| 30 Jan 2026 | Moltbook, a social network for AI agents, exposes its database and agent tokens | Moltbook | other | misconfiguration | | resolved |
| 30 Jan 2026 | Prompt injection via road signs shown to hijack autonomous cars and drones | | other | prompt injection | | reported |
| 27 Jan 2026 | Hundreds of malicious skills found on the OpenClaw skill marketplace | OpenClaw | workflow | supply chain | | resolved |
| 24 Jan 2026 | ChatterMate AI chatbot XSS via chat input exposes tokens (CVE-2026-24399) | ChatterMate | customer service | data leak | | resolved |
| 24 Jan 2026 | Unauthenticated arbitrary file upload in Kalrav AI Agent WordPress plugin (CVE-2025-13374) | | other | excessive permissions | | reported |
| 23 Jan 2026 | Unauthenticated command injection RCE in Framelink Figma and Ollama MCP servers | Framelink (Figma-Context-MCP); Ollama MCP Server | other | tool misuse | | confirmed |
| 22 Jan 2026 | Three information disclosure flaws in Microsoft Copilot, Copilot Studio and M365 Copilot | Microsoft | workflow | data leak | | confirmed |
| 21 Jan 2026 | Claude Code flaw let malicious repos exfiltrate Anthropic API keys (CVE-2026-21852) | Anthropic | coding | data leak | | resolved |
| 21 Jan 2026 | CVE-2026-22792: 5ire MCP client HTML injection enables MCP server creation and RCE | nanbingxyz | other | excessive permissions | | resolved |
| 19 Jan 2026 | Two CVEs in awesome-llm-apps agents: path traversal and cross-session token leak | awesome-llm-apps project | other | data leak | | reported |
| 16 Jan 2026 | CVE-2026-23523: Dive MCP host deeplink allows arbitrary command execution | OpenAgentPlatform | other | excessive permissions | | resolved |
| 16 Jan 2026 | MCPJam Inspector <=1.4.2 remote code execution via crafted MCP server install request | MCPJam | coding | misconfiguration | | resolved |
| 14 Jan 2026 | Sandbox escape in Enclave JavaScript sandbox for AI agents (CVE-2026-22686) | agentfront | coding | excessive permissions | | resolved |
| 14 Jan 2026 | CVE-2026-22708: Cursor agent allowlist bypass lets shell built-ins run unapproved | Cursor | coding | prompt injection | | resolved |
| 12 Jan 2026 | CVE-2026-22785: Code injection in orval MCP server generation from OpenAPI specs | orval-labs | coding | supply chain | | resolved |
| 12 Jan 2026 | Path traversal in Zen MCP Server allows arbitrary file reads (CVE-2025-66689) | BeehiveInnovations | coding | data leak | | resolved |
| 12 Jan 2026 | CVE-2024-58340: ReDoS in LangChain MRKL agent output parser | LangChain | workflow | prompt injection | | reported |
| 12 Jan 2026 | OpenCode AI coding agent: unauthenticated local RCE and XSS in web UI | anomalyco | coding | misconfiguration | | resolved |
| 10 Jan 2026 | Tencent WeKnora agent flaws allow prompt-based DB access and command injection | Tencent | other | prompt injection | | resolved |
| 7 Jan 2026 | CVE-2025-9611: DNS rebinding in Microsoft Playwright MCP Server via missing Origin check | Microsoft | browsing | misconfiguration | | resolved |
| 7 Jan 2026 | CVE-2025-67366: Path traversal via symlinks in @sylphxltd/filesystem-mcp v0.5.8 | sylphxltd | workflow | excessive permissions | | reported |
| 2 Jan 2026 | CVE-2026-21445: Missing authentication on Langflow API endpoints exposes conversation data | Langflow | workflow | misconfiguration | | resolved |
| 1 Jan 2026 | Anthropic discloses fourth case of Claude accessing third-party systems without authorization | Anthropic | other | misconfiguration | | confirmed |