Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Incident database

Structured records of AI agent security incidents: what happened, which vendor and agent type, the root cause, and every source we used. Filter, browse, or download as CSV.

Incidents by month, 2026 · 434 total · click a month to filter
Jan 2026: 23 incidents23JanFeb 2026: 26 incidents26FebMar 2026: 46 incidents46MarApr 2026: 46 incidents46AprMay 2026: 52 incidents52MayJun 2026: 51 incidents51JunJul 2026: 45 incidents45JulAug 2026: 82 incidents82AugSep 2026: 63 incidents63SepOct 2026: 0 incidents0OctNov 2026: 0 incidents0NovDec 2026: 0 incidents0Dec
Clear

52 incidents match

Incident dateIncidentVendorAgentRoot causeSeverityStatus
29 May 2026jqwik library contained hidden prompt injection telling AI coding agents to delete app outputjqwikcodingprompt injectionreported
29 May 2026CVE-2026-45312: RAGFlow Jinja2 template injection enables remote code executionInfiniFlowworkflowprompt injectionconfirmed
29 May 2026CVE-2026-45555: RCE in Roslyn CodeLens MCP Server via unchecked analyzer DLL loadingMarcelRoozekranscodingsupply chainresolved
29 May 2026n8n-MCP flaws leak telemetry data and misroute multi-tenant n8n API callsczlonkowski (n8n-mcp project)workflowdata leakresolved
29 May 2026FastGPT SSRF and code sandbox escape flaws fixed in 4.15.0-beta1labringworkflowmisconfigurationresolved
28 May 2026AnythingLLM agent filesystem skills allow command execution and path escapeMintplex Labsworkflowtool misuseresolved
27 May 2026CVE-2026-44830: Nocturne Memory MCP server auth bypass exposes agent memoryDataojitoriothermisconfigurationresolved
27 May 2026Gryph AI coding agent security layer logs sensitive file content (CVE-2026-45046)SafeDepcodingdata leakresolved
26 May 2026CVE-2026-44209: SSTI to RCE in banks LLM prompt template librarymasciothermisconfigurationresolved
26 May 2026CVE-2026-44450: Lumiverse MCP server endpoint allows authenticated remote code executionprolix-ocotherexcessive permissionsresolved
26 May 2026LangChain and LangSmith SDK unsafe deserialization of untrusted serialized objectsLangChainotherexcessive permissionsresolved
26 May 2026CVE-2026-44895: GitLab MCP Server HTTP transport exposes unauthenticated RPC endpointyoda-digitalcodingmisconfigurationresolved
24 May 2026CVE-2026-9353: Prompt injection flaw in NousResearch hermes-agent Skills GuardNousResearchotherprompt injectionreported
22 May 2026Command injection flaws in Microsoft Copilot and M365 Copilot (CVE-2026-41090, CVE-2026-42827)Microsoftotherunknownconfirmed
21 May 2026Central Dogma Git mirror disables SSH host-key verification (CVE-2026-11745)LINEothermisconfigurationconfirmed
15 May 2026Microsoft APM agent dependency manager: path traversal and symlink flaws (3 CVEs)Microsoftcodingsupply chainresolved
15 May 2026CVE-2026-44717: RCE in MCP Calculate Server via unsanitized eval()611711Darkothertool misuseresolved
15 May 2026CVE-2026-45401: SSRF via unvalidated redirects in Open WebUI web retrievalOpen WebUIbrowsingtool misuseresolved
14 May 2026Multiple vulnerabilities disclosed in MCP Registry and rmcp Rust SDKModel Context Protocolothersupply chainresolved
14 May 2026Hatchet cross-tenant data exposure via missing authorization (CVE-2026-42572)Hatchetworkflowmisconfigurationresolved
13 May 2026Vercel CLI leaked auth tokens in AI-agent non-interactive command output (CVE-2026-44479)Vercelcodingdata leakresolved
13 May 2026GitHub Copilot CLI arbitrary code execution via nested bare git repository (CVE-2026-45033)GitHubcodingtool misuseresolved
12 May 2026OpenAI agent swarm tied to May 2026 RubyGems supply chain attackOpenAIothersupply chainconfirmed
12 May 2026CVE-2026-42260: SSRF in Open-WebSearch MCP server URL safety checksAas-eebrowsingmisconfigurationresolved
12 May 2026JunoClaw agentic AI platform patches three MCP tool vulnerabilitiesJunoClawotherdata leakresolved
12 May 2026JunoClaw agent platform: shell command injection and SSRF flaws (CVE-2026-43990/43993)JunoClawworkflowtool misuseresolved
12 May 2026CVE-2026-42045: LobeChat artifact XSS chains to arbitrary command executionLobeHubotherprompt injectionresolved
12 May 2026Unauthenticated RCE in Code Runner MCP Server HTTP transport (CVE-2026-5029)codingexcessive permissionsreported
12 May 2026CVE-2025-65719: Remote code execution in Kubectl MCP Server v1.1.1Open Source Kubectl MCP Server (rohitg00)otherunknownreported
12 May 2026Langflow path traversal in Knowledge Bases API allows arbitrary directory deletionLangflowworkflowexcessive permissionsresolved
12 May 2026CVE-2026-44220: ciguard symlink traversal exposes files outside scan rootJo-Jo98 (ciguard project)codingdata leakresolved
12 May 2026CVE-2026-44246: Prompt injection in nnU-Net GitHub issue-triage agent workflowMIC-DKFZworkflowprompt injectionresolved
11 May 2026CVE-2026-30635: Command injection in automagik-genie 2.5.27 MCP serverothertool misusereported
11 May 2026CVE-2026-42869: Hardcoded JWT secret in SOCFortress CoPilot allows admin token forgerySOCFortressothermisconfigurationresolved
11 May 2026CVE-2026-43901: Wireshark MCP server allows arbitrary export path via unsandboxed toolbx33661 (Wireshark-MCP project)otherexcessive permissionsconfirmed
11 May 2026CVE-2026-31246: Command injection in GPT-Pilot Executor.run() enables RCEPythagora-iocodingtool misusereported
11 May 2026CVE-2026-8319: Remote resource exhaustion in aiwaves-cn agents memory recall functionaiwaves-cnotherunknownreported
11 May 2026DeepChat CVE-2026-43899: external URL handler bypass enables code executionThinkInAIXYZothermisconfigurationresolved
8 May 2026PromptHub SSRF via IPv6 bypass in skills fetch-remote endpoint (CVE-2026-42261)PromptHubworkflowmisconfigurationresolved
8 May 2026LiteLLM MCP preview endpoints allow authenticated users to run commands on proxy hostBerriAIotherexcessive permissionsresolved
8 May 2026PraisonAI MCP server path traversal enables arbitrary file write and code executionPraisonAIworkflowtool misuseresolved
8 May 2026Multiple vulnerabilities disclosed in FastGPT AI agent platform, including sandbox RCElabringworkflowmisconfigurationconfirmed
7 May 2026Microsoft discloses multiple Copilot injection and access control CVEs (May 2026)Microsoftotherprompt injectionconfirmed
6 May 2026Multiple OpenClaw MCP and gateway vulnerabilities patched (CVE-2026-44118, -44995, -45001)OpenClawotherexcessive permissionsresolved
5 May 2026CVE-2026-35228: Oracle MCP Server Helper Tool flaw allows malicious SQL executionOracleotherunknownconfirmed
5 May 2026CVE-2026-3456: SQL injection in WordPress GeekyBot AI chatbot pluginGeekyBotcustomer serviceunknownreported
5 May 2026Four unpatched CVEs in Langchain-Chatchat file APIs, exploits publicchatchat-spaceotherexcessive permissionsreported
5 May 2026SQLBot Text2SQL prompt injection enables arbitrary SQL execution and RCE (CVE-2026-33324)DataEaseotherprompt injectionresolved
4 May 2026CVE-2026-7729: SSRF in pixelsock directus-mcp 1.0.0 MCP interfacepixelsockworkflowtool misusereported
4 May 2026Evolver AI agent engine: path traversal, command injection and prototype pollution flawsEvoMapotherunknownresolved