31 Jul 2026 · Strands
Incorrect authorization in the http_request tool in Strands Agents Tools before version 0.8.2 could allow remote attackers to obtain credentials by influencing the LLM to route requests through attacker-controlled proxy infrastructure.
other·excessive permissions·
29 Jul 2026 · Anthropic
MCP Ruby SDK versions prior to 0.23.0 fail to expire sessions by default in StreamableHTTPTransport, allowing repeated initialize requests to create unbounded ServerSession objects and exhaust process memory.
other·misconfiguration·
29 Jul 2026 · Pydantic
Three vulnerabilities discovered in Pydantic AI framework allow attackers to bypass security controls: cloud metadata credential exposure via IPv6-encoded IPs, arbitrary file access through unvalidated UploadedFile references, and execution of unresolved tool calls with attacker-supplied arguments.
workflow·excessive permissions·
29 Jul 2026 · Flyto
Flyto2 Core prior to version 2.26.7 contains a server-side request forgery (SSRF) vulnerability in multiple HTTP-emitting modules that fail to validate caller-controlled URLs, allowing access to internal or metadata endpoints.
workflow·misconfiguration·
29 Jul 2026 · Anthropic
The MCP Ruby SDK versions prior to 0.23.0 contain four security vulnerabilities including DNS rebinding attacks, memory exhaustion, session fixation, and unauthenticated remote denial of service. All issues were fixed in version 0.23.0.
other·misconfiguration·
28 Jul 2026 · Alibaba Cloud
Alibabacloud RDS OpenAPI MCP server improperly exposes MCP endpoints listening on all network interfaces by default, allowing remote attackers to invoke exposed MCP tools.
other·misconfiguration·
28 Jul 2026 · GitHub
GitHub MCP Server prior to version 1.1.0 is vulnerable to a denial of service attack due to improper nil checking in the CompletionsHandler function. An unauthenticated client can crash the server by sending a completion request with a missing or empty ref field.
other·misconfiguration·
27 Jul 2026 · Moonshot AI
Kimi Code before version 0.27.0 has a Server-Side Request Forgery (SSRF) vulnerability in its FetchURL function that can be exploited via prompt injection. An attacker can bypass the hostname denylist by using crafted public hostnames that resolve to internal addresses or URLs that redirect to internal targets.
coding·prompt injection·
26 Jul 2026 · nanocoai
A vulnerability in nanocoai NanoClaw up to version 2.0.64 allows improper authorization through manipulation of the createChatSdkBridge.setup function in the MCP Server Approval component. The exploit is now public and requires local access.
other·excessive permissions·
25 Jul 2026 · SiYuan
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint that, when Publish server is enabled in anonymous mode, allows remote unauthenticated attackers to read sensitive configuration files, write arbitrary files, and plant malicious plugins leading to administrator takeover.
other·excessive permissions·
24 Jul 2026 · Microsoft
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
other·tool misuse·
24 Jul 2026 · BlenderMCP
BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that allows attackers to write arbitrary files and achieve persistent code execution through MITM attacks or prompt injection.
coding·prompt injection·
24 Jul 2026 · Jan
Jan versions through 0.8.4 contain a CORS misconfiguration vulnerability in the local API server that allows network-adjacent attackers to bypass trusted host restrictions and access the unauthenticated API to perform inference, enumerate models, invoke MCP tools, and read cross-origin responses.
other·misconfiguration·
24 Jul 2026 · Kortix AI
Suna before version 0.9.102 contains a broken access control vulnerability in its message queue API that allows authenticated attackers to access queue resources belonging to other users, read their prompt queues, and inject malicious prompts into their AI agent sessions.
other·excessive permissions·
23 Jul 2026 · APIFold
APIFold's webhook endpoint fails to validate signatures or require authentication, allowing unauthenticated attackers to inject arbitrary payloads into Redis and PostgreSQL. The vulnerability was patched in commit 7f19b52280f414f57af2b79a95333d1c8fbeece5.
other·misconfiguration·
23 Jul 2026 · Void
Void through version 1.3.4 contains a path traversal vulnerability in AI agent file-reading tools that allows network-adjacent attackers to read arbitrary files outside the workspace by injecting instructions into content the agent processes. Attackers can silently exfiltrate sensitive files such as SSH keys or cloud credentials.
coding·prompt injection·
23 Jul 2026 · AgentGPT
AgentGPT through version 1.0.0 contains an authorization bypass vulnerability that allows authenticated users to attach tasks to another user's agent run by supplying a target run_id without ownership verification. Attackers can corrupt task history, exhaust loop budgets, and drive LLM costs against victims.
workflow·excessive permissions·
22 Jul 2026 · n8n
n8n versions before 2.30.1 contain two critical vulnerabilities in AI Agents and OAuth 2.1 features that allow users to escalate privileges, execute arbitrary nodes, access credential secrets, and bypass workflow authorization checks.
other·excessive permissions·
22 Jul 2026 · Red Hat
A path traversal vulnerability in Ansible Lightspeed's Model Context Protocol server allows attackers to manipulate AI agents through indirect prompt injection, enabling unauthorized file writes and potential system compromise.
coding·prompt injection·
21 Jul 2026 · SepineTam
MCP-for-Stata versions prior to 1.17.3 are vulnerable to command injection through the unsanitized log_file_name parameter in the stata_do API and CLI. An attacker can inject arbitrary Stata commands by crafting a malicious log_file_name parameter.
coding·prompt injection·
21 Jul 2026 · mcp-webresearch
A server-side request forgery vulnerability in mcp-webresearch 0.1.7 allows attackers to use prompt injection to steer an LLM into accessing internal network services and cloud metadata endpoints through the visit_page tool, exposing sensitive credentials.
browsing·prompt injection·
20 Jul 2026 · Network-AI
Network-AI versions prior to 5.4.5 have an MCP SSE server that defaults to empty authentication and allows CORS, enabling unauthenticated attackers to invoke all 22 exposed MCP tools via cross-origin requests.
other·misconfiguration·
20 Jul 2026 · nolabs
The nono AI agent sandbox software prior to version 0.55.0 allowed access to local Unix domain sockets, enabling sandbox escape through the systemd dbus socket. Version 0.55.0 patches the vulnerability.
other·misconfiguration·
20 Jul 2026 · AgenticMail
Multiple vulnerabilities in AgenticMail packages allow AI agents to impersonate other agents, enumerate tasks, and execute prompt injection attacks. Fixes have been released in versions 0.9.32 and later.
coding·prompt injection·
20 Jul 2026 · NextCRM
NextCRM version 0.12.1 fails to enforce role-based access controls in its MCP product tools API, allowing any authenticated low-privileged user with an MCP API token to create, modify, archive, or delete products in the shared CRM catalog. The vulnerability was fixed in version 0.12.3.
coding·excessive permissions·
17 Jul 2026 · AI Copilot
The AI Copilot WordPress plugin before version 1.5.4 fails to bind OAuth access tokens to specific WordPress users, allowing unauthenticated attackers to complete a public OAuth flow and execute privileged MCP tools as an administrator, including arbitrary user creation and role escalation.
other·misconfiguration·
17 Jul 2026 · tailcallhq
ForgeCode, an AI pair-programming CLI, automatically loads and executes MCP servers defined in a repository's .mcp.json file without user confirmation, allowing arbitrary code execution when developers evaluate untrusted repositories.
coding·misconfiguration·
17 Jul 2026 · ruvnet
Agentic-Flow prior to version 2.0.14 contains a command injection vulnerability in MCP server tools where attacker-controlled parameters are directly interpolated into shell commands passed to execSync(), allowing arbitrary OS command execution with server privileges.
workflow·tool misuse·
17 Jul 2026 · IBM
IBM Langflow OSS versions 1.0.0 through 1.10.0 contain a code injection vulnerability in the ToolGuard component that allows authenticated users to bypass custom component restrictions and achieve arbitrary Python code execution on the backend.
workflow·excessive permissions·
16 Jul 2026 · Anthropic
A vulnerability in Claude Code Action prior to version 1.0.74 allowed attackers to achieve arbitrary code execution on GitHub Actions runners by including a malicious .mcp.json file in pull requests, potentially exfiltrating workflow secrets like API keys and tokens.
coding·misconfiguration·
16 Jul 2026 · dbt Labs
dbt-mcp versions prior to 1.17.1 contained two vulnerabilities: unsanitized command-line argument injection allowing MCP clients to inject dbt flags, and unredacted telemetry transmission of sensitive query parameters and variables to dbt Labs.
workflow·excessive permissions·
16 Jul 2026 · Apify
The Apify MCP server's fetch-apify-docs tool failed to properly validate documentation URLs, allowing attackers to bypass domain allowlisting and return arbitrary content to AI agents. The vulnerability was fixed in version 0.9.21.
other·misconfiguration·
9 Jul 2026 · aerostackdev
A server-side request forgery vulnerability was reported in aerostackdev's aerostack-mcp, where the media_url argument of the upload_media function in the mcp-whatsapp component can be manipulated remotely. The project, which uses rolling releases, was notified via an issue report but has not responded.
workflow·tool misuse·
9 Jul 2026 · n8n
Three disclosed vulnerabilities in the n8n workflow automation ecosystem allowed AI Agents to bypass a credential's Allowed HTTP Request Domains restriction via an MCP tool pointed at an attacker-controlled URL (CVE-2026-59207), and let authenticated tenants in n8n-MCP multi-tenant HTTP mode read or delete other tenants' workflow version backups containing credential references and authorization headers (CVE-2026-54052, CVE-2026-55608). All issues were fixed in updated releases.
workflow·excessive permissions·
8 Jul 2026 · GitHub
Security researchers at Noma Security published research dubbed "GitLost" describing how they manipulated GitHub's AI agent into exposing the contents of private repositories. The disclosure was widely discussed on Hacker News.
coding·prompt injection·
8 Jul 2026 · Composio
Composio SDK versions before 0.2.32-beta.283 lack an assertSafeFileUploadPath check in the readFileFromDisk function of tool-file-uploads.ts, letting attackers use prompt injection to manipulate file_uploadable parameters and make the CLI upload sensitive files such as SSH private keys to attacker-controlled storage. The issue was fixed in release 0.2.32-beta.283.
workflow·prompt injection·
8 Jul 2026 · BerriAI
Prior to version 1.84.0, LiteLLM's MCP Streamable HTTP endpoint let an unauthenticated attacker send a fabricated Authorization header that triggered an OAuth2 passthrough fallback, substituting an empty UserAPIKeyAuth() object for failed key validation and granting access to MCP tooling without a valid LiteLLM key. The issue was fixed in release 1.84.0.
other·excessive permissions·
8 Jul 2026 · Cline
Prior to version 3.0.30, the Cline Hub dashboard server launched by the `cline dashboard` command accepted WebSocket connections on /browser without validating the Origin header, and permitted unauthorized browser requests when ROOM_SECRET was unset on local 127.0.0.1 binds. Malicious websites could send desktopCommand frames to read workspace state, alter MCP and provider settings, and trigger command execution; fixed in 3.0.30.
coding·misconfiguration·
6 Jul 2026 · OpenAI
The OpenAI Codex desktop app for macOS automatically fetched remote images referenced in Markdown model responses, allowing an indirect prompt injection to encode session secrets into an image URL that was sent to an attacker-controlled server without user interaction. Exploitation could leak API keys, source code and data returned by connected tools.
coding·prompt injection·
6 Jul 2026 · SUSE
An information disclosure flaw in SUSE Rancher AI Agent 1.0 before 1.0.2 causes API keys and LLM response text containing potentially sensitive data to be written into logfiles when the DEBUG loglevel is set, allowing local attackers to misuse the exposed data or credentials.
workflow·data leak·
5 Jul 2026 · langchain-ai
A vulnerability in langchain-ai LangGraph up to version 1.2.4 involves the _freeze function in the Task Result Cache (libs/langgraph/langgraph/_internal/_cache.py), where manipulation of the default_cache_key argument leads to use of a weak hash. The issue can be exploited remotely but with high attack complexity, and a fix pull request is still awaiting acceptance.
workflow·unknown·
5 Jul 2026 · AIAnytime
A server-side request forgery flaw in the mcp-wiki/wiki-summary component of AIAnytime's Awesome-MCP-Server allows remote attackers to manipulate the 'url' argument in mcp-wiki/src/mcp_wiki/server.py. An exploit has been published and the project has not responded to the issue report.
workflow·tool misuse·
3 Jul 2026 · Kong
A vulnerability in the Kong Konnect Model Context Protocol (MCP) server before version 1.0.0 allows a remote attacker to carry out an indirect prompt injection attack and cause the server to execute unintended API requests. The issue is addressed in version 1.0.0 and documented in a GitHub security advisory.
workflow·prompt injection·
2 Jul 2026 · leshchenko1979
Versions of the fast-mcp-telegram Telegram MCP server prior to 0.19.1 built session-file paths directly from HTTP Bearer tokens without normalising path separators, letting a remote client authenticate as the default legacy Telegram session using a token such as '../fast-mcp-telegram/telegram'. The flaw bypassed the reserved session-name control and was fixed in release 0.19.1.
other·excessive permissions·
2 Jul 2026 · Microsoft
A URL redirection to untrusted site ('open redirect') vulnerability in Microsoft M365 Copilot allows an unauthorized attacker to elevate privileges over a network. The issue is tracked as CVE-2026-41106 and documented in Microsoft's security update guide.
workflow·misconfiguration·