| 29 Apr 2026 | CVE-2026-7417: SSRF in Algovate xhs-mcp MCP server publish tool | Algovate | workflow | tool misuse | | reported |
| 28 Apr 2026 | SSRF in Tencent CloudBase-MCP open-url endpoint (CVE-2026-7221) | TencentCloudBase | coding | tool misuse | | resolved |
| 27 Apr 2026 | SSRF in JoeCastrom mcp-chat-studio LLM Models API (CVE-2026-7147) | JoeCastrom | other | unknown | | reported |
| 27 Apr 2026 | SSRF in mcp-data-vis MCP web-scraper server (CVE-2026-7146) | AlejandroArciniegas | browsing | tool misuse | | reported |
| 27 Apr 2026 | SSRF in dh1011 auto-favicon MCP server tool (CVE-2026-7150) | dh1011 | other | tool misuse | | reported |
| 27 Apr 2026 | SSRF in dmitryglhf mcp-url-downloader MCP server (CVE-2026-7158) | dmitryglhf | browsing | tool misuse | | reported |
| 24 Apr 2026 | AnythingLLM stored XSS via unsanitised chart captions (CVE-2026-41318) | Mintplex Labs | other | prompt injection | | resolved |
| 24 Apr 2026 | LangChain SSRF protection bypasses in langchain-text-splitters and langchain-openai | LangChain | other | tool misuse | | resolved |
| 23 Apr 2026 | Paperclip AI agent orchestrator: unauthenticated and agent-key RCE flaws (CVE-2026-41208/41679) | Paperclip | workflow | excessive permissions | | resolved |
| 23 Apr 2026 | CVE-2026-33102: Open redirect in Microsoft 365 Copilot enables privilege elevation | Microsoft | other | unknown | | confirmed |
| 23 Apr 2026 | CVE-2026-41349: OpenClaw agentic consent bypass via config.patch | OpenClaw | other | excessive permissions | | resolved |
| 21 Apr 2026 | Path traversal in excel-mcp-server allows unauthenticated remote arbitrary file access | haris-musa | workflow | misconfiguration | | resolved |
| 21 Apr 2026 | CVE-2026-40608: Unbounded request body crashes Next AI Draw.io MCP sidecar | DayuanJiang | other | misconfiguration | | resolved |
| 21 Apr 2026 | Flowise pre-3.1.0: RCE via prompt injection in CSV/Airtable agents and MCP adapter | FlowiseAI | workflow | prompt injection | | resolved |
| 20 Apr 2026 | Two remotely exploitable flaws disclosed in ericc-ch copilot-api up to 0.7.0 | ericc-ch | coding | misconfiguration | | reported |
| 17 Apr 2026 | CVE-2026-6494: Log injection in Ansible Automation Platform MCP server | Red Hat | workflow | unknown | | confirmed |
| 17 Apr 2026 | mcp-neo4j-cypher read-only bypass via APOC procedures (CVE-2026-35402) | neo4j-contrib | other | excessive permissions | | resolved |
| 17 Apr 2026 | Claude Code flaws: Windows config hijack and symlink sandbox escape | Anthropic | coding | prompt injection | | resolved |
| 17 Apr 2026 | FastGPT NoSQL injection flaws allow authentication bypass and account takeover | labring | other | unknown | | resolved |
| 17 Apr 2026 | CVE-2025-66335: SQL injection flaw in Apache Doris MCP Server before 0.6.1 | Apache | other | tool misuse | | resolved |
| 16 Apr 2026 | CVE-2026-39313: unbounded request body in mcp-framework enables remote DoS | QuantGeekDev | other | supply chain | | resolved |
| 15 Apr 2026 | Argument injection in mcp-server-kubernetes port_forward tool (CVE-2026-39884) | Flux159 | workflow | tool misuse | | resolved |
| 15 Apr 2026 | Splunk MCP Server app logs session and authorization tokens in clear text (CVE-2026-20205) | Splunk | workflow | data leak | | resolved |
| 15 Apr 2026 | CVE-2026-30615: Prompt injection in Windsurf enables RCE via malicious MCP server registration | Windsurf | coding | prompt injection | | reported |
| 15 Apr 2026 | CVE-2026-30616: Remote code execution in Jaaz 1.0.30 MCP STDIO command handling | Jaaz | other | tool misuse | | reported |
| 15 Apr 2026 | CVE-2026-30624: Remote code execution in Agent Zero MCP server configuration | Agent Zero | other | tool misuse | | reported |
| 15 Apr 2026 | CVE-2026-30625: Remote code execution in Upsonic MCP task creation | Upsonic | workflow | tool misuse | | reported |
| 14 Apr 2026 | CVE-2026-23653: Command injection in GitHub Copilot and Visual Studio Code | Microsoft | coding | tool misuse | | confirmed |
| 13 Apr 2026 | CVE-2026-34476: SSRF via SW-URL header in Apache SkyWalking MCP | Apache Software Foundation | other | tool misuse | | resolved |
| 11 Apr 2026 | aws-mcp-server command injection flaws allow unauthenticated remote code execution | aws-mcp-server | workflow | tool misuse | | reported |
| 10 Apr 2026 | CVE-2026-35651: ANSI escape injection in OpenClaw approval prompts | OpenClaw | coding | prompt injection | | resolved |
| 10 Apr 2026 | FastGPT AI agent platform: unauthenticated SSRF and cross-tenant access control flaws | labring | workflow | excessive permissions | | resolved |
| 9 Apr 2026 | Apollo MCP Server DNS rebinding flaw allows local tool invocation (CVE-2026-35577) | Apollo GraphQL | workflow | misconfiguration | | resolved |
| 9 Apr 2026 | LangChain prompt-template validation flaw and LangChain-ChatChat MCP RCE disclosed | LangChain | other | tool misuse | | confirmed |
| 9 Apr 2026 | Command injection in awwaiid mcp-server-taskwarrior up to 1.0.1 (CVE-2026-5833) | awwaiid | workflow | tool misuse | | resolved |
| 9 Apr 2026 | AGiXT path traversal in essential_abilities allows arbitrary file access (CVE-2026-39981) | AGiXT | workflow | excessive permissions | | resolved |
| 8 Apr 2026 | CVE-2026-34724: Zammad server-side template injection enables RCE via AI Agent | Zammad | customer service | unknown | | resolved |
| 8 Apr 2026 | FrontMCP SSRF and local file read via unrestricted OpenAPI $ref dereferencing (CVE-2026-39885) | agentfront | other | misconfiguration | | resolved |
| 7 Apr 2026 | DNS rebinding flaw in MCP Java SDK allows remote tool calls (CVE-2026-35568) | Model Context Protocol | other | misconfiguration | | resolved |
| 6 Apr 2026 | CVE-2026-5607: SSRF in imprvhub mcp-browser-agent up to 0.8.0 | imprvhub | browsing | tool misuse | | reported |
| 6 Apr 2026 | CVE-2026-35394: mobile-mcp URL tool allows arbitrary Android intent execution | Mobile Next | workflow | tool misuse | | resolved |
| 5 Apr 2026 | CVE-2026-5584: Remote code injection in agenticSeek PyInterpreter.execute | Fosowl | coding | tool misuse | | reported |
| 3 Apr 2026 | Multiple critical vulnerabilities in PraisonAI multi-agent framework (8 CVEs) | PraisonAI | workflow | tool misuse | | resolved |
| 3 Apr 2026 | CVE-2025-64340: Command injection in FastMCP install commands on Windows | PrefectHQ | coding | tool misuse | | resolved |
| 2 Apr 2026 | FastMCP flaws before 3.2.0: authenticated SSRF and OAuth confused deputy | PrefectHQ | other | tool misuse | | resolved |
| 2 Apr 2026 | SSRF vulnerability in a11y-mcp MCP server (CVE-2026-5323) | priyankark | other | tool misuse | | resolved |