Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Incident database

Structured records of AI agent security incidents: what happened, which vendor and agent type, the root cause, and every source we used. Filter, browse, or download as CSV.

Incidents by month, 2026 · 434 total · click a month to filter
Jan 2026: 23 incidents23JanFeb 2026: 26 incidents26FebMar 2026: 46 incidents46MarApr 2026: 46 incidents46AprMay 2026: 52 incidents52MayJun 2026: 51 incidents51JunJul 2026: 45 incidents45JulAug 2026: 82 incidents82AugSep 2026: 63 incidents63SepOct 2026: 0 incidents0OctNov 2026: 0 incidents0NovDec 2026: 0 incidents0Dec
Clear

46 incidents match

Incident dateIncidentVendorAgentRoot causeSeverityStatus
31 Mar 2026LangChain path traversal in prompt loading allows arbitrary file read (CVE-2026-34070)LangChainotherdata leakresolved
31 Mar 2026CVE-2026-4399: Prompt injection in 1millionbot Millie chatbot1millionbotcustomer serviceprompt injectionreported
31 Mar 2026CVE-2026-29870: Path traversal enables arbitrary file write in agentic-context-engineagentic-context-engine projectothertool misusereported
31 Mar 2026FastGPT SSRF flaws in HTTP and MCP tools endpoints (CVE-2026-34162/34163)labringworkflowmisconfigurationresolved
31 Mar 2026Giskard library flaw: ChatWorkflow.chat renders input as Jinja2 template enabling RCEGiskardothermisconfigurationresolved
31 Mar 2026Nhost CLI MCP server lacked authentication and CORS enforcement (CVE-2026-34200)Nhostcodingmisconfigurationresolved
31 Mar 2026Origin-validation flaws in official MCP Java and Go SDKs allow cross-site accessModel Context Protocolothermisconfigurationresolved
31 Mar 2026CVE-2026-34451: Path validation flaw in Anthropic TypeScript SDK memory toolAnthropicotherprompt injectionresolved
30 Mar 2026Unauthenticated MCP endpoint in Nginx UI allows full nginx takeover (CVE-2026-33032)Nginx UIworkflowmisconfigurationconfirmed
28 Mar 2026CVE-2026-5002: Prompt injection in localGPT LLM prompt handlerPromtEngineerotherprompt injectionreported
27 Mar 2026Command injection in OpenHands git diff API allows arbitrary commands in agent sandboxOpenHandscodingtool misuseresolved
27 Mar 2026Prompt injection bypasses "safe command" auto-approval in multiple AI coding extensionscodingprompt injectionreported
27 Mar 2026LibreChat MCP/agent flaws enable SSRF and OAuth token exfiltrationLibreChatothertool misuseresolved
27 Mar 2026Zero-click prompt injection in nanobot AI assistant email channel (CVE-2026-33654)HKUDSotherprompt injectionresolved
27 Mar 2026KQL injection in Azure Data Explorer MCP Server (CVE-2026-33980)pab1it0 (adx-mcp-server project)othertool misuseresolved
27 Mar 2026Path traversal in @mobilenext/mobile-mcp MCP server (CVE-2026-33989)Mobile Nextworkflowtool misuseresolved
23 Mar 2026CVE-2026-23882: Arbitrary command execution via Blinko MCP server creationBlinkoworkflowtool misuseresolved
22 Mar 2026CVE-2026-4530: SQL injection in Aix-DB text2sql agent terminology retrieverapconwotherunknownreported
20 Mar 2026Multiple Langflow vulnerabilities, including unauthenticated RCE, fixed in 1.9.0Langflowworkflowexcessive permissionsresolved
20 Mar 2026CVE-2026-33060: SSRF in CKAN MCP Server via unvalidated base_url parameterondataworkflowprompt injectionresolved
20 Mar 2026Agentic tooling flaws: Claude Code trust bypass and MCP Go/Ruby SDK transport bugsAnthropiccodingexcessive permissionsresolved
20 Mar 2026FastGPT CI workflow flaw allows code execution and secret theft (CVE-2026-33075)labringworkflowsupply chainconfirmed
20 Mar 2026Multiple CVEs in PinchTab AI agent browser control serverPinchTabbrowsingtool misuseconfirmed
20 Mar 2026CVE-2026-33010: Wildcard CORS in mcp-memory-service exposes agent memoriesdoobidooothermisconfigurationresolved
19 Mar 2026Rogue AI agent implicated in security incident at MetaMetaotherunknownreported
19 Mar 2026Command injection flaws in Microsoft Copilot and M365 Copilot allow information disclosureMicrosoftotherunknownconfirmed
19 Mar 2026Discourse XSS via prompt injection in AI triage Review Queue (CVE-2026-27740)Discourseworkflowprompt injectionresolved
19 Mar 2026SQLBot stored prompt injection chain enables RCE (CVE-2026-32622)DataEaseotherprompt injectionresolved
16 Mar 2026AnythingLLM 1.11.1 and earlier: missing authentication and SQL Agent injection flawsMintplex Labsworkflowtool misuseconfirmed
16 Mar 2026CVE-2026-4270: AWS API MCP Server file access restriction bypassAWSotherexcessive permissionsresolved
16 Mar 2026FastMCP OAuth token audience flaw (CVE-2025-69196) fixed in 2.14.2PrefectHQotherexcessive permissionsresolved
12 Mar 2026CVE-2026-32247: Cypher injection in Graphiti search filters exploitable via prompt injectiongetzepotherprompt injectionresolved
11 Mar 2026CVE-2026-31854: Cursor indirect prompt injection enables automatic command executionCursorcodingprompt injectionresolved
11 Mar 2026ha-mcp Home Assistant MCP server: SSRF and XSS flaws in beta OAuth consent formhomeassistant-aiworkflowunknownresolved
11 Mar 2026CVE-2026-32128: FastGPT Python sandbox file-write guardrail bypass via fcntl stdout remapFastGPT (labring)codingmisconfigurationconfirmed
10 Mar 2026Microsoft discloses AI command injection in M365 Copilot and SSRF in Azure MCP ServerMicrosoftworkflowprompt injectionconfirmed
10 Mar 2026MCP Atlassian server flaws allow SSRF and arbitrary file write before v0.17.0soopersetworkflowtool misuseresolved
7 Mar 2026mcp-memory-service exposes system details via unauthenticated health endpoint (CVE-2026-29787)doobidooothermisconfigurationresolved
7 Mar 2026PinchTab SSRF in /download endpoint allows internal network and file access (CVE-2026-30834)PinchTabbrowsingexcessive permissionsresolved
7 Mar 2026WeKnora MCP tool name collision enables prompt injection and tool hijackingTencentworkflowprompt injectionresolved
6 Mar 2026GitHub Copilot CLI shell tool bypass allows arbitrary code execution (CVE-2026-29783)GitHubcodingprompt injectionresolved
6 Mar 2026Agentgateway MCP-to-OpenAPI request injection flaw (CVE-2026-29791)Agentgatewayothertool misuseresolved
5 Mar 2026Trivy VS Code extension 1.8.12 on OpenVSX compromised to exfiltrate secrets via AI agentAqua Securitycodingsupply chainresolved
5 Mar 2026OpenClaw agent platform: SSRF and RCE via prompt injection (CVE-2026-28451, CVE-2026-30741)OpenClawotherprompt injectionconfirmed
3 Mar 2026CVE-2025-12345: Remote buffer overflow in LLM-Claw agent deployment functionotherunknownresolved
2 Mar 2026CVE-2026-2256: command injection in ModelScope ms-agent via prompt-derived inputModelScopeotherprompt injectionreported