Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Incident database

Structured records of AI agent security incidents: what happened, which vendor and agent type, the root cause, and every source we used. Filter, browse, or download as CSV.

Incidents by month, 2026 · 434 total · click a month to filter
Jan 2026: 23 incidents23JanFeb 2026: 26 incidents26FebMar 2026: 46 incidents46MarApr 2026: 46 incidents46AprMay 2026: 52 incidents52MayJun 2026: 51 incidents51JunJul 2026: 45 incidents45JulAug 2026: 82 incidents82AugSep 2026: 63 incidents63SepOct 2026: 0 incidents0OctNov 2026: 0 incidents0NovDec 2026: 0 incidents0Dec
Clear

46 incidents match

Incident dateIncidentVendorAgentRoot causeSeverityStatus
29 Apr 2026CVE-2026-7417: SSRF in Algovate xhs-mcp MCP server publish toolAlgovateworkflowtool misusereported
28 Apr 2026SSRF in Tencent CloudBase-MCP open-url endpoint (CVE-2026-7221)TencentCloudBasecodingtool misuseresolved
27 Apr 2026SSRF in JoeCastrom mcp-chat-studio LLM Models API (CVE-2026-7147)JoeCastromotherunknownreported
27 Apr 2026SSRF in mcp-data-vis MCP web-scraper server (CVE-2026-7146)AlejandroArciniegasbrowsingtool misusereported
27 Apr 2026SSRF in dh1011 auto-favicon MCP server tool (CVE-2026-7150)dh1011othertool misusereported
27 Apr 2026SSRF in dmitryglhf mcp-url-downloader MCP server (CVE-2026-7158)dmitryglhfbrowsingtool misusereported
24 Apr 2026AnythingLLM stored XSS via unsanitised chart captions (CVE-2026-41318)Mintplex Labsotherprompt injectionresolved
24 Apr 2026LangChain SSRF protection bypasses in langchain-text-splitters and langchain-openaiLangChainothertool misuseresolved
23 Apr 2026Paperclip AI agent orchestrator: unauthenticated and agent-key RCE flaws (CVE-2026-41208/41679)Paperclipworkflowexcessive permissionsresolved
23 Apr 2026CVE-2026-33102: Open redirect in Microsoft 365 Copilot enables privilege elevationMicrosoftotherunknownconfirmed
23 Apr 2026CVE-2026-41349: OpenClaw agentic consent bypass via config.patchOpenClawotherexcessive permissionsresolved
21 Apr 2026Path traversal in excel-mcp-server allows unauthenticated remote arbitrary file accessharis-musaworkflowmisconfigurationresolved
21 Apr 2026CVE-2026-40608: Unbounded request body crashes Next AI Draw.io MCP sidecarDayuanJiangothermisconfigurationresolved
21 Apr 2026Flowise pre-3.1.0: RCE via prompt injection in CSV/Airtable agents and MCP adapterFlowiseAIworkflowprompt injectionresolved
20 Apr 2026Two remotely exploitable flaws disclosed in ericc-ch copilot-api up to 0.7.0ericc-chcodingmisconfigurationreported
17 Apr 2026CVE-2026-6494: Log injection in Ansible Automation Platform MCP serverRed Hatworkflowunknownconfirmed
17 Apr 2026mcp-neo4j-cypher read-only bypass via APOC procedures (CVE-2026-35402)neo4j-contribotherexcessive permissionsresolved
17 Apr 2026Claude Code flaws: Windows config hijack and symlink sandbox escapeAnthropiccodingprompt injectionresolved
17 Apr 2026FastGPT NoSQL injection flaws allow authentication bypass and account takeoverlabringotherunknownresolved
17 Apr 2026CVE-2025-66335: SQL injection flaw in Apache Doris MCP Server before 0.6.1Apacheothertool misuseresolved
16 Apr 2026CVE-2026-39313: unbounded request body in mcp-framework enables remote DoSQuantGeekDevothersupply chainresolved
15 Apr 2026Argument injection in mcp-server-kubernetes port_forward tool (CVE-2026-39884)Flux159workflowtool misuseresolved
15 Apr 2026Splunk MCP Server app logs session and authorization tokens in clear text (CVE-2026-20205)Splunkworkflowdata leakresolved
15 Apr 2026CVE-2026-30615: Prompt injection in Windsurf enables RCE via malicious MCP server registrationWindsurfcodingprompt injectionreported
15 Apr 2026CVE-2026-30616: Remote code execution in Jaaz 1.0.30 MCP STDIO command handlingJaazothertool misusereported
15 Apr 2026CVE-2026-30624: Remote code execution in Agent Zero MCP server configurationAgent Zeroothertool misusereported
15 Apr 2026CVE-2026-30625: Remote code execution in Upsonic MCP task creationUpsonicworkflowtool misusereported
14 Apr 2026CVE-2026-23653: Command injection in GitHub Copilot and Visual Studio CodeMicrosoftcodingtool misuseconfirmed
13 Apr 2026CVE-2026-34476: SSRF via SW-URL header in Apache SkyWalking MCPApache Software Foundationothertool misuseresolved
11 Apr 2026aws-mcp-server command injection flaws allow unauthenticated remote code executionaws-mcp-serverworkflowtool misusereported
10 Apr 2026CVE-2026-35651: ANSI escape injection in OpenClaw approval promptsOpenClawcodingprompt injectionresolved
10 Apr 2026FastGPT AI agent platform: unauthenticated SSRF and cross-tenant access control flawslabringworkflowexcessive permissionsresolved
9 Apr 2026Apollo MCP Server DNS rebinding flaw allows local tool invocation (CVE-2026-35577)Apollo GraphQLworkflowmisconfigurationresolved
9 Apr 2026LangChain prompt-template validation flaw and LangChain-ChatChat MCP RCE disclosedLangChainothertool misuseconfirmed
9 Apr 2026Command injection in awwaiid mcp-server-taskwarrior up to 1.0.1 (CVE-2026-5833)awwaiidworkflowtool misuseresolved
9 Apr 2026AGiXT path traversal in essential_abilities allows arbitrary file access (CVE-2026-39981)AGiXTworkflowexcessive permissionsresolved
8 Apr 2026CVE-2026-34724: Zammad server-side template injection enables RCE via AI AgentZammadcustomer serviceunknownresolved
8 Apr 2026FrontMCP SSRF and local file read via unrestricted OpenAPI $ref dereferencing (CVE-2026-39885)agentfrontothermisconfigurationresolved
7 Apr 2026DNS rebinding flaw in MCP Java SDK allows remote tool calls (CVE-2026-35568)Model Context Protocolothermisconfigurationresolved
6 Apr 2026CVE-2026-5607: SSRF in imprvhub mcp-browser-agent up to 0.8.0imprvhubbrowsingtool misusereported
6 Apr 2026CVE-2026-35394: mobile-mcp URL tool allows arbitrary Android intent executionMobile Nextworkflowtool misuseresolved
5 Apr 2026CVE-2026-5584: Remote code injection in agenticSeek PyInterpreter.executeFosowlcodingtool misusereported
3 Apr 2026Multiple critical vulnerabilities in PraisonAI multi-agent framework (8 CVEs)PraisonAIworkflowtool misuseresolved
3 Apr 2026CVE-2025-64340: Command injection in FastMCP install commands on WindowsPrefectHQcodingtool misuseresolved
2 Apr 2026FastMCP flaws before 3.2.0: authenticated SSRF and OAuth confused deputyPrefectHQothertool misuseresolved
2 Apr 2026SSRF vulnerability in a11y-mcp MCP server (CVE-2026-5323)priyankarkothertool misuseresolved