Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Incident database

Structured records of AI agent security incidents: what happened, which vendor and agent type, the root cause, and every source we used. Filter, browse, or download as CSV.

Incidents by month, 2026 · 434 total · click a month to filter
Jan 2026: 23 incidents23JanFeb 2026: 26 incidents26FebMar 2026: 46 incidents46MarApr 2026: 46 incidents46AprMay 2026: 52 incidents52MayJun 2026: 51 incidents51JunJul 2026: 45 incidents45JulAug 2026: 82 incidents82AugSep 2026: 63 incidents63SepOct 2026: 0 incidents0OctNov 2026: 0 incidents0NovDec 2026: 0 incidents0Dec
Clear

45 incidents match

29 Jul 2026 · Anthropic

MCP Ruby SDK memory exhaustion via unbounded session objects

MCP Ruby SDK versions prior to 0.23.0 fail to expire sessions by default in StreamableHTTPTransport, allowing repeated initialize requests to create unbounded ServerSession objects and exhaust process memory.

other·misconfiguration·

29 Jul 2026 · Pydantic

Pydantic AI Multiple Vulnerabilities in Versions 1.56.0-2.0.0b5

Three vulnerabilities discovered in Pydantic AI framework allow attackers to bypass security controls: cloud metadata credential exposure via IPv6-encoded IPs, arbitrary file access through unvalidated UploadedFile references, and execution of unresolved tool calls with attacker-supplied arguments.

workflow·excessive permissions·

29 Jul 2026 · Flyto

Flyto2 Core SSRF vulnerability in HTTP modules

Flyto2 Core prior to version 2.26.7 contains a server-side request forgery (SSRF) vulnerability in multiple HTTP-emitting modules that fail to validate caller-controlled URLs, allowing access to internal or metadata endpoints.

workflow·misconfiguration·

29 Jul 2026 · Anthropic

MCP Ruby SDK Multiple Vulnerabilities Prior to 0.23.0

The MCP Ruby SDK versions prior to 0.23.0 contain four security vulnerabilities including DNS rebinding attacks, memory exhaustion, session fixation, and unauthenticated remote denial of service. All issues were fixed in version 0.23.0.

other·misconfiguration·

28 Jul 2026 · GitHub

GitHub MCP Server nil pointer dereference denial of service

GitHub MCP Server prior to version 1.1.0 is vulnerable to a denial of service attack due to improper nil checking in the CompletionsHandler function. An unauthenticated client can crash the server by sending a completion request with a missing or empty ref field.

other·misconfiguration·

27 Jul 2026 · Moonshot AI

CVE-2026-17534: Kimi Code SSRF via DNS resolution bypass

Kimi Code before version 0.27.0 has a Server-Side Request Forgery (SSRF) vulnerability in its FetchURL function that can be exploited via prompt injection. An attacker can bypass the hostname denylist by using crafted public hostnames that resolve to internal addresses or URLs that redirect to internal targets.

coding·prompt injection·

26 Jul 2026 · nanocoai

CVE-2026-17433: Improper authorization in nanocoai NanoClaw

A vulnerability in nanocoai NanoClaw up to version 2.0.64 allows improper authorization through manipulation of the createChatSdkBridge.setup function in the MCP Server Approval component. The exploit is now public and requires local access.

other·excessive permissions·

25 Jul 2026 · SiYuan

CVE-2026-66012: SiYuan Missing Authorization in MCP Kernel Endpoint

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint that, when Publish server is enabled in anonymous mode, allows remote unauthenticated attackers to read sensitive configuration files, write arbitrary files, and plant malicious plugins leading to administrator takeover.

other·excessive permissions·

24 Jul 2026 · BlenderMCP

BlenderMCP path traversal vulnerability in download_polyhaven_asset

BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that allows attackers to write arbitrary files and achieve persistent code execution through MITM attacks or prompt injection.

coding·prompt injection·

24 Jul 2026 · Jan

Jan Local API Server CORS Misconfiguration (CVE-2026-66005)

Jan versions through 0.8.4 contain a CORS misconfiguration vulnerability in the local API server that allows network-adjacent attackers to bypass trusted host restrictions and access the unauthenticated API to perform inference, enumerate models, invoke MCP tools, and read cross-origin responses.

other·misconfiguration·

24 Jul 2026 · Kortix AI

Suna message queue API broken access control vulnerability

Suna before version 0.9.102 contains a broken access control vulnerability in its message queue API that allows authenticated attackers to access queue resources belonging to other users, read their prompt queues, and inject malicious prompts into their AI agent sessions.

other·excessive permissions·

23 Jul 2026 · APIFold

APIFold webhook endpoint accepts unauthenticated arbitrary JSON

APIFold's webhook endpoint fails to validate signatures or require authentication, allowing unauthenticated attackers to inject arbitrary payloads into Redis and PostgreSQL. The vulnerability was patched in commit 7f19b52280f414f57af2b79a95333d1c8fbeece5.

other·misconfiguration·

23 Jul 2026 · Void

Void path traversal in AI agent file-reading tools

Void through version 1.3.4 contains a path traversal vulnerability in AI agent file-reading tools that allows network-adjacent attackers to read arbitrary files outside the workspace by injecting instructions into content the agent processes. Attackers can silently exfiltrate sensitive files such as SSH keys or cloud credentials.

coding·prompt injection·

23 Jul 2026 · AgentGPT

AgentGPT authorization bypass allows unauthorized task attachment

AgentGPT through version 1.0.0 contains an authorization bypass vulnerability that allows authenticated users to attach tasks to another user's agent run by supplying a target run_id without ownership verification. Attackers can corrupt task history, exhaust loop budgets, and drive LLM costs against victims.

workflow·excessive permissions·

22 Jul 2026 · n8n

n8n privilege escalation and OAuth authorization vulnerabilities

n8n versions before 2.30.1 contain two critical vulnerabilities in AI Agents and OAuth 2.1 features that allow users to escalate privileges, execute arbitrary nodes, access credential secrets, and bypass workflow authorization checks.

other·excessive permissions·

22 Jul 2026 · Red Hat

Path traversal in Ansible Lightspeed MCP server via prompt injection

A path traversal vulnerability in Ansible Lightspeed's Model Context Protocol server allows attackers to manipulate AI agents through indirect prompt injection, enabling unauthorized file writes and potential system compromise.

coding·prompt injection·

21 Jul 2026 · SepineTam

MCP-for-Stata Command Injection via log_file_name Parameter

MCP-for-Stata versions prior to 1.17.3 are vulnerable to command injection through the unsanitized log_file_name parameter in the stata_do API and CLI. An attacker can inject arbitrary Stata commands by crafting a malicious log_file_name parameter.

coding·prompt injection·

21 Jul 2026 · mcp-webresearch

mcp-webresearch 0.1.7 SSRF vulnerability via LLM prompt injection

A server-side request forgery vulnerability in mcp-webresearch 0.1.7 allows attackers to use prompt injection to steer an LLM into accessing internal network services and cloud metadata endpoints through the visit_page tool, exposing sensitive credentials.

browsing·prompt injection·

20 Jul 2026 · Network-AI

Network-AI MCP SSE Server Missing Authentication

Network-AI versions prior to 5.4.5 have an MCP SSE server that defaults to empty authentication and allows CORS, enabling unauthenticated attackers to invoke all 22 exposed MCP tools via cross-origin requests.

other·misconfiguration·

20 Jul 2026 · nolabs

nono Sandbox Escape via Unix Domain Socket Access

The nono AI agent sandbox software prior to version 0.55.0 allowed access to local Unix domain sockets, enabling sandbox escape through the systemd dbus socket. Version 0.55.0 patches the vulnerability.

other·misconfiguration·

20 Jul 2026 · NextCRM

NextCRM MCP API Missing Role Checks in Product Operations

NextCRM version 0.12.1 fails to enforce role-based access controls in its MCP product tools API, allowing any authenticated low-privileged user with an MCP API token to create, modify, archive, or delete products in the shared CRM catalog. The vulnerability was fixed in version 0.12.3.

coding·excessive permissions·

17 Jul 2026 · AI Copilot

AI Copilot WordPress plugin OAuth token binding vulnerability

The AI Copilot WordPress plugin before version 1.5.4 fails to bind OAuth access tokens to specific WordPress users, allowing unauthenticated attackers to complete a public OAuth flow and execute privileged MCP tools as an administrator, including arbitrary user creation and role escalation.

other·misconfiguration·

17 Jul 2026 · ruvnet

CVE-2026-58195: Agentic-Flow Command Injection via MCP Server Tools

Agentic-Flow prior to version 2.0.14 contains a command injection vulnerability in MCP server tools where attacker-controlled parameters are directly interpolated into shell commands passed to execSync(), allowing arbitrary OS command execution with server privileges.

workflow·tool misuse·

17 Jul 2026 · IBM

IBM Langflow OSS code injection via ToolGuard integration

IBM Langflow OSS versions 1.0.0 through 1.10.0 contain a code injection vulnerability in the ToolGuard component that allows authenticated users to bypass custom component restrictions and achieve arbitrary Python code execution on the backend.

workflow·excessive permissions·

16 Jul 2026 · Anthropic

Claude Code Action arbitrary code execution via malicious .mcp.json

A vulnerability in Claude Code Action prior to version 1.0.74 allowed attackers to achieve arbitrary code execution on GitHub Actions runners by including a malicious .mcp.json file in pull requests, potentially exfiltrating workflow secrets like API keys and tokens.

coding·misconfiguration·

16 Jul 2026 · dbt Labs

dbt-mcp argument injection and data leak vulnerabilities

dbt-mcp versions prior to 1.17.1 contained two vulnerabilities: unsanitized command-line argument injection allowing MCP clients to inject dbt flags, and unredacted telemetry transmission of sensitive query parameters and variables to dbt Labs.

workflow·excessive permissions·

16 Jul 2026 · Apify

Apify MCP Server URL Validation Bypass

The Apify MCP server's fetch-apify-docs tool failed to properly validate documentation URLs, allowing attackers to bypass domain allowlisting and return arbitrary content to AI agents. The vulnerability was fixed in version 0.9.21.

other·misconfiguration·

9 Jul 2026 · aerostackdev

CVE-2026-15189: SSRF in aerostack-mcp WhatsApp MCP upload_media tool

A server-side request forgery vulnerability was reported in aerostackdev's aerostack-mcp, where the media_url argument of the upload_media function in the mcp-whatsapp component can be manipulated remotely. The project, which uses rolling releases, was notified via an issue report but has not responded.

workflow·tool misuse·

9 Jul 2026 · n8n

n8n and n8n-MCP flaws expose credentials and cross-tenant workflow backups

Three disclosed vulnerabilities in the n8n workflow automation ecosystem allowed AI Agents to bypass a credential's Allowed HTTP Request Domains restriction via an MCP tool pointed at an attacker-controlled URL (CVE-2026-59207), and let authenticated tenants in n8n-MCP multi-tenant HTTP mode read or delete other tenants' workflow version backups containing credential references and authorization headers (CVE-2026-54052, CVE-2026-55608). All issues were fixed in updated releases.

workflow·excessive permissions·

8 Jul 2026 · Composio

CVE-2026-59807: Composio SDK path validation bypass enables credential file exfiltration

Composio SDK versions before 0.2.32-beta.283 lack an assertSafeFileUploadPath check in the readFileFromDisk function of tool-file-uploads.ts, letting attackers use prompt injection to manipulate file_uploadable parameters and make the CLI upload sensitive files such as SSH private keys to attacker-controlled storage. The issue was fixed in release 0.2.32-beta.283.

workflow·prompt injection·

8 Jul 2026 · BerriAI

LiteLLM MCP endpoint authentication bypass via forged Authorization header (CVE-2026-59822)

Prior to version 1.84.0, LiteLLM's MCP Streamable HTTP endpoint let an unauthenticated attacker send a fabricated Authorization header that triggered an OAuth2 passthrough fallback, substituting an empty UserAPIKeyAuth() object for failed key validation and granting access to MCP tooling without a valid LiteLLM key. The issue was fixed in release 1.84.0.

other·excessive permissions·

8 Jul 2026 · Cline

CVE-2026-59723: Cline Hub dashboard WebSocket flaw allows remote command execution

Prior to version 3.0.30, the Cline Hub dashboard server launched by the `cline dashboard` command accepted WebSocket connections on /browser without validating the Origin header, and permitted unauthorized browser requests when ROOM_SECRET was unset on local 127.0.0.1 binds. Malicious websites could send desktopCommand frames to read workspace state, alter MCP and provider settings, and trigger command execution; fixed in 3.0.30.

coding·misconfiguration·

6 Jul 2026 · OpenAI

CVE-2026-14898: Codex macOS app image rendering enables prompt-injection data exfiltration

The OpenAI Codex desktop app for macOS automatically fetched remote images referenced in Markdown model responses, allowing an indirect prompt injection to encode session secrets into an image URL that was sent to an attacker-controlled server without user interaction. Exploitation could leak API keys, source code and data returned by connected tools.

coding·prompt injection·

6 Jul 2026 · SUSE

CVE-2026-44934: SUSE Rancher AI Agent leaks API keys in DEBUG logs

An information disclosure flaw in SUSE Rancher AI Agent 1.0 before 1.0.2 causes API keys and LLM response text containing potentially sensitive data to be written into logfiles when the DEBUG loglevel is set, allowing local attackers to misuse the exposed data or credentials.

workflow·data leak·

5 Jul 2026 · langchain-ai

CVE-2026-14742: Weak hash in LangGraph task result cache key

A vulnerability in langchain-ai LangGraph up to version 1.2.4 involves the _freeze function in the Task Result Cache (libs/langgraph/langgraph/_internal/_cache.py), where manipulation of the default_cache_key argument leads to use of a weak hash. The issue can be exploited remotely but with high attack complexity, and a fix pull request is still awaiting acceptance.

workflow·unknown·

5 Jul 2026 · AIAnytime

SSRF in AIAnytime Awesome-MCP-Server wiki-summary tool (CVE-2026-14748)

A server-side request forgery flaw in the mcp-wiki/wiki-summary component of AIAnytime's Awesome-MCP-Server allows remote attackers to manipulate the 'url' argument in mcp-wiki/src/mcp_wiki/server.py. An exploit has been published and the project has not responded to the issue report.

workflow·tool misuse·

3 Jul 2026 · Kong

CVE-2026-13341: Indirect prompt injection in Kong Konnect MCP server

A vulnerability in the Kong Konnect Model Context Protocol (MCP) server before version 1.0.0 allows a remote attacker to carry out an indirect prompt injection attack and cause the server to execute unintended API requests. The issue is addressed in version 1.0.0 and documented in a GitHub security advisory.

workflow·prompt injection·

2 Jul 2026 · leshchenko1979

fast-mcp-telegram MCP server auth bypass via path traversal in bearer token (CVE-2026-52830)

Versions of the fast-mcp-telegram Telegram MCP server prior to 0.19.1 built session-file paths directly from HTTP Bearer tokens without normalising path separators, letting a remote client authenticate as the default legacy Telegram session using a token such as '../fast-mcp-telegram/telegram'. The flaw bypassed the reserved session-name control and was fixed in release 0.19.1.

other·excessive permissions·

2 Jul 2026 · Microsoft

CVE-2026-41106: Open redirect in M365 Copilot enables privilege elevation

A URL redirection to untrusted site ('open redirect') vulnerability in Microsoft M365 Copilot allows an unauthorized attacker to elevate privileges over a network. The issue is tracked as CVE-2026-41106 and documented in Microsoft's security update guide.

workflow·misconfiguration·