| 31 Mar 2026 | LangChain path traversal in prompt loading allows arbitrary file read (CVE-2026-34070) | LangChain | other | data leak | | resolved |
| 31 Mar 2026 | CVE-2026-4399: Prompt injection in 1millionbot Millie chatbot | 1millionbot | customer service | prompt injection | | reported |
| 31 Mar 2026 | CVE-2026-29870: Path traversal enables arbitrary file write in agentic-context-engine | agentic-context-engine project | other | tool misuse | | reported |
| 31 Mar 2026 | FastGPT SSRF flaws in HTTP and MCP tools endpoints (CVE-2026-34162/34163) | labring | workflow | misconfiguration | | resolved |
| 31 Mar 2026 | Giskard library flaw: ChatWorkflow.chat renders input as Jinja2 template enabling RCE | Giskard | other | misconfiguration | | resolved |
| 31 Mar 2026 | Nhost CLI MCP server lacked authentication and CORS enforcement (CVE-2026-34200) | Nhost | coding | misconfiguration | | resolved |
| 31 Mar 2026 | Origin-validation flaws in official MCP Java and Go SDKs allow cross-site access | Model Context Protocol | other | misconfiguration | | resolved |
| 31 Mar 2026 | CVE-2026-34451: Path validation flaw in Anthropic TypeScript SDK memory tool | Anthropic | other | prompt injection | | resolved |
| 30 Mar 2026 | Unauthenticated MCP endpoint in Nginx UI allows full nginx takeover (CVE-2026-33032) | Nginx UI | workflow | misconfiguration | | confirmed |
| 28 Mar 2026 | CVE-2026-5002: Prompt injection in localGPT LLM prompt handler | PromtEngineer | other | prompt injection | | reported |
| 27 Mar 2026 | Command injection in OpenHands git diff API allows arbitrary commands in agent sandbox | OpenHands | coding | tool misuse | | resolved |
| 27 Mar 2026 | Prompt injection bypasses "safe command" auto-approval in multiple AI coding extensions | | coding | prompt injection | | reported |
| 27 Mar 2026 | LibreChat MCP/agent flaws enable SSRF and OAuth token exfiltration | LibreChat | other | tool misuse | | resolved |
| 27 Mar 2026 | Zero-click prompt injection in nanobot AI assistant email channel (CVE-2026-33654) | HKUDS | other | prompt injection | | resolved |
| 27 Mar 2026 | KQL injection in Azure Data Explorer MCP Server (CVE-2026-33980) | pab1it0 (adx-mcp-server project) | other | tool misuse | | resolved |
| 27 Mar 2026 | Path traversal in @mobilenext/mobile-mcp MCP server (CVE-2026-33989) | Mobile Next | workflow | tool misuse | | resolved |
| 23 Mar 2026 | CVE-2026-23882: Arbitrary command execution via Blinko MCP server creation | Blinko | workflow | tool misuse | | resolved |
| 22 Mar 2026 | CVE-2026-4530: SQL injection in Aix-DB text2sql agent terminology retriever | apconw | other | unknown | | reported |
| 20 Mar 2026 | Multiple Langflow vulnerabilities, including unauthenticated RCE, fixed in 1.9.0 | Langflow | workflow | excessive permissions | | resolved |
| 20 Mar 2026 | CVE-2026-33060: SSRF in CKAN MCP Server via unvalidated base_url parameter | ondata | workflow | prompt injection | | resolved |
| 20 Mar 2026 | Agentic tooling flaws: Claude Code trust bypass and MCP Go/Ruby SDK transport bugs | Anthropic | coding | excessive permissions | | resolved |
| 20 Mar 2026 | FastGPT CI workflow flaw allows code execution and secret theft (CVE-2026-33075) | labring | workflow | supply chain | | confirmed |
| 20 Mar 2026 | Multiple CVEs in PinchTab AI agent browser control server | PinchTab | browsing | tool misuse | | confirmed |
| 20 Mar 2026 | CVE-2026-33010: Wildcard CORS in mcp-memory-service exposes agent memories | doobidoo | other | misconfiguration | | resolved |
| 19 Mar 2026 | Rogue AI agent implicated in security incident at Meta | Meta | other | unknown | | reported |
| 19 Mar 2026 | Command injection flaws in Microsoft Copilot and M365 Copilot allow information disclosure | Microsoft | other | unknown | | confirmed |
| 19 Mar 2026 | Discourse XSS via prompt injection in AI triage Review Queue (CVE-2026-27740) | Discourse | workflow | prompt injection | | resolved |
| 19 Mar 2026 | SQLBot stored prompt injection chain enables RCE (CVE-2026-32622) | DataEase | other | prompt injection | | resolved |
| 16 Mar 2026 | AnythingLLM 1.11.1 and earlier: missing authentication and SQL Agent injection flaws | Mintplex Labs | workflow | tool misuse | | confirmed |
| 16 Mar 2026 | CVE-2026-4270: AWS API MCP Server file access restriction bypass | AWS | other | excessive permissions | | resolved |
| 16 Mar 2026 | FastMCP OAuth token audience flaw (CVE-2025-69196) fixed in 2.14.2 | PrefectHQ | other | excessive permissions | | resolved |
| 12 Mar 2026 | CVE-2026-32247: Cypher injection in Graphiti search filters exploitable via prompt injection | getzep | other | prompt injection | | resolved |
| 11 Mar 2026 | CVE-2026-31854: Cursor indirect prompt injection enables automatic command execution | Cursor | coding | prompt injection | | resolved |
| 11 Mar 2026 | ha-mcp Home Assistant MCP server: SSRF and XSS flaws in beta OAuth consent form | homeassistant-ai | workflow | unknown | | resolved |
| 11 Mar 2026 | CVE-2026-32128: FastGPT Python sandbox file-write guardrail bypass via fcntl stdout remap | FastGPT (labring) | coding | misconfiguration | | confirmed |
| 10 Mar 2026 | Microsoft discloses AI command injection in M365 Copilot and SSRF in Azure MCP Server | Microsoft | workflow | prompt injection | | confirmed |
| 10 Mar 2026 | MCP Atlassian server flaws allow SSRF and arbitrary file write before v0.17.0 | sooperset | workflow | tool misuse | | resolved |
| 7 Mar 2026 | mcp-memory-service exposes system details via unauthenticated health endpoint (CVE-2026-29787) | doobidoo | other | misconfiguration | | resolved |
| 7 Mar 2026 | PinchTab SSRF in /download endpoint allows internal network and file access (CVE-2026-30834) | PinchTab | browsing | excessive permissions | | resolved |
| 7 Mar 2026 | WeKnora MCP tool name collision enables prompt injection and tool hijacking | Tencent | workflow | prompt injection | | resolved |
| 6 Mar 2026 | GitHub Copilot CLI shell tool bypass allows arbitrary code execution (CVE-2026-29783) | GitHub | coding | prompt injection | | resolved |
| 6 Mar 2026 | Agentgateway MCP-to-OpenAPI request injection flaw (CVE-2026-29791) | Agentgateway | other | tool misuse | | resolved |
| 5 Mar 2026 | Trivy VS Code extension 1.8.12 on OpenVSX compromised to exfiltrate secrets via AI agent | Aqua Security | coding | supply chain | | resolved |
| 5 Mar 2026 | OpenClaw agent platform: SSRF and RCE via prompt injection (CVE-2026-28451, CVE-2026-30741) | OpenClaw | other | prompt injection | | confirmed |
| 3 Mar 2026 | CVE-2025-12345: Remote buffer overflow in LLM-Claw agent deployment function | | other | unknown | | resolved |
| 2 Mar 2026 | CVE-2026-2256: command injection in ModelScope ms-agent via prompt-derived input | ModelScope | other | prompt injection | | reported |