Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Incident database

Structured records of AI agent security incidents: what happened, which vendor and agent type, the root cause, and every source we used. Filter, browse, or download as CSV.

Incidents by month, 2026 · 434 total · click a month to filter
Jan 2026: 23 incidents23JanFeb 2026: 26 incidents26FebMar 2026: 46 incidents46MarApr 2026: 46 incidents46AprMay 2026: 52 incidents52MayJun 2026: 51 incidents51JunJul 2026: 45 incidents45JulAug 2026: 82 incidents82AugSep 2026: 63 incidents63SepOct 2026: 0 incidents0OctNov 2026: 0 incidents0NovDec 2026: 0 incidents0Dec
Clear

26 incidents match

Incident dateIncidentVendorAgentRoot causeSeverityStatus
26 Feb 2026Path traversal in MCP git server's git_add tool stages files outside repositoryModel Context Protocolcodingtool misuseresolved
26 Feb 2026Zed editor agent file tools symlink escape (CVE-2026-27967)Zed Industriescodingexcessive permissionsresolved
26 Feb 2026Agenta LLMOps platform: sandbox escape RCE and SSTI in server-side evaluatorsAgentaothermisconfigurationresolved
26 Feb 2026Langflow CSV Agent node RCE via prompt injection (CVE-2026-27966)Langflowworkflowprompt injectionresolved
25 Feb 2026Parse Dashboard AI Agent endpoint flaws allow unauthenticated master-key database accessParse Communityotherexcessive permissionsresolved
25 Feb 2026CVE-2026-27597: Sandbox escape in Enclave AI agent JavaScript sandbox enables RCEagentfrontcodingunknownresolved
25 Feb 2026LangChain SSRF redirect bypass and LangSmith Studio token-leak vulnerabilitiesLangChainworkflowdata leakresolved
21 Feb 2026CVE-2026-27203: Environment variable injection in eBay API MCP ServerYosefHayim (ebay-mcp open source project)othertool misusereported
19 Feb 2026Multiple OpenClaw AI assistant vulnerabilities disclosed, including prompt injection pathsOpenClawotherprompt injectionresolved
19 Feb 2026CVE-2026-26057: Cisco Skill Scanner API server unauthenticated DoS and arbitrary file uploadCiscoothermisconfigurationresolved
13 Feb 2026Reflected XSS in Cloudflare agents SDK AI Playground OAuth callback (CVE-2026-1721)Cloudflareothermisconfigurationresolved
13 Feb 2026CVE-2026-26268: Cursor sandbox escape via writable .git configurationCursorcodingprompt injectionresolved
11 Feb 2026Command injection in sf-mcp-server Salesforce MCP server (CVE-2026-26029)akutishevskyworkflowtool misuseresolved
10 Feb 2026Command injection flaws in GitHub Copilot and Visual Studio enable remote code executionMicrosoftcodingunknownconfirmed
10 Feb 2026FastGPT AI agent platform: unauthenticated plugin API access and SSRF flawslabringworkflowexcessive permissionsresolved
10 Feb 2026LangChain SSRF flaws in ChatOpenAI token counter and RecursiveUrlLoaderLangChainworkflowtool misuseresolved
9 Feb 2026CVE-2026-1868: Template injection in GitLab AI Gateway Duo Workflow ServiceGitLabworkflowunknownresolved
9 Feb 2026CVE-2026-25905: mcp-run-python sandbox escape enables MCP server hijackingcodingexcessive permissionsreported
6 Feb 2026CVE-2026-25650: MCP Salesforce Connector leaks Salesforce auth tokensmn2gntworkflowdata leakresolved
6 Feb 2026Pydantic AI framework patches path traversal XSS and SSRF vulnerabilitiesPydanticworkflowtool misuseresolved
6 Feb 2026Microsoft AI agent tooling flaws: Semantic Kernel file write and Copilot command injectionMicrosoftcodingtool misuseresolved
6 Feb 2026CVE-2026-25533: Sandbox escape in Enclave JavaScript sandbox for AI agent codeagentfrontcodingexcessive permissionsresolved
4 Feb 2026AutoGPT platform SSRF in SendDiscordFileBlock (CVE-2025-62616)Significant Gravitasworkflowtool misuseresolved
4 Feb 2026OpenClaw path traversal in isValidMedia() enables arbitrary file read (CVE-2026-25475)OpenClawotherexcessive permissionsresolved
4 Feb 2026CVE-2026-25546: Command injection in godot-mcp MCP server enables RCECoding-Solocodingtool misuseresolved
3 Feb 2026Multiple Claude Code permission and sandbox bypass vulnerabilities patchedAnthropiccodingtool misuseresolved