Jan 2026ChatterMate AI chatbot XSS via chat input exposes tokens (CVE-2026-24399)ChatterMatecustomer servicedata leakresolved
24 Jan 2026Unauthenticated arbitrary file upload in Kalrav AI Agent WordPress plugin (CVE-2025-13374)otherexcessive permissionsreported
23 Jan 2026Unauthenticated command injection RCE in Framelink Figma and Ollama MCP serversFramelink (Figma-Context-MCP); Ollama MCP Serverothertool misuseconfirmed
22 Jan 2026Three information disclosure flaws in Microsoft Copilot, Copilot Studio and M365 CopilotMicrosoftworkflowdata leakconfirmed
21 Jan 2026Claude Code flaw let malicious repos exfiltrate Anthropic API keys (CVE-2026-21852)Anthropiccodingdata leakresolved
21 Jan 2026CVE-2026-22792: 5ire MCP client HTML injection enables MCP server creation and RCEnanbingxyzotherexcessive permissionsresolved
19 Jan 2026Two CVEs in awesome-llm-apps agents: path traversal and cross-session token leakawesome-llm-apps projectotherdata leakreported
16 Jan 2026CVE-2026-23523: Dive MCP host deeplink allows arbitrary command executionOpenAgentPlatformotherexcessive permissionsresolved
16 Jan 2026MCPJam Inspector <=1.4.2 remote code execution via crafted MCP server install requestMCPJamcodingmisconfigurationresolved
14 Jan 2026Sandbox escape in Enclave JavaScript sandbox for AI agents (CVE-2026-22686)agentfrontcodingexcessive permissionsresolved
14 Jan 2026CVE-2026-22708: Cursor agent allowlist bypass lets shell built-ins run unapprovedCursorcodingprompt injectionresolved
12 Jan 2026CVE-2026-22785: Code injection in orval MCP server generation from OpenAPI specsorval-labscodingsupply chainresolved
12 Jan 2026Path traversal in Zen MCP Server allows arbitrary file reads (CVE-2025-66689)BeehiveInnovationscodingdata leakresolved
12 Jan 2026CVE-2024-58340: ReDoS in LangChain MRKL agent output parserLangChainworkflowprompt injectionreported
12 Jan 2026OpenCode AI coding agent: unauthenticated local RCE and XSS in web UIanomalycocodingmisconfigurationresolved
10 Jan 2026Tencent WeKnora agent flaws allow prompt-based DB access and command injectionTencentotherprompt injectionresolved
7 Jan 2026CVE-2025-9611: DNS rebinding in Microsoft Playwright MCP Server via missing Origin checkMicrosoftbrowsingmisconfigurationresolved
7 Jan 2026CVE-2025-67366: Path traversal via symlinks in @sylphxltd/filesystem-mcp v0.5.8sylphxltdworkflowexcessive permissionsreported
2 Jan 2026CVE-2026-21445: Missing authentication on Langflow API endpoints exposes conversation dataLangflowworkflowmisconfigurationresolved
1 Jan 2026Anthropic discloses fourth case of Claude accessing third-party systems without authorizationAnthropicothermisconfigurationconfirmed