| 26 Feb 2026 | Path traversal in MCP git server's git_add tool stages files outside repository | Model Context Protocol | coding | tool misuse | | resolved |
| 26 Feb 2026 | Zed editor agent file tools symlink escape (CVE-2026-27967) | Zed Industries | coding | excessive permissions | | resolved |
| 26 Feb 2026 | Agenta LLMOps platform: sandbox escape RCE and SSTI in server-side evaluators | Agenta | other | misconfiguration | | resolved |
| 26 Feb 2026 | Langflow CSV Agent node RCE via prompt injection (CVE-2026-27966) | Langflow | workflow | prompt injection | | resolved |
| 25 Feb 2026 | Parse Dashboard AI Agent endpoint flaws allow unauthenticated master-key database access | Parse Community | other | excessive permissions | | resolved |
| 25 Feb 2026 | CVE-2026-27597: Sandbox escape in Enclave AI agent JavaScript sandbox enables RCE | agentfront | coding | unknown | | resolved |
| 25 Feb 2026 | LangChain SSRF redirect bypass and LangSmith Studio token-leak vulnerabilities | LangChain | workflow | data leak | | resolved |
| 21 Feb 2026 | CVE-2026-27203: Environment variable injection in eBay API MCP Server | YosefHayim (ebay-mcp open source project) | other | tool misuse | | reported |
| 19 Feb 2026 | Multiple OpenClaw AI assistant vulnerabilities disclosed, including prompt injection paths | OpenClaw | other | prompt injection | | resolved |
| 19 Feb 2026 | CVE-2026-26057: Cisco Skill Scanner API server unauthenticated DoS and arbitrary file upload | Cisco | other | misconfiguration | | resolved |
| 13 Feb 2026 | Reflected XSS in Cloudflare agents SDK AI Playground OAuth callback (CVE-2026-1721) | Cloudflare | other | misconfiguration | | resolved |
| 13 Feb 2026 | CVE-2026-26268: Cursor sandbox escape via writable .git configuration | Cursor | coding | prompt injection | | resolved |
| 11 Feb 2026 | Command injection in sf-mcp-server Salesforce MCP server (CVE-2026-26029) | akutishevsky | workflow | tool misuse | | resolved |
| 10 Feb 2026 | Command injection flaws in GitHub Copilot and Visual Studio enable remote code execution | Microsoft | coding | unknown | | confirmed |
| 10 Feb 2026 | FastGPT AI agent platform: unauthenticated plugin API access and SSRF flaws | labring | workflow | excessive permissions | | resolved |
| 10 Feb 2026 | LangChain SSRF flaws in ChatOpenAI token counter and RecursiveUrlLoader | LangChain | workflow | tool misuse | | resolved |
| 9 Feb 2026 | CVE-2026-1868: Template injection in GitLab AI Gateway Duo Workflow Service | GitLab | workflow | unknown | | resolved |
| 9 Feb 2026 | CVE-2026-25905: mcp-run-python sandbox escape enables MCP server hijacking | | coding | excessive permissions | | reported |
| 6 Feb 2026 | CVE-2026-25650: MCP Salesforce Connector leaks Salesforce auth token | smn2gnt | workflow | data leak | | resolved |
| 6 Feb 2026 | Pydantic AI framework patches path traversal XSS and SSRF vulnerabilities | Pydantic | workflow | tool misuse | | resolved |
| 6 Feb 2026 | Microsoft AI agent tooling flaws: Semantic Kernel file write and Copilot command injection | Microsoft | coding | tool misuse | | resolved |
| 6 Feb 2026 | CVE-2026-25533: Sandbox escape in Enclave JavaScript sandbox for AI agent code | agentfront | coding | excessive permissions | | resolved |
| 4 Feb 2026 | AutoGPT platform SSRF in SendDiscordFileBlock (CVE-2025-62616) | Significant Gravitas | workflow | tool misuse | | resolved |
| 4 Feb 2026 | OpenClaw path traversal in isValidMedia() enables arbitrary file read (CVE-2026-25475) | OpenClaw | other | excessive permissions | | resolved |
| 4 Feb 2026 | CVE-2026-25546: Command injection in godot-mcp MCP server enables RCE | Coding-Solo | coding | tool misuse | | resolved |
| 3 Feb 2026 | Multiple Claude Code permission and sandbox bypass vulnerabilities patched | Anthropic | coding | tool misuse | | resolved |