| 30 Jun 2026 | CVE-2026-10564: SSRF in IBM Langflow OSS RSS and SearXNG components | IBM | workflow | prompt injection | | confirmed |
| 30 Jun 2026 | CVE-2026-9132: GitHub Enterprise Server Copilot diff endpoint exposed private repo code | GitHub | coding | excessive permissions | | resolved |
| 30 Jun 2026 | CVE-2026-58446: Presenton MCP endpoint bypasses session authentication | Presenton | workflow | misconfiguration | | resolved |
| 30 Jun 2026 | CVE-2026-58168: DeepTutor authorization bypass grants unrestricted MCP tool access | HKUDS | other | excessive permissions | | resolved |
| 29 Jun 2026 | Two Claude Code vulnerabilities: world-readable /copy output and worktree sandbox escape | Anthropic | coding | misconfiguration | | resolved |
| 29 Jun 2026 | CVE-2026-13437: App tokens leaked via AI Agent job API in Devolutions PowerShell Universal | Devolutions | workflow | data leak | | confirmed |
| 29 Jun 2026 | CVE-2026-13524: Improper authorization in Cherry Studio MCP OAuth callback server | CherryHQ | other | excessive permissions | | reported |
| 28 Jun 2026 | Flowise Custom MCP env var denylist bypass enables RCE (CVE-2026-58057) | FlowiseAI | workflow | tool misuse | | resolved |
| 26 Jun 2026 | Mattermost Agents MCP server SSRF allows internal data exfiltration (CVE-2026-4339) | Mattermost | workflow | tool misuse | | confirmed |
| 26 Jun 2026 | AutoGPT denial-of-service flaw in AITextSummarizerBlock (CVE-2025-32394) | Significant Gravitas | workflow | unknown | | resolved |
| 26 Jun 2026 | CVE-2026-48529: GitHub MCP Server shares first user's credentials in lockdown mode | GitHub | coding | excessive permissions | | resolved |
| 25 Jun 2026 | LibreChat: agent file-upload authorization bypass and MCP OAuth token theft flaws | LibreChat | other | excessive permissions | | resolved |
| 25 Jun 2026 | ToolJet patches three flaws: cross-tenant credential decryption, SSRF and plugin RCE | ToolJet | workflow | excessive permissions | | resolved |
| 25 Jun 2026 | Cursor sandbox escape flaws (CVE-2026-50548/50549) allow writes outside workspace | Cursor | coding | excessive permissions | | resolved |
| 24 Jun 2026 | Jenkins MCP Server Plugin missing permission check exposes Pipeline replay scripts | Jenkins | workflow | excessive permissions | | confirmed |
| 24 Jun 2026 | Multiple command injection and policy bypass flaws in Warp agentic dev environment | Warp | coding | tool misuse | | resolved |
| 24 Jun 2026 | Twenty CRM AI agent monitor IDOR exposed cross-workspace chat history (CVE-2026-55583) | Twenty | other | excessive permissions | | resolved |
| 23 Jun 2026 | Multiple Langflow vulnerabilities: unauthenticated RCE, IDOR and path traversal | Langflow | workflow | excessive permissions | | resolved |
| 23 Jun 2026 | CVE-2026-54316: Claude Code WebFetch allowlist enabled covert data exfiltration | Anthropic | coding | excessive permissions | | resolved |
| 23 Jun 2026 | Daytona AI code-execution runtime discloses six flaws including cross-tenant access | Daytona | coding | excessive permissions | | resolved |
| 23 Jun 2026 | CVE-2026-55249: Command injection in @rtk-ai/rtk-rewrite OpenClaw plugin | rtk-ai | coding | tool misuse | | confirmed |
| 23 Jun 2026 | CVE-2026-12112: Session hijacking flaw in foreman-mcp-server enables privilege escalation | Red Hat | workflow | misconfiguration | | resolved |
| 22 Jun 2026 | CVE-2025-66336: SQL injection and authorization bypass in Apache Doris MCP Server | Apache Software Foundation | other | excessive permissions | | resolved |
| 22 Jun 2026 | CVE-2026-55443: LangChain path traversal allows file disclosure outside intended root | LangChain | workflow | excessive permissions | | resolved |
| 21 Jun 2026 | Two SSRF vulnerabilities in BerriAI LiteLLM MCP server components (<=1.82.2) | BerriAI | other | tool misuse | | reported |
| 20 Jun 2026 | Multiple remote code execution flaws in Flowise AI agent-builder platform | FlowiseAI | workflow | excessive permissions | | resolved |
| 19 Jun 2026 | line-desktop-mcp HTTP mode exposes unauthenticated MCP endpoint (CVE-2026-49357) | dtwang | workflow | misconfiguration | | resolved |
| 19 Jun 2026 | gin-vue-admin 2.9.1 code-generation/MCP flaw allows remote code execution (CVE-2026-48787) | flipped-aurora | coding | tool misuse | | reported |
| 18 Jun 2026 | CVE-2026-11719: Scope enforcement bypass in MCP Toolbox for Databases | Google (googleapis) | workflow | excessive permissions | | confirmed |
| 18 Jun 2026 | CVE-2026-49257: mcp-pinot MCP server exposes unauthenticated Pinot access | StarTree (startreedata) | other | misconfiguration | | resolved |
| 18 Jun 2026 | Eclipse Theia AI chat prompt injection and data exfiltration flaws before 1.71.0 | Eclipse Foundation | coding | prompt injection | | resolved |
| 18 Jun 2026 | Multiple Microsoft Copilot vulnerabilities disclosed, including workspace escape and data exposure | Microsoft | coding | excessive permissions | | confirmed |
| 18 Jun 2026 | PraisonAI flaw lets agents run arbitrary shell commands via forced auto-approval | PraisonAI | workflow | excessive permissions | | resolved |
| 18 Jun 2026 | CVE-2026-12045: pgAdmin 4 AI Assistant read-only transaction bypass via prompt injection | pgAdmin | workflow | prompt injection | | resolved |
| 17 Jun 2026 | Pydantic AI cloud-metadata blocklist bypass via IPv6 transition addresses (CVE-2026-48782) | Pydantic | workflow | tool misuse | | resolved |
| 17 Jun 2026 | CVE-2026-20265: Splunk AI Toolkit allowlist flaw enables agent data exfiltration | Splunk | other | misconfiguration | | resolved |
| 17 Jun 2026 | Network-AI MCP SSE server unauthenticated by default (CVE-2026-48814) | Jovancoding | workflow | misconfiguration | | resolved |
| 17 Jun 2026 | Windows-MCP unauthenticated HTTP control plane allowed arbitrary PowerShell execution | CursorTouch | other | misconfiguration | | resolved |
| 16 Jun 2026 | CVE-2026-53840: OpenClaw leaks custom headers via MCP cross-origin redirects | OpenClaw | other | data leak | | resolved |
| 15 Jun 2026 | CVE-2026-12203: Unauthenticated data exposure in HKUDS AI-Trader research export | HKUDS | other | excessive permissions | | resolved |
| 15 Jun 2026 | Cursor Desktop ran workspace-defined Claude hooks without user approval (CVE-2026-48124) | Cursor | coding | excessive permissions | | resolved |
| 13 Jun 2026 | browse-mcp Path Traversal and Arbitrary File Write | That1Drifter | browsing | excessive permissions | | resolved |
| 12 Jun 2026 | CVE-2026-50287: AgenticMail MCP server HTTP endpoint lacks authentication | AgenticMail | other | misconfiguration | | resolved |
| 11 Jun 2026 | mcp-server-kubernetes access controls bypassable at tool execution layer (CVE-2026-46519) | Flux159 | workflow | excessive permissions | | resolved |
| 11 Jun 2026 | CVE-2026-47250: mcp-server-kubernetes kubectl_generic allows token exfiltration via log prompt injection | Flux159 | workflow | prompt injection | | resolved |
| 9 Jun 2026 | CVE-2026-45482: Path traversal in GitHub Copilot and Visual Studio Code | Microsoft | coding | unknown | | confirmed |
| 4 Jun 2026 | Injection flaws in Microsoft Copilot products allow info disclosure and code execution | Microsoft | other | unknown | | confirmed |
| 2 Jun 2026 | CVE-2026-42073: OpenClaude MCP OAuth state check bypass allows callback server shutdown | Gitlawb | coding | unknown | | resolved |
| 2 Jun 2026 | LibreChat MCP integration flaws leak server secrets and allow cross-agent file deletion | LibreChat | other | data leak | | resolved |
| 1 Jun 2026 | SSRF in horizon921 mcpilot 0.1.0 MCP API call endpoint (CVE-2026-10280) | horizon921 | workflow | tool misuse | | reported |